<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: configuration change used to be pushed to firewall in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/configuration-change-used-to-be-pushed-to-firewall/m-p/558474#M113286</link>
    <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/306700"&gt;@kevinospf&lt;/a&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;thank you for reply.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;To get more detailed log to troubleshoot the issue, you should SSH to Panorama, then issue in CLI this command:&amp;nbsp;tail follow yes mp-log configd.log. From CLI you typically get more information compared to logs in GUI.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Kind Regards&lt;/P&gt;
&lt;P&gt;Pavel&lt;/P&gt;</description>
    <pubDate>Tue, 19 Sep 2023 05:30:42 GMT</pubDate>
    <dc:creator>PavelK</dc:creator>
    <dc:date>2023-09-19T05:30:42Z</dc:date>
    <item>
      <title>configuration change used to be pushed to firewall</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/configuration-change-used-to-be-pushed-to-firewall/m-p/557753#M113142</link>
      <description>&lt;P&gt;Hi Configuration change in template/stack used to be pushed to the firewall from panorama. but now after some change(creating new zone etc) made on template is pushed to the firewall, the change cannot be seen at the firewall again. so the configuration not be pushed to the firewall. Palo alto firewall is connected to panorama normally and it shows its in Sync status. Please see the below screenshot. Did I miss some step? Thanks&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="kevinospf_0-1694620407770.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/53676iC554BBD10F0BC0A3/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="kevinospf_0-1694620407770.png" alt="kevinospf_0-1694620407770.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 13 Sep 2023 18:39:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/configuration-change-used-to-be-pushed-to-firewall/m-p/557753#M113142</guid>
      <dc:creator>kevinospf</dc:creator>
      <dc:date>2023-09-13T18:39:03Z</dc:date>
    </item>
    <item>
      <title>Re: configuration change used to be pushed to firewall</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/configuration-change-used-to-be-pushed-to-firewall/m-p/557779#M113146</link>
      <description>&lt;P&gt;On the firewall itself are you seeing the commit job taking place and completely successfully? If so is it possible whatever your are pushing from Panorama has the config overridden on the local firewall?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you look at the template stack, not the template, in Panorama are the changes reflected there fine?&lt;/P&gt;</description>
      <pubDate>Wed, 13 Sep 2023 18:44:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/configuration-change-used-to-be-pushed-to-firewall/m-p/557779#M113146</guid>
      <dc:creator>Claw4609</dc:creator>
      <dc:date>2023-09-13T18:44:09Z</dc:date>
    </item>
    <item>
      <title>Re: configuration change used to be pushed to firewall</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/configuration-change-used-to-be-pushed-to-firewall/m-p/557816#M113155</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/306700"&gt;@kevinospf&lt;/a&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;only to add a few points to&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/227075"&gt;@Claw4609&lt;/a&gt;&amp;nbsp;great answer.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;There should be no issue with pushing a zone to managed Firewall. I would recommend to check that Template is part of Template Stack where Firewall is assigned and also check the order of Template in Template Stack. For overlapping configurations the priority of Templates in Template Stack is from top to bottom.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Make sure that local configuration is not overriding Template configuration. KB for reference:&amp;nbsp;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u0000008UgMCAU" target="_self"&gt;Pushed config from Panorama not being applied on the local Firewall&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If there is no issue with above points, I would be looking into configuration logs to see what is really happing under: Monitor &amp;gt; Logs &amp;gt; Configuration and for more detailed logs in CLI:&amp;nbsp;&lt;SPAN&gt;tail follow yes mp-log configd.log&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Kind Regards&lt;/P&gt;
&lt;P&gt;Pavel&lt;/P&gt;</description>
      <pubDate>Thu, 14 Sep 2023 00:42:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/configuration-change-used-to-be-pushed-to-firewall/m-p/557816#M113155</guid>
      <dc:creator>PavelK</dc:creator>
      <dc:date>2023-09-14T00:42:37Z</dc:date>
    </item>
    <item>
      <title>Re: configuration change used to be pushed to firewall</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/configuration-change-used-to-be-pushed-to-firewall/m-p/557817#M113156</link>
      <description>&lt;P&gt;Thanks for your reply.&lt;/P&gt;
&lt;P&gt;No I cannot see it at all. did I miss some steps?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Looks like some configuration cannot be pushed as the push button is grayed out, while other can be pushed to firewall sometimes.&lt;/P&gt;
&lt;P&gt;Are there any rules to control this?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 14 Sep 2023 01:07:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/configuration-change-used-to-be-pushed-to-firewall/m-p/557817#M113156</guid>
      <dc:creator>kevinospf</dc:creator>
      <dc:date>2023-09-14T01:07:36Z</dc:date>
    </item>
    <item>
      <title>Re: configuration change used to be pushed to firewall</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/configuration-change-used-to-be-pushed-to-firewall/m-p/557849#M113158</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/306700"&gt;@kevinospf&lt;/a&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;thank you for reply.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;At this point, I would try to remove the problematic configuration from your Template, commit it to Panorama, then add the same configuration, commit it and push it again to managed Firewall. While this is being pushed, I would watch out for this job in managed Firewall from task menu:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="PavelK_0-1694665376128.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/53696iA396881CD92BD721/image-size/medium?v=v2&amp;amp;px=400" role="button" title="PavelK_0-1694665376128.png" alt="PavelK_0-1694665376128.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Once this completes and desired configuration is not in the place, I would review logs on Panorama and managed Firewall to see in depth what was configured:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV data-pm-slice="1 1 []" data-en-clipboard="true"&gt;&lt;STRONG&gt;&lt;SPAN&gt;Panorama&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN&gt;: tail follow yes mp-log configd.log&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;STRONG&gt;&lt;SPAN&gt;FW&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN&gt;: tail follow yes mp-log devsrv.log&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regarding your question whether there is any configuration that can't be pushed from Panorama, the short answer is basically everything that is configurable in Device Group and Template can be pushed. There might be some corner cases, but I could not find any documentation that would pointed out to specific configuration that can't be done from Panorama.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Kind Regards&lt;/P&gt;
&lt;P&gt;Pavel&lt;/P&gt;</description>
      <pubDate>Thu, 14 Sep 2023 04:29:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/configuration-change-used-to-be-pushed-to-firewall/m-p/557849#M113158</guid>
      <dc:creator>PavelK</dc:creator>
      <dc:date>2023-09-14T04:29:47Z</dc:date>
    </item>
    <item>
      <title>Re: configuration change used to be pushed to firewall</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/configuration-change-used-to-be-pushed-to-firewall/m-p/558400#M113270</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/192693"&gt;@PavelK&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks for your reply. You are right. After test based on what you talked above, I know why some change could not be push via Template.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;One more question, Pushing template change does not need Device group change, but pushing Device group change to firewalll needs the Template, is this correct? Please see the below screanshot&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="kevinospf_0-1695056313186.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/53811i97A252C0081DD7C6/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="kevinospf_0-1695056313186.png" alt="kevinospf_0-1695056313186.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 18 Sep 2023 16:59:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/configuration-change-used-to-be-pushed-to-firewall/m-p/558400#M113270</guid>
      <dc:creator>kevinospf</dc:creator>
      <dc:date>2023-09-18T16:59:18Z</dc:date>
    </item>
    <item>
      <title>Re: configuration change used to be pushed to firewall</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/configuration-change-used-to-be-pushed-to-firewall/m-p/558460#M113282</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/306700"&gt;@kevinospf&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;thank you for reply.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The "Reference Templates" configuration in Device Group is not mandatory. Technically both Device Group and Template stack are independent configurations, however in some scenarios they have dependency on each other. The&amp;nbsp;Reference Templates is used in the case you are pushing Device Group configuration to the Firewall that has no Template Stack assigned. For example you need zones from Template to push policies in Device Group. Could you check this tutorial:&amp;nbsp;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000PNfeCAG" target="_self"&gt;Why Would I Need to Create Reference Templates in Device Groups?&lt;/A&gt;&amp;nbsp;and documentation&amp;nbsp;&lt;A href="https://docs.paloaltonetworks.com/panorama/11-0/panorama-admin/manage-firewalls/manage-device-groups/add-a-device-group" target="_self"&gt;Reference Template&lt;/A&gt;&amp;nbsp;(Refer to step No.4).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Kind Regards&lt;/P&gt;
&lt;P&gt;Pavel&lt;/P&gt;</description>
      <pubDate>Mon, 18 Sep 2023 23:39:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/configuration-change-used-to-be-pushed-to-firewall/m-p/558460#M113282</guid>
      <dc:creator>PavelK</dc:creator>
      <dc:date>2023-09-18T23:39:04Z</dc:date>
    </item>
    <item>
      <title>Re: configuration change used to be pushed to firewall</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/configuration-change-used-to-be-pushed-to-firewall/m-p/558467#M113283</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/192693"&gt;@PavelK&lt;/a&gt;&amp;nbsp;Thank you PavelK for your answer&lt;/P&gt;
&lt;P&gt;You talked as below. I have not understand comletely. I can see and check logs in Dashboad. but it looks like the logs are very brief and simple. Is there detail logs in somewhere else?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What does that mean? regarding "&lt;SPAN&gt; tail follow yes mp-log configd.log"&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;------------------&lt;/P&gt;
&lt;P&gt;Once this completes and desired configuration is not in the place, I would review logs on Panorama and managed Firewall to see in depth what was configured:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV data-pm-slice="1 1 []" data-en-clipboard="true"&gt;&lt;STRONG&gt;&lt;SPAN&gt;Panorama&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN&gt;: tail follow yes mp-log configd.log&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;STRONG&gt;&lt;SPAN&gt;FW&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN&gt;: tail follow yes mp-log devsrv.log&lt;/SPAN&gt;&lt;/DIV&gt;</description>
      <pubDate>Tue, 19 Sep 2023 02:04:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/configuration-change-used-to-be-pushed-to-firewall/m-p/558467#M113283</guid>
      <dc:creator>kevinospf</dc:creator>
      <dc:date>2023-09-19T02:04:15Z</dc:date>
    </item>
    <item>
      <title>Re: configuration change used to be pushed to firewall</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/configuration-change-used-to-be-pushed-to-firewall/m-p/558474#M113286</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/306700"&gt;@kevinospf&lt;/a&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;thank you for reply.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;To get more detailed log to troubleshoot the issue, you should SSH to Panorama, then issue in CLI this command:&amp;nbsp;tail follow yes mp-log configd.log. From CLI you typically get more information compared to logs in GUI.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Kind Regards&lt;/P&gt;
&lt;P&gt;Pavel&lt;/P&gt;</description>
      <pubDate>Tue, 19 Sep 2023 05:30:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/configuration-change-used-to-be-pushed-to-firewall/m-p/558474#M113286</guid>
      <dc:creator>PavelK</dc:creator>
      <dc:date>2023-09-19T05:30:42Z</dc:date>
    </item>
  </channel>
</rss>

