<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Panorama Onboarding and Managing of PAN FW's in Panorama Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/panorama-discussions/panorama-onboarding-and-managing-of-pan-fw-s/m-p/997139#M2676</link>
    <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/77347"&gt;@TomYoung&lt;/a&gt; Thanks for your inputs. Just to clarify Active/Passive firewalls are displaying as Connected, but when I export/pushed config for the passive firewall active firewalls policies was stripped off as well.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I think because we have not disabled config sync for the HA pair.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What would your approach with this if we want to have no downtime?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Currently, On Panorama Active FW is disconnected, Passive FW is connected.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;1. Fix the Connection issues first, can we disassociate the Active Firewall again then continue the steps?&lt;/P&gt;
&lt;P&gt;2. Failover the traffic to the passive firewall? Checking on the Local Firewall GUI HA dashboard all seems to be matched excluding the Configuration which is not sync.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;
&lt;P&gt;Nicko&lt;/P&gt;</description>
    <pubDate>Mon, 09 Dec 2024 04:42:14 GMT</pubDate>
    <dc:creator>NickoKristian</dc:creator>
    <dc:date>2024-12-09T04:42:14Z</dc:date>
    <item>
      <title>Panorama Onboarding and Managing of PAN FW's</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/panorama-onboarding-and-managing-of-pan-fw-s/m-p/997068#M2674</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have a few questions, but let me share first what happened.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;End State Goal:&lt;/STRONG&gt; Have the Panorama manage our HQ and Branch Firewalls( 5 Firewalls Involved, We have license for this)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We have tried to onboard and use panorama for management of our PAN Firewalls.&lt;/P&gt;
&lt;P&gt;We have &lt;STRONG&gt;successfully onboarded our Active/Passive firewalls&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;(From Device&amp;gt;Managed Devices&amp;gt;Summary) status can be seen &lt;U&gt;&lt;STRONG&gt;both as connected&lt;/STRONG&gt;&lt;/U&gt;.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;U&gt;&lt;STRONG&gt;FIRST&lt;/STRONG&gt;&lt;/U&gt; tried to &lt;U&gt;&lt;STRONG&gt;import and push&lt;/STRONG&gt;&lt;/U&gt; the running configuration of the &lt;U&gt;&lt;STRONG&gt;Passive Firewall&lt;/STRONG&gt;&lt;/U&gt;, then we experienced a&lt;STRONG&gt;&lt;FONT color="#FF0000"&gt; down time.&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Checking on the&lt;STRONG&gt;&lt;U&gt; Active PA FW&lt;/U&gt;&lt;/STRONG&gt; the &lt;FONT color="#FF0000"&gt;&lt;STRONG&gt;configuration was stripped off&lt;/STRONG&gt;&lt;/FONT&gt;(No policies can be seen).&lt;/P&gt;
&lt;P&gt;We load our the backup config on the Active FW to recover services.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Now when I checked Panorama from Device&amp;gt;Managed Devices&amp;gt;Summary&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Active FW&lt;/STRONG&gt; is showing as&lt;STRONG&gt; &lt;FONT color="#FF0000"&gt;disconnected&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Passive&lt;/STRONG&gt; is showing as &lt;FONT color="#00FF00"&gt;&lt;STRONG&gt;connected&lt;/STRONG&gt;.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Policies&lt;/STRONG&gt; from the &lt;STRONG&gt;passive&lt;/STRONG&gt; firewall &lt;STRONG&gt;&lt;FONT color="#00FF00"&gt;is visible&lt;/FONT&gt;&lt;/STRONG&gt; on the Panorama,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have not associated the Active Firewall to the Device Group and Device Template yet.&lt;/P&gt;
&lt;P&gt;From the GUI it is under the "not associated list"&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Questions:&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;1. Is it a normal behavior for the configuration of the firewalls to be stripped off once they are being managed by Panorama?&lt;/P&gt;
&lt;P&gt;2. What if in the scenario that the Panorama Suddenly reboots, does this mean that traffic for all the devices it manage will go down since there are no configurations the NGFW's?&lt;/P&gt;
&lt;P&gt;3. Given our current status now what would be the best advisable thing to do next?:&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &lt;STRONG&gt;a).&lt;/STRONG&gt; Manually Failover the Traffic from Active FW to Passive FW then import the "Current Suspended" FW running configuration to the Panorama.&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &lt;STRONG&gt;b).&lt;/STRONG&gt; Can we just proceed on adding the Active FW to the Device Group &amp;amp; Device Template Created for the Passive FW.&lt;/P&gt;
&lt;P&gt;4. Are there any documentations for onboarding/Import and Push Active/Passive Firewalls to Panorama?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Any help would be very much appreciated.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;
&lt;P&gt;Nicko&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;LI-PRODUCT title="Panorama" id="Panorama"&gt;&lt;/LI-PRODUCT&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;LI-PRODUCT title="NGFW" id="NGFW"&gt;&lt;/LI-PRODUCT&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/213716"&gt;@panorama&lt;/a&gt;&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/7369"&gt;@Panoramaortho&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 07 Dec 2024 08:54:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/panorama-onboarding-and-managing-of-pan-fw-s/m-p/997068#M2674</guid>
      <dc:creator>NickoKristian</dc:creator>
      <dc:date>2024-12-07T08:54:28Z</dc:date>
    </item>
    <item>
      <title>Re: Panorama Onboarding and Managing of PAN FW's</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/panorama-onboarding-and-managing-of-pan-fw-s/m-p/997079#M2675</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/295338"&gt;@NickoKristian&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;1. Is it a normal behavior for the configuration of the firewalls to be stripped off once they are being managed by Panorama?&amp;nbsp; Yes.&amp;nbsp; The &lt;SPAN class="ph uicontrol"&gt;"Export or push device config bundle&lt;/SPAN&gt;" step will delete the local policies and objects.&amp;nbsp; This is needed or you will get a bunch of duplicate value errors.&amp;nbsp; The Force Template Values step will delete the local Network and Device values, except management interface IP address.&lt;/LI&gt;
&lt;LI&gt;What if in the scenario that the Panorama Suddenly reboots, does this mean that traffic for all the devices it manage will go down since there are no configurations the NGFW's?&amp;nbsp; No.&amp;nbsp; Once the Panorama configuration is pushed, it remains on the NGFW.&amp;nbsp; It appears your push failed because the NGFW was disconnected from Panorama.&lt;/LI&gt;
&lt;LI&gt;Given our current status now what would be the best advisable thing to do next?&amp;nbsp; You need to fix the disconnect error first.&amp;nbsp; You may want to failover if needed for connectivity to Panorama.&amp;nbsp; &lt;A href="https://docs.paloaltonetworks.com/panorama/10-1/panorama-admin/troubleshooting/recover-managed-device-connectivity-to-panorama" target="_blank"&gt;https://docs.paloaltonetworks.com/panorama/10-1/panorama-admin/troubleshooting/recover-managed-device-connectivity-to-panorama&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;Are there any documentations for onboarding/Import and Push Active/Passive Firewalls to Panorama?&amp;nbsp; &lt;A href="https://docs.paloaltonetworks.com/panorama/10-2/panorama-admin/manage-firewalls/transition-a-firewall-to-panorama-management/migrate-a-firewall-ha-pair-to-panorama-management" target="_blank"&gt;https://docs.paloaltonetworks.com/panorama/10-2/panorama-admin/manage-firewalls/transition-a-firewall-to-panorama-management/migrate-a-firewall-ha-pair-to-panorama-management&lt;/A&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;</description>
      <pubDate>Sun, 08 Dec 2024 03:31:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/panorama-onboarding-and-managing-of-pan-fw-s/m-p/997079#M2675</guid>
      <dc:creator>TomYoung</dc:creator>
      <dc:date>2024-12-08T03:31:36Z</dc:date>
    </item>
    <item>
      <title>Re: Panorama Onboarding and Managing of PAN FW's</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/panorama-onboarding-and-managing-of-pan-fw-s/m-p/997139#M2676</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/77347"&gt;@TomYoung&lt;/a&gt; Thanks for your inputs. Just to clarify Active/Passive firewalls are displaying as Connected, but when I export/pushed config for the passive firewall active firewalls policies was stripped off as well.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I think because we have not disabled config sync for the HA pair.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What would your approach with this if we want to have no downtime?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Currently, On Panorama Active FW is disconnected, Passive FW is connected.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;1. Fix the Connection issues first, can we disassociate the Active Firewall again then continue the steps?&lt;/P&gt;
&lt;P&gt;2. Failover the traffic to the passive firewall? Checking on the Local Firewall GUI HA dashboard all seems to be matched excluding the Configuration which is not sync.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;
&lt;P&gt;Nicko&lt;/P&gt;</description>
      <pubDate>Mon, 09 Dec 2024 04:42:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/panorama-onboarding-and-managing-of-pan-fw-s/m-p/997139#M2676</guid>
      <dc:creator>NickoKristian</dc:creator>
      <dc:date>2024-12-09T04:42:14Z</dc:date>
    </item>
    <item>
      <title>Re: Panorama Onboarding and Managing of PAN FW's</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/panorama-onboarding-and-managing-of-pan-fw-s/m-p/1218987#M2766</link>
      <description>&lt;P&gt;Yes you have to make sure config sync is disabled and also remove the HA configuration from the template and as it a unique value local to the firewall.&lt;/P&gt;
&lt;P&gt;Panorama-&amp;gt; select the Template-&amp;gt; High Availability-&amp;gt; Remove All&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 02 Feb 2025 02:13:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/panorama-onboarding-and-managing-of-pan-fw-s/m-p/1218987#M2766</guid>
      <dc:creator>vivekms</dc:creator>
      <dc:date>2025-02-02T02:13:51Z</dc:date>
    </item>
    <item>
      <title>Re: Panorama Onboarding and Managing of PAN FW's</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/panorama-onboarding-and-managing-of-pan-fw-s/m-p/1219151#M2770</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/1257911573"&gt;@vivekms&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;HA can be pushed from Panorama with template variables.&amp;nbsp; Not a big deal, just an FYI.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;</description>
      <pubDate>Mon, 03 Feb 2025 21:06:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/panorama-onboarding-and-managing-of-pan-fw-s/m-p/1219151#M2770</guid>
      <dc:creator>TomYoung</dc:creator>
      <dc:date>2025-02-03T21:06:43Z</dc:date>
    </item>
  </channel>
</rss>

