<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Move/clone/copy from FW Local Policies to existing Device Groups in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/move-clone-copy-from-fw-local-policies-to-existing-device-groups/m-p/529101#M109230</link>
    <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/179185"&gt;@Metgatz&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I bet "load config partial" will do the trick.&amp;nbsp; &lt;A href="https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-cli-quick-start/use-the-cli/load-configurations/load-a-partial-configuration" target="_blank" rel="noopener"&gt;https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-cli-quick-start/use-the-cli/load-configurations/load-a-partial-configuration&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Export the config from the NGFW.&amp;nbsp; Import to Panorama, but do not load.&amp;nbsp; Run "load config partial" from the CLI of Panorama:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Mode merge&lt;/LI&gt;
&lt;LI&gt;From NGFW file&lt;/LI&gt;
&lt;LI&gt;From security policy Xpath (from NGFW API browser)&lt;/LI&gt;
&lt;LI&gt;To running-config&lt;/LI&gt;
&lt;LI&gt;To device group security policy pre-rules Xpath (from Panorama API browser).&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;I've done load config partial a few times, but I can't remember if I moved from local to device group.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You could also use Expedition if (1) it was already (2) or you wanted to - set it up.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;</description>
    <pubDate>Mon, 30 Jan 2023 03:07:39 GMT</pubDate>
    <dc:creator>TomYoung</dc:creator>
    <dc:date>2023-01-30T03:07:39Z</dc:date>
    <item>
      <title>Move/clone/copy from FW Local Policies to existing Device Groups</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/move-clone-copy-from-fw-local-policies-to-existing-device-groups/m-p/528689#M109161</link>
      <description>&lt;P class=""&gt;&lt;SPAN class=""&gt;&lt;SPAN&gt;Clone or move FW Local Policies to Device Groups&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;DIV id="viewer-e3jig" class=""&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;
&lt;P class=""&gt;&lt;SPAN class=""&gt;&lt;SPAN&gt;Hello good afternoon, as always, thanks for the collaboration, time and good vibes.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;DIV id="viewer-4cg32" class=""&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;
&lt;P class=""&gt;&lt;SPAN class=""&gt;&lt;SPAN&gt;I have the following question.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;DIV id="viewer-ag0fd" class=""&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;
&lt;P class=""&gt;&lt;SPAN class=""&gt;&lt;SPAN&gt;Due to bad practices some admins have made changes and added local policies.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;DIV id="viewer-ed36v" class=""&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;
&lt;P class=""&gt;&lt;SPAN class=""&gt;&lt;SPAN&gt;The Firewall in HA has its device-groups where there are a large number of policies, ie most, almost 90% are via device groups, but there are 10% that created them locally.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;DIV id="viewer-c2if3" class=""&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;
&lt;P class=""&gt;&lt;SPAN class=""&gt;&lt;SPAN&gt;So is there a way to take those local policies, clone them, move them, etc ?&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;DIV id="viewer-917ft" class=""&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;
&lt;P class=""&gt;&lt;SPAN class=""&gt;&lt;SPAN&gt;So that you don't have to create them manually?&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;DIV id="viewer-49l9a" class=""&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;
&lt;P class=""&gt;&lt;SPAN class=""&gt;&lt;SPAN&gt;Thanks, I remain attentive&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;DIV id="viewer-1f79g" class=""&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;
&lt;P class=""&gt;&lt;SPAN class=""&gt;&lt;SPAN&gt;Best regards &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;</description>
      <pubDate>Thu, 26 Jan 2023 07:19:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/move-clone-copy-from-fw-local-policies-to-existing-device-groups/m-p/528689#M109161</guid>
      <dc:creator>Metgatz</dc:creator>
      <dc:date>2023-01-26T07:19:13Z</dc:date>
    </item>
    <item>
      <title>Re: Move/clone/copy from FW Local Policies to existing Device Groups</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/move-clone-copy-from-fw-local-policies-to-existing-device-groups/m-p/529078#M109228</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/179185"&gt;@Metgatz&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;Unfortunately as far as I know Panorama does not have any mechanism to get local policy rules and update the device group. But there is "hacky" way to do it.&lt;/P&gt;
&lt;P&gt;In my humble opinion - if the rules are not many, just do it in the dummy manual way:&lt;/P&gt;
&lt;P&gt;- Connect to FW with CLI&lt;/P&gt;
&lt;P&gt;- Set configuration view to set mode -&amp;gt; set cli config-output-format set&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;&amp;gt; set cli config-output-format set&lt;/LI-CODE&gt;
&lt;P&gt;- Enter config mode and show security policy. Note this way show command will show only the local configured rules&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;&amp;gt; configure
# show rulebase security rules&lt;/LI-CODE&gt;
&lt;P&gt;- Copy everything from here to text file&lt;/P&gt;
&lt;P&gt;- Panorama cannot push rules with rulename already exist. So you need to add some prefix/suffix to the rulenames in the text file&lt;/P&gt;
&lt;P&gt;- Connect to Panorama with CLI, climb the config three to the device group you want to update and paste the rules from the text file&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;&amp;gt; configure
# edit device-group XXXX pre-rulebase security
//(optional, but recommended)
# run set cli scripting-mode on
&amp;lt;paste rules from text file&amp;gt;
# run set cli scripting-mode off&lt;/LI-CODE&gt;
&lt;P&gt;- Move the rules at desired location in GUI (you can do it over CLI, but I for me this action is easier in the GUI). Note that we created the rules in the pre-rules sections, the purpose is for the new rules to shadow the local rules so the traffic can start matching those instead of the local. &lt;/P&gt;
&lt;P&gt;- Once you confirm all traffic is matching the Panorama pushed rules, delete the local configured one&lt;/P&gt;
&lt;P&gt;- (Optional) remove the prefix/suffix that you add to the rulenames as it is no longer required (local rules are gone)&lt;/P&gt;
&lt;P&gt;You &lt;U&gt;need to &lt;/U&gt;do this for any address, service, group and any other object that is created locally and used by this rules.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I prefer this method, because I am sure no import will mess my Panorama config, or it will affect the rest of the rules. The problem is that it doesn't scale well if you have too many object, services, security profiles and rules to import.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Here comes the "hacky" way - &lt;A href="https://knowledgebase.paloaltonetworks.com/kcsArticleDetail?id=kA10g0000008UIP&amp;amp;refURL=http%3A%2F%2Fknowledgebase.paloaltonetworks.com%2FkcsArticleDetail&amp;amp;refURL=http%3A%2F%2Fknowledgebase.paloaltonetworks.com%2FkcsArticleDetail" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/kcsArticleDetail?id=kA10g0000008UIP&amp;amp;refURL=http%3A%2F%2Fknowledgebase.paloaltonetworks.com%2FkcsArticleDetail&amp;amp;refURL=http%3A%2F%2Fknowledgebase.paloaltonetworks.com%2FkcsArticleDetail&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;In summary:&lt;BR /&gt;- You convert all firewall to local. This will merge panorama pushed config with the local and import it to the local config file&lt;/P&gt;
&lt;P&gt;- You remove firewall from existing device-group and template (guide tells you to remove FW completely, but I don't think is necessary, just de-associate it with any device-group and template in order to import device config)&lt;/P&gt;
&lt;P&gt;- Import device config to Panorama. This will create new templates and device-group and associate the FW with them&lt;/P&gt;
&lt;P&gt;- Export device config to the firewall, which will "convert" the whole config from local to Panorama pushed"&lt;/P&gt;
&lt;P&gt;- Push config to firewall to have green light for config sync.&lt;/P&gt;
&lt;P&gt;- Once you happy with the result, you can delete the old device-group and templates and rename those that are associated with the FW,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 29 Jan 2023 22:50:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/move-clone-copy-from-fw-local-policies-to-existing-device-groups/m-p/529078#M109228</guid>
      <dc:creator>aleksandar.astardzhiev</dc:creator>
      <dc:date>2023-01-29T22:50:36Z</dc:date>
    </item>
    <item>
      <title>Re: Move/clone/copy from FW Local Policies to existing Device Groups</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/move-clone-copy-from-fw-local-policies-to-existing-device-groups/m-p/529101#M109230</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/179185"&gt;@Metgatz&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I bet "load config partial" will do the trick.&amp;nbsp; &lt;A href="https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-cli-quick-start/use-the-cli/load-configurations/load-a-partial-configuration" target="_blank" rel="noopener"&gt;https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-cli-quick-start/use-the-cli/load-configurations/load-a-partial-configuration&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Export the config from the NGFW.&amp;nbsp; Import to Panorama, but do not load.&amp;nbsp; Run "load config partial" from the CLI of Panorama:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Mode merge&lt;/LI&gt;
&lt;LI&gt;From NGFW file&lt;/LI&gt;
&lt;LI&gt;From security policy Xpath (from NGFW API browser)&lt;/LI&gt;
&lt;LI&gt;To running-config&lt;/LI&gt;
&lt;LI&gt;To device group security policy pre-rules Xpath (from Panorama API browser).&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;I've done load config partial a few times, but I can't remember if I moved from local to device group.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You could also use Expedition if (1) it was already (2) or you wanted to - set it up.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;</description>
      <pubDate>Mon, 30 Jan 2023 03:07:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/move-clone-copy-from-fw-local-policies-to-existing-device-groups/m-p/529101#M109230</guid>
      <dc:creator>TomYoung</dc:creator>
      <dc:date>2023-01-30T03:07:39Z</dc:date>
    </item>
    <item>
      <title>Re: Move/clone/copy from FW Local Policies to existing Device Groups</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/move-clone-copy-from-fw-local-policies-to-existing-device-groups/m-p/529224#M109257</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/77347"&gt;@TomYoung&lt;/a&gt;&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/70130"&gt;@aleksandar.astardzhiev&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks to both of you for the tips, I will check them out and try, they are good approaches.&lt;/P&gt;
&lt;P&gt;Now have any of you in PANORAMA done an import of a backup and then a.:&lt;/P&gt;
&lt;P&gt;Load Named Configuration - Select Device Groups &amp;amp; Template ?&lt;/P&gt;
&lt;P&gt;Has anyone had the experience of loading, from the GUI, selecting only one particular Device Groups example, so as not to alter anything else in Panorama at all?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks, I remain attentive&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Best regards&lt;/P&gt;</description>
      <pubDate>Tue, 31 Jan 2023 02:45:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/move-clone-copy-from-fw-local-policies-to-existing-device-groups/m-p/529224#M109257</guid>
      <dc:creator>Metgatz</dc:creator>
      <dc:date>2023-01-31T02:45:24Z</dc:date>
    </item>
  </channel>
</rss>

