<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ZTP Update on 1st Connect Fails with no Threat Protection License in Panorama Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/panorama-discussions/ztp-update-on-1st-connect-fails-with-no-threat-protection/m-p/1000222#M2727</link>
    <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/1516577565"&gt;@K.Saucier&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Q1 - You should be able to stop installing the content by unchecking the option "auto push on 1rst connection".&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Q2 - I would say it depends on the configuration pushed by Panorama. If the configuration has a object which cannot be resolved (because not present on the firewall, for instance an app-id name), it is expected for the commit to fail. Have you disabled the "ms-powerapps" on Panorama? If yes, remove that configuration and that should do the job.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Olivier&lt;/P&gt;</description>
    <pubDate>Tue, 07 Jan 2025 06:19:29 GMT</pubDate>
    <dc:creator>ozheng</dc:creator>
    <dc:date>2025-01-07T06:19:29Z</dc:date>
    <item>
      <title>ZTP Update on 1st Connect Fails with no Threat Protection License</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/ztp-update-on-1st-connect-fails-with-no-threat-protection/m-p/1000183#M2725</link>
      <description>&lt;P&gt;Good morning all,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Relatively new to Palo/Pano so I apologize if this is a completely basic question but search has not turned up much/anything.&amp;nbsp; I'm testing ZTP deploy for a number of new PA-445's.&amp;nbsp; Everything is working as expected so far except for being able to push a PanOS update on 1st connect.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="KSaucier_4-1736176652701.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/65056i048CF029E1B8196C/image-size/medium?v=v2&amp;amp;px=400" role="button" title="KSaucier_4-1736176652701.png" alt="KSaucier_4-1736176652701.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The device connects fine,but seems like it tries to update Applications and Threats DB's as part of the 'Update on 1st connect' process.&amp;nbsp; That A&amp;amp;T update is failing because, seemingly because it's trying to update the panupv2-all-contents DB instead of just the panupv2-all-apps DB and my firewalls don't have a valid Threat Protect license so they can't update the Threat Protect DB&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="KSaucier_0-1736176097078.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/65052i300F1E0334D70E4F/image-size/medium?v=v2&amp;amp;px=400" role="button" title="KSaucier_0-1736176097078.png" alt="KSaucier_0-1736176097078.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I've tried just deleting the all-contents file from Pano but it just comes back (gets redownloaded) on the next update attempt.&amp;nbsp; Pano just repeatedly tried to push the update over and over, seemingly without a way to cancel, until I reset the firewall.&amp;nbsp; I also lose connectivity to the firewall after each push attempt, even though the firewall isn't rebooting.&amp;nbsp; Not sure why that is but it keeps me from being able to connect to the firewall remotely to even try a manual update.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="KSaucier_1-1736176192699.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/65053iBB2722F01F3B981E/image-size/medium?v=v2&amp;amp;px=400" role="button" title="KSaucier_1-1736176192699.png" alt="KSaucier_1-1736176192699.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I tried changing the 445's Template to not have an update schedule for A&amp;amp;T, which seems to have kept it from trying to push the A&amp;amp;T update over and over again.&amp;nbsp; I know that's not a solution so it was a temporary test until I can figure out how to stop the A&amp;amp;T from trying to update the Threat DB as well.&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="KSaucier_2-1736176344297.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/65054i6918A0B3CD33D8A6/image-size/medium?v=v2&amp;amp;px=400" role="button" title="KSaucier_2-1736176344297.png" alt="KSaucier_2-1736176344297.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Unfortunately, it seems that I need an Application update on the new firewall or the commit fails because it can't find one of the new Applications.&amp;nbsp; 🤦‍&lt;span class="lia-unicode-emoji" title=":male_sign:"&gt;♂️&lt;/span&gt;&amp;nbsp; If I manually go and perform a panv2-all-apps update on the firewall itself, this message gets resolved, but I'd really like to resolve it through Pano so I don't need to manually touch the firewall, since I'll be shipping these out to end user sites.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="KSaucier_3-1736176387880.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/65055iD145F4BAAB8E04C2/image-size/medium?v=v2&amp;amp;px=400" role="button" title="KSaucier_3-1736176387880.png" alt="KSaucier_3-1736176387880.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;So, 2 questions:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;1. Is there some way to disable pushing A&amp;amp;T when using 'Auto Push on 1st Connect' or of disabling the Threat portion of the A&amp;amp;T update?&amp;nbsp; None of the firewalls I'm pushing with ZTP will have Threat Protection licenses so this is unnecessary.&amp;nbsp; It's possible there will be firewalls added to Pano later that will have TP licenses so, ideally, I'd rather not globally disable TP updates, but I could do it at the Device Group/Template/Stack level.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;2. Is it common for entire commits to fail because of a missing application?&amp;nbsp; Seems crazy that the whole process just dies because it can't find an application that I'm not even using in a rule.&amp;nbsp; Trying to force the Template Values during commit doesn't help as it still just failed because ms-powerapps is missing.&amp;nbsp; It seems the only way around this is to directly access the firewall and update the apps package, but I can't even do that at the moment because it's still in ZTP mode because it can't finish the commit.&amp;nbsp; 🤦‍&lt;span class="lia-unicode-emoji" title=":male_sign:"&gt;♂️&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Any help or pointers for the FNG would be much appreciated.&amp;nbsp; Thanks!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 06 Jan 2025 15:26:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/ztp-update-on-1st-connect-fails-with-no-threat-protection/m-p/1000183#M2725</guid>
      <dc:creator>K.Saucier</dc:creator>
      <dc:date>2025-01-06T15:26:21Z</dc:date>
    </item>
    <item>
      <title>Re: ZTP Update on 1st Connect Fails with no Threat Protection License</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/ztp-update-on-1st-connect-fails-with-no-threat-protection/m-p/1000222#M2727</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/1516577565"&gt;@K.Saucier&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Q1 - You should be able to stop installing the content by unchecking the option "auto push on 1rst connection".&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Q2 - I would say it depends on the configuration pushed by Panorama. If the configuration has a object which cannot be resolved (because not present on the firewall, for instance an app-id name), it is expected for the commit to fail. Have you disabled the "ms-powerapps" on Panorama? If yes, remove that configuration and that should do the job.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Olivier&lt;/P&gt;</description>
      <pubDate>Tue, 07 Jan 2025 06:19:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/ztp-update-on-1st-connect-fails-with-no-threat-protection/m-p/1000222#M2727</guid>
      <dc:creator>ozheng</dc:creator>
      <dc:date>2025-01-07T06:19:29Z</dc:date>
    </item>
    <item>
      <title>Re: ZTP Update on 1st Connect Fails with no Threat Protection License</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/ztp-update-on-1st-connect-fails-with-no-threat-protection/m-p/1000275#M2730</link>
      <description>&lt;P&gt;Thanks for the reply.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Q1:&amp;nbsp; Yes, I can uncheck that, but then it won't automatically update the firmware.&amp;nbsp; I want the firewall to be fully updated upon deployment (some of these firewalls will sit in storage for a few months before deployment) and it seems like the firewall or Pano should be smart enough to not try to install content that isn't licensed but that doesn't seem to be the case.&amp;nbsp; I figured maybe I was missing a setting to tell the Template that Threat Protection was not enabled but I feel like I have looked at every setting in Pano and I haven't found anything.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Q2:&amp;nbsp; ms-powerapps exists in the Pano Template but I have not changed anything with it.&amp;nbsp; I did try disabling it to see if it made a difference but it doesn't.&amp;nbsp; I thought the orange cog on the entry might have meant something but a bunch of other apps have the same indicator so I guess not.&amp;nbsp; If I could get the Threat Protection to stop trying to install non-licensed software, I think this issue would resolved itself as it would be able to update the application data and commit.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="KSaucier_0-1736259625629.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/65076i1795539B3DB8633A/image-size/medium?v=v2&amp;amp;px=400" role="button" title="KSaucier_0-1736259625629.png" alt="KSaucier_0-1736259625629.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 07 Jan 2025 14:23:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/ztp-update-on-1st-connect-fails-with-no-threat-protection/m-p/1000275#M2730</guid>
      <dc:creator>K.Saucier</dc:creator>
      <dc:date>2025-01-07T14:23:20Z</dc:date>
    </item>
    <item>
      <title>Re: ZTP Update on 1st Connect Fails with no Threat Protection License</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/ztp-update-on-1st-connect-fails-with-no-threat-protection/m-p/1000314#M2732</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/1516577565"&gt;@K.Saucier&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I guess the best course of action is to open a case to TAC to investigate why it tries to push apps-and-threats instead of apps-only content.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Olivier&lt;/P&gt;</description>
      <pubDate>Wed, 08 Jan 2025 01:25:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/ztp-update-on-1st-connect-fails-with-no-threat-protection/m-p/1000314#M2732</guid>
      <dc:creator>ozheng</dc:creator>
      <dc:date>2025-01-08T01:25:26Z</dc:date>
    </item>
  </channel>
</rss>

