<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Panorama integration in Panorama Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/panorama-discussions/panorama-integration/m-p/442196#M502</link>
    <description>&lt;P&gt;Do we foresee any downtime during taking existing running firewalls behind panorama server? Also what precautions we should consider for such work?&lt;/P&gt;</description>
    <pubDate>Wed, 20 Oct 2021 12:48:55 GMT</pubDate>
    <dc:creator>d.spider</dc:creator>
    <dc:date>2021-10-20T12:48:55Z</dc:date>
    <item>
      <title>Panorama integration</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/panorama-integration/m-p/442196#M502</link>
      <description>&lt;P&gt;Do we foresee any downtime during taking existing running firewalls behind panorama server? Also what precautions we should consider for such work?&lt;/P&gt;</description>
      <pubDate>Wed, 20 Oct 2021 12:48:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/panorama-integration/m-p/442196#M502</guid>
      <dc:creator>d.spider</dc:creator>
      <dc:date>2021-10-20T12:48:55Z</dc:date>
    </item>
    <item>
      <title>Re: Panorama integration</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/panorama-integration/m-p/442209#M503</link>
      <description>&lt;P&gt;Thank you for posting question&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/195649"&gt;@d.spider&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is your question related to migration of a Firewall to be managed by Panorama? If yes, then there should be no down time / outage. If you are looking into importing Firewall configuration into Panorama and pushing Device Group / Template created based in imported configuration, then here is corresponding KB:&amp;nbsp;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClZSCA0" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClZSCA0&lt;/A&gt;&lt;/P&gt;&lt;P&gt;When it comes to precautions, on the top of my head I can think of these points:&lt;/P&gt;&lt;P&gt;- Panorama should be running the same or higher PAN-OS version than Firewall.&lt;/P&gt;&lt;P&gt;- If Firewall is configured for HA refer to this KB:&amp;nbsp;&lt;A href="https://knowledgebase.paloaltonetworks.com/kcsArticleDetail?id=kA10g000000PNG0" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/kcsArticleDetail?id=kA10g000000PNG0&lt;/A&gt;&lt;/P&gt;&lt;P&gt;- If you are going to reuse Device Group that is referring to any built in EDL and push it to Firewall that does not have Threat License, it will fail.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Alternative way to importing configuration to Panorama, would be to create a new Device Group + Template/Template stack, associate Firewall with&amp;nbsp;Device Group and Template Stack and then push the configuration to Firewall. As long as the objects are using unique names and not duplicated with local configuration it will work, however drawback with this approach, ideally you want to clean up local configuration. Also, some of the setting from Template will not be applied unless you select: Force Template Values. Here is corresponding KB:&amp;nbsp;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000PMj1CAG" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000PMj1CAG&lt;/A&gt;&amp;nbsp;This option could be disruptive if not configured properly.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Kind Regards&lt;/P&gt;&lt;P&gt;Pavel&lt;/P&gt;</description>
      <pubDate>Wed, 20 Oct 2021 13:30:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/panorama-integration/m-p/442209#M503</guid>
      <dc:creator>PavelK</dc:creator>
      <dc:date>2021-10-20T13:30:36Z</dc:date>
    </item>
    <item>
      <title>Re: Panorama integration</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/panorama-integration/m-p/442511#M504</link>
      <description>&lt;P&gt;This is really helpful&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 21 Oct 2021 09:32:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/panorama-integration/m-p/442511#M504</guid>
      <dc:creator>d.spider</dc:creator>
      <dc:date>2021-10-21T09:32:42Z</dc:date>
    </item>
  </channel>
</rss>

