<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Panorama not show rules shadow in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/panorama-not-show-rules-shadow/m-p/451093#M101115</link>
    <description>&lt;P&gt;Thank you for reply&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/192671"&gt;@Alpalo&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Do you mean you imported local Firewall configuration into Panorama and pushed it back to Firewall from Device Group?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Kind Regards&lt;/P&gt;&lt;P&gt;Pavel&lt;/P&gt;</description>
    <pubDate>Thu, 02 Dec 2021 22:06:00 GMT</pubDate>
    <dc:creator>PavelK</dc:creator>
    <dc:date>2021-12-02T22:06:00Z</dc:date>
    <item>
      <title>Panorama not show rules shadow</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/panorama-not-show-rules-shadow/m-p/449956#M100991</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I have several devices managed from Panorama. All in version 9.1.7 .&lt;/P&gt;&lt;P&gt;When I commit from the team it shows the rules shadow warnings but when I do the same from the panorama it is not shown.&lt;/P&gt;&lt;P&gt;Does anyone know the reason for this?&lt;/P&gt;&lt;P&gt;Is it possible to see the shading rules from panorama?&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;</description>
      <pubDate>Mon, 29 Nov 2021 11:54:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/panorama-not-show-rules-shadow/m-p/449956#M100991</guid>
      <dc:creator>Alpalo</dc:creator>
      <dc:date>2021-11-29T11:54:36Z</dc:date>
    </item>
    <item>
      <title>Re: Panorama not show rules shadow</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/panorama-not-show-rules-shadow/m-p/450241#M101018</link>
      <description>&lt;P&gt;Thank you for posting question&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/192671"&gt;@Alpalo&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I believe the reason why you are not seeing a shadow rule warning while committing Panorama configuration is the fact that you are committing rules that are being pushed by Panorama and within those rules you do not have any shadow rules, however while committing local Firewall configuration you are seeing shadow rules that were locally configured. Since, Panorama does not own and manage locally configured rules, you will not see that warning from Panorama.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I can't think of a way to get that view of shadow rules from Panorama other than going to: Device Group &amp;gt; Security &amp;gt; Preview Rules &amp;gt; Rule Base: Security, then select Device Group and Device, then you will get a view of all the rules (pushed by Panorama and local). You can refer to rule usage, to see rules that are not getting hit.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;An alternative, could be a 3rd party tool for example Firemon to detect redundant/unnecessary rules, but this is far off the topic.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Kind Regards&lt;/P&gt;&lt;P&gt;Pavel&lt;/P&gt;</description>
      <pubDate>Tue, 30 Nov 2021 00:06:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/panorama-not-show-rules-shadow/m-p/450241#M101018</guid>
      <dc:creator>PavelK</dc:creator>
      <dc:date>2021-11-30T00:06:02Z</dc:date>
    </item>
    <item>
      <title>Re: Panorama not show rules shadow</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/panorama-not-show-rules-shadow/m-p/450980#M101100</link>
      <description>&lt;P&gt;All rules are being transferred from Panorama and loaded in FW in volatile. In local, with some exception there are no rules at all.&lt;/P&gt;&lt;P&gt;Any idea?&lt;/P&gt;&lt;P&gt;Thanks so much&lt;/P&gt;</description>
      <pubDate>Thu, 02 Dec 2021 15:27:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/panorama-not-show-rules-shadow/m-p/450980#M101100</guid>
      <dc:creator>Alpalo</dc:creator>
      <dc:date>2021-12-02T15:27:47Z</dc:date>
    </item>
    <item>
      <title>Re: Panorama not show rules shadow</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/panorama-not-show-rules-shadow/m-p/451093#M101115</link>
      <description>&lt;P&gt;Thank you for reply&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/192671"&gt;@Alpalo&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Do you mean you imported local Firewall configuration into Panorama and pushed it back to Firewall from Device Group?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Kind Regards&lt;/P&gt;&lt;P&gt;Pavel&lt;/P&gt;</description>
      <pubDate>Thu, 02 Dec 2021 22:06:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/panorama-not-show-rules-shadow/m-p/451093#M101115</guid>
      <dc:creator>PavelK</dc:creator>
      <dc:date>2021-12-02T22:06:00Z</dc:date>
    </item>
    <item>
      <title>Re: Panorama not show rules shadow</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/panorama-not-show-rules-shadow/m-p/451168#M101124</link>
      <description>&lt;P&gt;No, the configuration is pushed from the panorama.&lt;/P&gt;</description>
      <pubDate>Fri, 03 Dec 2021 08:00:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/panorama-not-show-rules-shadow/m-p/451168#M101124</guid>
      <dc:creator>Alpalo</dc:creator>
      <dc:date>2021-12-03T08:00:30Z</dc:date>
    </item>
  </channel>
</rss>

