<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Network Interface not pushed from Panorama in Panorama Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/panorama-discussions/network-interface-not-pushed-from-panorama/m-p/239265#M429</link>
    <description>&lt;P&gt;The green/yellow gear symbols behind the interface on your firewall screenshot indicates that you have an override active on the firewall. This means that the interface is configured locally and overwrites the config pushed from panorama.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You can disable the override on the firewall itself - there is an option to revert in the task line below the interfaces.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Furthermore you can force template values from panorama - but this will affect all overrides!&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;In both cases be very careful and check that the template configuration on panorama matches the local configuration of ther firewall - or you will run into trouble!&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 09 Nov 2018 10:47:02 GMT</pubDate>
    <dc:creator>AlexSieber</dc:creator>
    <dc:date>2018-11-09T10:47:02Z</dc:date>
    <item>
      <title>Network Interface not pushed from Panorama</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/network-interface-not-pushed-from-panorama/m-p/238999#M426</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We need&amp;nbsp;to add an extra IP Range to route out one of the existing sub interfaces on the Palo Alto firewall.&lt;/P&gt;&lt;P&gt;The change has been committed and pushed in Panorama but is not showing on the firewall.&lt;/P&gt;&lt;P&gt;Both using version 8.1.3&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Firewall network interface:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="FW network interface.jpg" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/17460iC7CEC3588C8BB655/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="FW network interface.jpg" alt="FW network interface.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Panorama network interface with the change circle in red:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Panorama network interface.jpg" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/17461i2A16DECB41F4384D/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Panorama network interface.jpg" alt="Panorama network interface.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;How do we push this change to the firewall or do we have to replicate the change on the firewalls?&lt;/P&gt;&lt;P&gt;Any documentation on this?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advance!&lt;/P&gt;</description>
      <pubDate>Thu, 08 Nov 2018 01:43:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/network-interface-not-pushed-from-panorama/m-p/238999#M426</guid>
      <dc:creator>FarzanaMustafa</dc:creator>
      <dc:date>2018-11-08T01:43:42Z</dc:date>
    </item>
    <item>
      <title>Re: Network Interface not pushed from Panorama</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/network-interface-not-pushed-from-panorama/m-p/239006#M427</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/98673"&gt;@FarzanaMustafa&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;If the commit and push had finished completely are you positive you made the change to the right template?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 08 Nov 2018 02:04:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/network-interface-not-pushed-from-panorama/m-p/239006#M427</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2018-11-08T02:04:05Z</dc:date>
    </item>
    <item>
      <title>Re: Network Interface not pushed from Panorama</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/network-interface-not-pushed-from-panorama/m-p/239064#M428</link>
      <description>&lt;P&gt;I would check that it committed successfully. I remember when I first started using panorama I thought since I did not get an error that it committed and pushed correctly even though if you go in and check it my have failed for some reason.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 08 Nov 2018 13:02:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/network-interface-not-pushed-from-panorama/m-p/239064#M428</guid>
      <dc:creator>dstjames</dc:creator>
      <dc:date>2018-11-08T13:02:37Z</dc:date>
    </item>
    <item>
      <title>Re: Network Interface not pushed from Panorama</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/network-interface-not-pushed-from-panorama/m-p/239265#M429</link>
      <description>&lt;P&gt;The green/yellow gear symbols behind the interface on your firewall screenshot indicates that you have an override active on the firewall. This means that the interface is configured locally and overwrites the config pushed from panorama.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You can disable the override on the firewall itself - there is an option to revert in the task line below the interfaces.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Furthermore you can force template values from panorama - but this will affect all overrides!&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;In both cases be very careful and check that the template configuration on panorama matches the local configuration of ther firewall - or you will run into trouble!&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 09 Nov 2018 10:47:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/network-interface-not-pushed-from-panorama/m-p/239265#M429</guid>
      <dc:creator>AlexSieber</dc:creator>
      <dc:date>2018-11-09T10:47:02Z</dc:date>
    </item>
    <item>
      <title>Re: Network Interface not pushed from Panorama</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/network-interface-not-pushed-from-panorama/m-p/239298#M430</link>
      <description>&lt;P&gt;when you say&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;force template values from panorama - but this will affect all overrides!&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;does you mean this will override any local config on firewall to new values pushed from the panorama?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 09 Nov 2018 15:24:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/network-interface-not-pushed-from-panorama/m-p/239298#M430</guid>
      <dc:creator>MP18</dc:creator>
      <dc:date>2018-11-09T15:24:37Z</dc:date>
    </item>
    <item>
      <title>Re: Network Interface not pushed from Panorama</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/network-interface-not-pushed-from-panorama/m-p/239304#M431</link>
      <description>&lt;P&gt;yes this is the case, any part of local configuration that also exists in the panorama template will be overwritten.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Local configuration parts that do not exist in the template will remain unchanged, they do not get deleted.&lt;/P&gt;</description>
      <pubDate>Fri, 09 Nov 2018 16:08:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/network-interface-not-pushed-from-panorama/m-p/239304#M431</guid>
      <dc:creator>AlexSieber</dc:creator>
      <dc:date>2018-11-09T16:08:35Z</dc:date>
    </item>
    <item>
      <title>Re: Network Interface not pushed from Panorama</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/network-interface-not-pushed-from-panorama/m-p/435643#M432</link>
      <description>&lt;P&gt;...And if none of the above suggestions is your fix, and it's more like you have AE interfaces with subinterfaces, currently overriding Panorama-pushed, and then you are ready to revert those to Panorama-pushed, you may very well end up with an error similar to above... *The undocumented solution is, after verifying that your Panorama version of the interface configs (and corresponding VRs and zones) is correct, to manually delete (via CLI on firewall) the subinterfaces and then the corresponding AE, and then Panorama-pushed will show appear with all green cogs.&lt;/P&gt;</description>
      <pubDate>Wed, 22 Sep 2021 01:21:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/network-interface-not-pushed-from-panorama/m-p/435643#M432</guid>
      <dc:creator>CDCT-Security</dc:creator>
      <dc:date>2021-09-22T01:21:02Z</dc:date>
    </item>
  </channel>
</rss>

