<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic NGFW Local Config Audits with SCM in Strata Cloud Manager</title>
    <link>https://live.paloaltonetworks.com/t5/strata-cloud-manager/ngfw-local-config-audits-with-scm/m-p/1223832#M5</link>
    <description>&lt;P&gt;&lt;STRONG&gt;How to identify local configuration changes on NGFW’s managed by SCM&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;First log into SCM and then navigate to the “Manage&amp;gt;Configuration&amp;gt;NGFW and Prisma Access” tabs.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Now click on the “Configuration Scope” and find the folders for the firewalls or firewall you want to look at.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="SCM1.png" style="width: 278px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/66635i05EB1249F9FF5AB6/image-size/large?v=v2&amp;amp;px=999" role="button" title="SCM1.png" alt="SCM1.png" /&gt;&lt;/span&gt;&lt;/STRONG&gt;&lt;STRONG&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="SCM2.png" style="width: 250px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/66636i6F8FA536B87DA157/image-size/large?v=v2&amp;amp;px=999" role="button" title="SCM2.png" alt="SCM2.png" /&gt;&lt;/span&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Now that you are in the configuration scope of “All Firewalls”, make sure you are on the overview tab.&amp;nbsp; You will now see any conflicts under “Variables”.&amp;nbsp; Any firewalls with a conflict will show with a link “View Conflicts”.&amp;nbsp; Click on the link. &lt;/SPAN&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="SCM3.png" style="width: 841px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/66637iB4293FBAB73DEA74/image-size/large?v=v2&amp;amp;px=999" role="button" title="SCM3.png" alt="SCM3.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;This will bring you to all the firewalls with a conflict.&amp;nbsp; You can also see how many conflicts and their locations.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Click on a firewall to view the conflicts.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="SCM4.png" style="width: 761px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/66638i5936A6B66EEA8235/image-size/large?v=v2&amp;amp;px=999" role="button" title="SCM4.png" alt="SCM4.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;On this firewall I can see there are conflicts in the objects in the general and services configurations.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="SCM5.png" style="width: 831px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/66640iFFCA9D5C2A15C046/image-size/large?v=v2&amp;amp;px=999" role="button" title="SCM5.png" alt="SCM5.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;When you click on the link to the conflict it will bring you to that part of the configuration.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;In this example it takes me to the Device Setup tab.&amp;nbsp; I can see the configuration on the General Settings tab and Services tab show a conflict with the local device configs.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="SCM6.png" style="width: 759px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/66639iAE6FEF0905485D48/image-size/large?v=v2&amp;amp;px=999" role="button" title="SCM6.png" alt="SCM6.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;By clicking on the “Show Config Diff” I can see what is configured on the local device versus SCM.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="scm7.png" style="width: 704px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/66641i9D9BB40EEFD5A06A/image-size/large?v=v2&amp;amp;px=999" role="button" title="scm7.png" alt="scm7.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;This allows you to identify what has been changed and whether or not it needs to be done from SCM.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;On the next firewall it shows a conflict with an ethernet port and that it has been overwritten on the local configuration.&amp;nbsp; By clicking on the link it will take you into the configuration.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="scm8.png" style="width: 842px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/66651iEF554539567C0DE3/image-size/large?v=v2&amp;amp;px=999" role="button" title="scm8.png" alt="scm8.png" /&gt;&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;On the top of the configuration you will see an option to “Show local device configs”.&amp;nbsp; By sliding the option over you can see what is configured locally.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="scm9.png" style="width: 839px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/66652iDB6F3F00CD6A329A/image-size/large?v=v2&amp;amp;px=999" role="button" title="scm9.png" alt="scm9.png" /&gt;&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;You can also use the “Show Config Diff” like before to see the difference in the local versus SCM pushed configuration.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="scm10.png" style="width: 840px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/66653i0AA666AD01E043A8/image-size/large?v=v2&amp;amp;px=999" role="button" title="scm10.png" alt="scm10.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 13 Mar 2025 23:06:48 GMT</pubDate>
    <dc:creator>nayubi</dc:creator>
    <dc:date>2025-03-13T23:06:48Z</dc:date>
    <item>
      <title>NGFW Local Config Audits with SCM</title>
      <link>https://live.paloaltonetworks.com/t5/strata-cloud-manager/ngfw-local-config-audits-with-scm/m-p/1223832#M5</link>
      <description>&lt;P&gt;&lt;STRONG&gt;How to identify local configuration changes on NGFW’s managed by SCM&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;First log into SCM and then navigate to the “Manage&amp;gt;Configuration&amp;gt;NGFW and Prisma Access” tabs.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Now click on the “Configuration Scope” and find the folders for the firewalls or firewall you want to look at.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="SCM1.png" style="width: 278px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/66635i05EB1249F9FF5AB6/image-size/large?v=v2&amp;amp;px=999" role="button" title="SCM1.png" alt="SCM1.png" /&gt;&lt;/span&gt;&lt;/STRONG&gt;&lt;STRONG&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="SCM2.png" style="width: 250px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/66636i6F8FA536B87DA157/image-size/large?v=v2&amp;amp;px=999" role="button" title="SCM2.png" alt="SCM2.png" /&gt;&lt;/span&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Now that you are in the configuration scope of “All Firewalls”, make sure you are on the overview tab.&amp;nbsp; You will now see any conflicts under “Variables”.&amp;nbsp; Any firewalls with a conflict will show with a link “View Conflicts”.&amp;nbsp; Click on the link. &lt;/SPAN&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="SCM3.png" style="width: 841px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/66637iB4293FBAB73DEA74/image-size/large?v=v2&amp;amp;px=999" role="button" title="SCM3.png" alt="SCM3.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;This will bring you to all the firewalls with a conflict.&amp;nbsp; You can also see how many conflicts and their locations.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Click on a firewall to view the conflicts.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="SCM4.png" style="width: 761px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/66638i5936A6B66EEA8235/image-size/large?v=v2&amp;amp;px=999" role="button" title="SCM4.png" alt="SCM4.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;On this firewall I can see there are conflicts in the objects in the general and services configurations.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="SCM5.png" style="width: 831px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/66640iFFCA9D5C2A15C046/image-size/large?v=v2&amp;amp;px=999" role="button" title="SCM5.png" alt="SCM5.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;When you click on the link to the conflict it will bring you to that part of the configuration.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;In this example it takes me to the Device Setup tab.&amp;nbsp; I can see the configuration on the General Settings tab and Services tab show a conflict with the local device configs.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="SCM6.png" style="width: 759px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/66639iAE6FEF0905485D48/image-size/large?v=v2&amp;amp;px=999" role="button" title="SCM6.png" alt="SCM6.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;By clicking on the “Show Config Diff” I can see what is configured on the local device versus SCM.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="scm7.png" style="width: 704px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/66641i9D9BB40EEFD5A06A/image-size/large?v=v2&amp;amp;px=999" role="button" title="scm7.png" alt="scm7.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;This allows you to identify what has been changed and whether or not it needs to be done from SCM.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;On the next firewall it shows a conflict with an ethernet port and that it has been overwritten on the local configuration.&amp;nbsp; By clicking on the link it will take you into the configuration.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="scm8.png" style="width: 842px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/66651iEF554539567C0DE3/image-size/large?v=v2&amp;amp;px=999" role="button" title="scm8.png" alt="scm8.png" /&gt;&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;On the top of the configuration you will see an option to “Show local device configs”.&amp;nbsp; By sliding the option over you can see what is configured locally.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="scm9.png" style="width: 839px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/66652iDB6F3F00CD6A329A/image-size/large?v=v2&amp;amp;px=999" role="button" title="scm9.png" alt="scm9.png" /&gt;&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;You can also use the “Show Config Diff” like before to see the difference in the local versus SCM pushed configuration.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="scm10.png" style="width: 840px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/66653i0AA666AD01E043A8/image-size/large?v=v2&amp;amp;px=999" role="button" title="scm10.png" alt="scm10.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 13 Mar 2025 23:06:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/strata-cloud-manager/ngfw-local-config-audits-with-scm/m-p/1223832#M5</guid>
      <dc:creator>nayubi</dc:creator>
      <dc:date>2025-03-13T23:06:48Z</dc:date>
    </item>
  </channel>
</rss>

