<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Automate Firewall Policies and Objects in Automation/API Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/automation-api-discussions/automate-firewall-policies-and-objects/m-p/533851#M3326</link>
    <description>&lt;P&gt;Thanks&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/124057"&gt;@SimonT&lt;/a&gt;. Any experience with it in terms of playbooks?&lt;/P&gt;</description>
    <pubDate>Thu, 09 Mar 2023 21:33:25 GMT</pubDate>
    <dc:creator>Tobi_Babatunde</dc:creator>
    <dc:date>2023-03-09T21:33:25Z</dc:date>
    <item>
      <title>Automate Firewall Policies and Objects</title>
      <link>https://live.paloaltonetworks.com/t5/automation-api-discussions/automate-firewall-policies-and-objects/m-p/532147#M3317</link>
      <description>&lt;P&gt;Hello Everyone,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have a bunch of Palos been centrally managed by Panorama. I am about to embark on an automation journey - more interested in configuration management. I am interested to know what the best practices are and how the community got started on their journey.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Presently use dynamic objects and tags on my configuration, and push all rules via my Panorama.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What are the best practices for the automation journey? How do I ingest all my present rulesets and objects et al to the configuration management tool?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 24 Feb 2023 00:48:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/automation-api-discussions/automate-firewall-policies-and-objects/m-p/532147#M3317</guid>
      <dc:creator>Tobi_Babatunde</dc:creator>
      <dc:date>2023-02-24T00:48:36Z</dc:date>
    </item>
    <item>
      <title>Re: Automate Firewall Policies and Objects</title>
      <link>https://live.paloaltonetworks.com/t5/automation-api-discussions/automate-firewall-policies-and-objects/m-p/532791#M3323</link>
      <description>&lt;P&gt;Having successfully used direct API, pandevice and pan-os python modules for some years I would in your case recommend the pan-ansible modules:&amp;nbsp;&lt;A href="https://ansible-pan.readthedocs.io/en/latest/" target="_blank"&gt;https://ansible-pan.readthedocs.io/en/latest/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Ansible itself handles any workflow and the modules handle all the parsing etc. Does exactly what you need.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 01 Mar 2023 23:48:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/automation-api-discussions/automate-firewall-policies-and-objects/m-p/532791#M3323</guid>
      <dc:creator>SimonT</dc:creator>
      <dc:date>2023-03-01T23:48:39Z</dc:date>
    </item>
    <item>
      <title>Re: Automate Firewall Policies and Objects</title>
      <link>https://live.paloaltonetworks.com/t5/automation-api-discussions/automate-firewall-policies-and-objects/m-p/533851#M3326</link>
      <description>&lt;P&gt;Thanks&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/124057"&gt;@SimonT&lt;/a&gt;. Any experience with it in terms of playbooks?&lt;/P&gt;</description>
      <pubDate>Thu, 09 Mar 2023 21:33:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/automation-api-discussions/automate-firewall-policies-and-objects/m-p/533851#M3326</guid>
      <dc:creator>Tobi_Babatunde</dc:creator>
      <dc:date>2023-03-09T21:33:25Z</dc:date>
    </item>
    <item>
      <title>Re: Automate Firewall Policies and Objects</title>
      <link>https://live.paloaltonetworks.com/t5/automation-api-discussions/automate-firewall-policies-and-objects/m-p/533853#M3327</link>
      <description>&lt;P&gt;I'm sure you read the documentation (&lt;A href="https://github.com/PaloAltoNetworks/pan-os-ansible" target="_blank"&gt;https://github.com/PaloAltoNetworks/pan-os-ansible&lt;/A&gt;) but in case not there are links to sample playbooks&amp;nbsp;&lt;A href="https://github.com/PaloAltoNetworks/ansible-playbooks" target="_blank"&gt;https://github.com/PaloAltoNetworks/ansible-playbooks&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 09 Mar 2023 21:39:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/automation-api-discussions/automate-firewall-policies-and-objects/m-p/533853#M3327</guid>
      <dc:creator>SimonT</dc:creator>
      <dc:date>2023-03-09T21:39:07Z</dc:date>
    </item>
    <item>
      <title>Re: Automate Firewall Policies and Objects</title>
      <link>https://live.paloaltonetworks.com/t5/automation-api-discussions/automate-firewall-policies-and-objects/m-p/533857#M3328</link>
      <description>&lt;P&gt;I sure did. But those look like basic implementations. I was hoping to see things around real world complex scenarios and also integrations to accept inputs from users which gets checked et al.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But it is a good start.&lt;/P&gt;</description>
      <pubDate>Thu, 09 Mar 2023 21:49:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/automation-api-discussions/automate-firewall-policies-and-objects/m-p/533857#M3328</guid>
      <dc:creator>Tobi_Babatunde</dc:creator>
      <dc:date>2023-03-09T21:49:09Z</dc:date>
    </item>
    <item>
      <title>Re: Automate Firewall Policies and Objects</title>
      <link>https://live.paloaltonetworks.com/t5/automation-api-discussions/automate-firewall-policies-and-objects/m-p/533864#M3329</link>
      <description>&lt;P&gt;A lot of functionality is provided by ansible-pan so its just a case of mapping your requirements to your own playbook (which you can build by cribbing the examples). Start basic. Any data integrity checking can all be done using Ansible built-in modules. Its 100% real world. Perhaps start with a CLI based tool and develop a front end solution later. If you are focusing on configuration management one option might be to store your "standard configuration" as YAML/Jinja2 format in a GitHub repository (you get free version control) and have your tool draw down from that to compare with your actual configurations. Then act on any deficiencies and email a status report. Having said that, check out AIOps&amp;nbsp;&lt;A href="https://www.paloaltonetworks.com/network-security/aiops-for-ngfw" target="_blank"&gt;https://www.paloaltonetworks.com/network-security/aiops-for-ngfw&lt;/A&gt;. It might do some of what you need.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 09 Mar 2023 22:26:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/automation-api-discussions/automate-firewall-policies-and-objects/m-p/533864#M3329</guid>
      <dc:creator>SimonT</dc:creator>
      <dc:date>2023-03-09T22:26:35Z</dc:date>
    </item>
  </channel>
</rss>

