<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Panorama import local managed device issue in Panorama Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/panorama-discussions/panorama-import-local-managed-device-issue/m-p/441023#M493</link>
    <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;P&gt;I added a PA to panorama test lab with version 9.1.11 them import configuration. However I am unable to push config from panorama to PA and I found below errors which showing customized application is in use, then I need to delete many objects and policies on PA firewall to push configuration. I want to know is it a normal practice for Panorama to manage production PA in the first time? Many thanks!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Details:&lt;BR /&gt;.&amp;nbsp;Validation Error:&lt;BR /&gt;.&amp;nbsp;application -&amp;gt; Custom-IE 'Custom-IE' is already in use&lt;BR /&gt;.&amp;nbsp;application is invalid&lt;BR /&gt;.&amp;nbsp;Error: Profile compile error, duplicated name Block files&lt;BR /&gt;.&amp;nbsp;Error: Profile compiler : Block files invalid type 5&lt;BR /&gt;.&amp;nbsp;Error: Profile compiler : invalid profile name Block files&lt;BR /&gt;.&amp;nbsp;Error: Profile compiler : Vsys section error&lt;BR /&gt;.&amp;nbsp;Error: Profile compiler : parsing config error&lt;BR /&gt;.&amp;nbsp;(Module: device)&lt;BR /&gt;.&amp;nbsp;Commit failed&lt;BR /&gt;&amp;nbsp;&lt;/P&gt;&lt;/DIV&gt;&lt;/DIV&gt;</description>
    <pubDate>Fri, 15 Oct 2021 05:41:08 GMT</pubDate>
    <dc:creator>TonyTam</dc:creator>
    <dc:date>2021-10-15T05:41:08Z</dc:date>
    <item>
      <title>Panorama import local managed device issue</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/panorama-import-local-managed-device-issue/m-p/441023#M493</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;P&gt;I added a PA to panorama test lab with version 9.1.11 them import configuration. However I am unable to push config from panorama to PA and I found below errors which showing customized application is in use, then I need to delete many objects and policies on PA firewall to push configuration. I want to know is it a normal practice for Panorama to manage production PA in the first time? Many thanks!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Details:&lt;BR /&gt;.&amp;nbsp;Validation Error:&lt;BR /&gt;.&amp;nbsp;application -&amp;gt; Custom-IE 'Custom-IE' is already in use&lt;BR /&gt;.&amp;nbsp;application is invalid&lt;BR /&gt;.&amp;nbsp;Error: Profile compile error, duplicated name Block files&lt;BR /&gt;.&amp;nbsp;Error: Profile compiler : Block files invalid type 5&lt;BR /&gt;.&amp;nbsp;Error: Profile compiler : invalid profile name Block files&lt;BR /&gt;.&amp;nbsp;Error: Profile compiler : Vsys section error&lt;BR /&gt;.&amp;nbsp;Error: Profile compiler : parsing config error&lt;BR /&gt;.&amp;nbsp;(Module: device)&lt;BR /&gt;.&amp;nbsp;Commit failed&lt;BR /&gt;&amp;nbsp;&lt;/P&gt;&lt;/DIV&gt;&lt;/DIV&gt;</description>
      <pubDate>Fri, 15 Oct 2021 05:41:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/panorama-import-local-managed-device-issue/m-p/441023#M493</guid>
      <dc:creator>TonyTam</dc:creator>
      <dc:date>2021-10-15T05:41:08Z</dc:date>
    </item>
    <item>
      <title>Re: Panorama import local managed device issue</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/panorama-import-local-managed-device-issue/m-p/441032#M494</link>
      <description>&lt;P&gt;Thank you for posting question&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/194631"&gt;@TonyTam&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regarding the error you posted, you will have to resolve it first before you can push the configuration back to Firewall. Unfortunately there is no other way around except deleting it or renaming.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I can't really say what the best practice is, but there are only 2 options.&lt;/P&gt;&lt;P&gt;Either onboard new Firewall. Here is corresponding Best Practice Link:&amp;nbsp;&lt;A href="https://docs.paloaltonetworks.com/best-practices/10-1/best-practices-for-managing-firewalls-with-panorama/adding-firewalls-to-panorama/use-case-onboarding-new-next-generation-firewalls-to-panorama.html" target="_blank"&gt;https://docs.paloaltonetworks.com/best-practices/10-1/best-practices-for-managing-firewalls-with-panorama/adding-firewalls-to-panorama/use-case-onboarding-new-next-generation-firewalls-to-panorama.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Or migrate existing Firewall by importing configuration to Panorama and pushing it back to Firewall. Here is corresponding Best Practice:&amp;nbsp;&lt;A href="https://docs.paloaltonetworks.com/best-practices/10-1/best-practices-for-managing-firewalls-with-panorama/adding-firewalls-to-panorama/use-case-migrate-your-next-generation-firewalls-to-panorama.html#id50db55bc-c363-4194-b1bf-e22c50f6ae99" target="_blank"&gt;https://docs.paloaltonetworks.com/best-practices/10-1/best-practices-for-managing-firewalls-with-panorama/adding-firewalls-to-panorama/use-case-migrate-your-next-generation-firewalls-to-panorama.html#id50db55bc-c363-4194-b1bf-e22c50f6ae99&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In my case when we deployed Panorama we already had several Firewalls deployed in production and despite the fact there was an option to migrate Firewall to Panorama by importing configuration, I opted for onboarding it as a new Firewall then I pushed all the configuration from Device Group and Template Stack and deleted all local configuration as far as I could. What I personally did not like about importing existing configuration were 2 things:&lt;/P&gt;&lt;P&gt;- Local configuration was already messy and not following any convention, so I did not want to import messy configuration and turn it into Device Group/Template.&lt;/P&gt;&lt;P&gt;- I wanted to avoid issue you posted here that by importing I need to resolve several issue first. Also, I was afraid of merging of config and forcing of Template Values especially for critical Firewalls.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;By pushing new configuration by Panorama with different naming convention than local configuration has avoided any configuration duplication. This approach has still several disadvantages. It is time consuming to clean up all local configuration and unless I select: "Force Template Values" most of the configuration is pushed but not applied unless I override it and commit it locally. At this moment I have under Panorama over 150+ Firewalls and I used the same approach regardless it is brand new device or existing one that I turned into Panorama managed. We have decided not to use Panorama for interface configuration and routing. This is what we manage locally as we would like to have more control and avoid operational mistakes by pushing something centrally that will break control plane.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you have greenfield deployment I would leverage Panorama as much as you can. Unless you are concerned about some of the points I mentioned I do not discourage you to use import of local configuration to Panorama and pushing it back. I know many admins that use it successfully in their deployments.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Kind Regards&lt;/P&gt;&lt;P&gt;Pavel&lt;/P&gt;</description>
      <pubDate>Fri, 15 Oct 2021 07:09:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/panorama-import-local-managed-device-issue/m-p/441032#M494</guid>
      <dc:creator>PavelK</dc:creator>
      <dc:date>2021-10-15T07:09:26Z</dc:date>
    </item>
    <item>
      <title>Re: Panorama import local managed device issue</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/panorama-import-local-managed-device-issue/m-p/441050#M495</link>
      <description>&lt;P&gt;Thanks for your suggestion.&lt;/P&gt;&lt;P&gt;According to below KB,&amp;nbsp;I found that I miss the important part "Export or push device config bundle".&lt;/P&gt;&lt;P&gt;Seems the most convenient method to delete all local configuration when pushing.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000CloRCAS" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000CloRCAS&lt;/A&gt;&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Push the device configuration bundle to the firewall to remove all policies and objects from the local configuration.&amp;nbsp;&lt;SPAN&gt;Go to Panorama &amp;gt; Setup &amp;gt; Operations&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;and click '&lt;/SPAN&gt;&lt;SPAN&gt;Export or push device config bundle'&lt;/SPAN&gt;&lt;SPAN&gt;.&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;Select the&amp;nbsp;&lt;/SPAN&gt;Device&lt;SPAN&gt;&amp;nbsp;from which you imported the configuration, click&amp;nbsp;&lt;/SPAN&gt;OK&lt;SPAN&gt;, and click&amp;nbsp;&lt;/SPAN&gt;Push &amp;amp; Commit&lt;SPAN&gt;.&lt;/SPAN&gt;&lt;/LI&gt;&lt;/OL&gt;</description>
      <pubDate>Fri, 15 Oct 2021 08:12:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/panorama-import-local-managed-device-issue/m-p/441050#M495</guid>
      <dc:creator>TonyTam</dc:creator>
      <dc:date>2021-10-15T08:12:40Z</dc:date>
    </item>
    <item>
      <title>Re: Panorama import local managed device issue</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/panorama-import-local-managed-device-issue/m-p/446537#M519</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/194631"&gt;@TonyTam&lt;/a&gt; is correct.&amp;nbsp; When you initially import a firewall configuration into Panorama, you need to "Export or push device config bundle" to remove the local configuration and replace with Panorama configuration.&amp;nbsp; If you try Commit &amp;gt; Push to Devices you will get the "already in use" or "duplicated name" errors.&amp;nbsp; You only have to do it once, and then you can manage from Panorama normally.&lt;/P&gt;</description>
      <pubDate>Tue, 09 Nov 2021 17:17:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/panorama-import-local-managed-device-issue/m-p/446537#M519</guid>
      <dc:creator>TomYoung</dc:creator>
      <dc:date>2021-11-09T17:17:02Z</dc:date>
    </item>
    <item>
      <title>Re: Panorama import local managed device issue</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/panorama-import-local-managed-device-issue/m-p/584678#M2304</link>
      <description>&lt;P&gt;Thank you for the detailed explanations,&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/192693"&gt;@PavelK&lt;/a&gt;&amp;nbsp;and&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/77347"&gt;@TomYoung&lt;/a&gt;&amp;nbsp;we ran into plenty of conflicts onboarding firewalls that were already part of our infrastructure. I have found that not moving the firewall from the DG and Template it creates until the config package has been successfully pushed helps minimize conflicts. I also found that sometimes the error output will flag items that are clearly in the configuration in Panorama but are not being recognized by the firewall during the push. No other solution has worked besides re-adding the object locally on the firewall and then committing the config locally as well. After that the commit succeeds and the device can be moved to the preferred DG and template stack. Hope this helps anyone else who runs into this.&lt;/P&gt;</description>
      <pubDate>Tue, 23 Apr 2024 20:25:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/panorama-import-local-managed-device-issue/m-p/584678#M2304</guid>
      <dc:creator>RodyDeLaRosa</dc:creator>
      <dc:date>2024-04-23T20:25:22Z</dc:date>
    </item>
  </channel>
</rss>

