<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Suggestion on Initial Configuration of Palo-Alto in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/suggestion-on-initial-configuration-of-palo-alto/m-p/522852#M108313</link>
    <description>&lt;P&gt;day1 is intended to be the very first config you put on a device so you have a good baseline of preconfigured security profiles and security settings.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;a good way to integrate it into panorama would be to import it and set it as a shared template / shared device group objects so it can permeate into your other firewalls&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;your use case will be somewhat difficult as you already have a config in panorama which will overwrite or ignore the (local) day1 config. if you want to use day1, it is best to also import that into panorama and merge both configurations&lt;/P&gt;</description>
    <pubDate>Wed, 30 Nov 2022 09:55:54 GMT</pubDate>
    <dc:creator>reaper</dc:creator>
    <dc:date>2022-11-30T09:55:54Z</dc:date>
    <item>
      <title>Suggestion on Initial Configuration of Palo-Alto</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/suggestion-on-initial-configuration-of-palo-alto/m-p/514163#M106918</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;
&lt;P&gt;We would be needing suggestion on the below scenario:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We are having an new Palo-Alto firewall connected via management console in our data center which is integrated with Panorama and we have pre-configured the box by pushing the templates available in panorama. Now we are moving the box to the&amp;nbsp; location and mounting it and planning to perform initial configurations by connecting the firewall to the actual network. Our client suggested to upload the DAy-1 configuration&amp;nbsp; file to the palo-Alto firewall while assigning the mgmt IP to the firewall.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Query is:&lt;/P&gt;
&lt;P&gt;1. Is the above condition will works ? If yes, will both our pre-configured configurations and Day-1 configuration will be present in our firewall ?&lt;/P&gt;
&lt;P&gt;2. will the day-1 configurations will be local to firewall and if yes,&amp;nbsp; is there any way to manage it via Panorama.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 07 Sep 2022 14:41:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/suggestion-on-initial-configuration-of-palo-alto/m-p/514163#M106918</guid>
      <dc:creator>Sujanya</dc:creator>
      <dc:date>2022-09-07T14:41:03Z</dc:date>
    </item>
    <item>
      <title>Re: Suggestion on Initial Configuration of Palo-Alto</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/suggestion-on-initial-configuration-of-palo-alto/m-p/522852#M108313</link>
      <description>&lt;P&gt;day1 is intended to be the very first config you put on a device so you have a good baseline of preconfigured security profiles and security settings.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;a good way to integrate it into panorama would be to import it and set it as a shared template / shared device group objects so it can permeate into your other firewalls&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;your use case will be somewhat difficult as you already have a config in panorama which will overwrite or ignore the (local) day1 config. if you want to use day1, it is best to also import that into panorama and merge both configurations&lt;/P&gt;</description>
      <pubDate>Wed, 30 Nov 2022 09:55:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/suggestion-on-initial-configuration-of-palo-alto/m-p/522852#M108313</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2022-11-30T09:55:54Z</dc:date>
    </item>
    <item>
      <title>Re: Suggestion on Initial Configuration of Palo-Alto</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/suggestion-on-initial-configuration-of-palo-alto/m-p/522869#M108316</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/216045"&gt;@Sujanya&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/7608"&gt;@reaper&lt;/a&gt; is correct that ideally the Day 1 Configuration is for Day 1, but it is good to try to add them later rather than never.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you load the Day 1 Configuration on the NGFW and then add it to the appropriate device group and template stack in Panorama:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;The above configuration will work.&lt;/LI&gt;
&lt;LI&gt;The Day 1 Configuration will be local to the firewall.
&lt;OL class="lia-list-style-type-lower-alpha"&gt;
&lt;LI&gt;If you have duplicate policies or objects, you will get an error.&amp;nbsp; This is unlikely unless you have configured some Day 1 items before.&lt;/LI&gt;
&lt;LI&gt;Network or device configurations will not be overwritten unless you select Force Template Values.&lt;/LI&gt;
&lt;/OL&gt;
&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;To manage the Day 1 Config from Panorama, you have a few of options.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Import the firewall configuration into separate a separate device group and template (1st URL below).&amp;nbsp; Messy.&lt;/LI&gt;
&lt;LI&gt;Import the NGFW configuration to Panorama and load config partial the pieces (2nd URL below).&amp;nbsp; Still messy.&lt;/LI&gt;
&lt;LI&gt;Create a Day 1 Configuration for Panorama.&amp;nbsp; Maybe messy maybe not.&lt;BR /&gt;
&lt;OL class="lia-list-style-type-lower-alpha"&gt;
&lt;LI&gt;Import but do not load it.&amp;nbsp; Do not load the Day 1 Configuration on the NGFW.&lt;/LI&gt;
&lt;LI&gt;Add the Day 1 Configuration device group and template to the candidate configuration via load config partial.&lt;/LI&gt;
&lt;LI&gt;Nest the Day 1 Configuration device group (sample_devicegroup) into your hierarchy and add the Day 1 Configuration template (iron-skillet) to your stack.&lt;/LI&gt;
&lt;/OL&gt;
&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;Try the commands below &lt;EM&gt;at your own risk &lt;/EM&gt;to see if it adds the Panorama Day 1 Configuration device group and template to your Panorama candidate configuration.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;load config partial mode merge from-xpath /config/devices/entry[@name='localhost.localdomain']/device-group/entry[@name='sample_devicegroup'] &amp;nbsp;to-xpath /config/devices/entry[@name='localhost.localdomain']/device-group from &amp;lt;day1filename&amp;gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;load config partial mode merge from-xpath /config/devices/entry[@name='localhost.localdomain']/template/entry[@name='iron-skillet'] &amp;nbsp;to-xpath /config/devices/entry[@name='localhost.localdomain']/template from &amp;lt;day1filename&amp;gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000CloRCAS" target="_blank" rel="noopener"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000CloRCAS&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/panorama/10-1/panorama-admin/manage-firewalls/transition-a-firewall-to-panorama-management/load-a-partial-firewall-configuration-into-panorama" target="_blank" rel="noopener"&gt;https://docs.paloaltonetworks.com/panorama/10-1/panorama-admin/manage-firewalls/transition-a-firewall-to-panorama-management/load-a-partial-firewall-configuration-into-panorama&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Edit:&amp;nbsp; With regard to Panorama, loading the Day 1 Configuration for a new Panorama build is ideal.&amp;nbsp; It also includes modifications to the "shared" device group and items under the Panorama tab in addition to the device group and templates referenced above.&lt;/P&gt;</description>
      <pubDate>Wed, 30 Nov 2022 16:04:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/suggestion-on-initial-configuration-of-palo-alto/m-p/522869#M108316</guid>
      <dc:creator>TomYoung</dc:creator>
      <dc:date>2022-11-30T16:04:05Z</dc:date>
    </item>
    <item>
      <title>Re: Suggestion on Initial Configuration of Palo-Alto</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/suggestion-on-initial-configuration-of-palo-alto/m-p/523116#M108349</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/7608"&gt;@reaper&lt;/a&gt;&amp;nbsp; /&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/77347"&gt;@TomYoung&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Thanks for the clear explanation. I will follow the same.&lt;/P&gt;</description>
      <pubDate>Fri, 02 Dec 2022 10:08:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/suggestion-on-initial-configuration-of-palo-alto/m-p/523116#M108349</guid>
      <dc:creator>Sujanya</dc:creator>
      <dc:date>2022-12-02T10:08:15Z</dc:date>
    </item>
  </channel>
</rss>

