<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PA1410 new install with ZTP disabled but still has ztp references. in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/pa1410-new-install-with-ztp-disabled-but-still-has-ztp/m-p/586281#M117017</link>
    <description>&lt;P&gt;update on this..&lt;/P&gt;
&lt;P&gt;so today we deployed another FW out the box.. same process, however this time at first logon I did the step3 commands.. all worked but still unable to commit as it removed the interface configs etc and was complaining about invalid config when commiting...&lt;/P&gt;
&lt;P&gt;workaround was to manually add an interface on the device and created a new zone.. once done I was able to commit the policy..&lt;/P&gt;
&lt;P&gt;after that I did the device registration, license and content downloads followed by pan-os upgrade.&lt;/P&gt;
&lt;P&gt;seems to be ok now and ready for action.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 09 May 2024 12:59:15 GMT</pubDate>
    <dc:creator>PA_nts</dc:creator>
    <dc:date>2024-05-09T12:59:15Z</dc:date>
    <item>
      <title>PA1410 new install with ZTP disabled but still has ztp references.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa1410-new-install-with-ztp-disabled-but-still-has-ztp/m-p/586175#M116995</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;
&lt;P&gt;so we are in the process of deploying a few brand new PA 1410's out the box.&lt;/P&gt;
&lt;P&gt;during initial bootup the field engineer connects with the console cable, and is then asked to install either ZTP mode or standard mode.&lt;/P&gt;
&lt;P&gt;engineer selects standard mode and proceed.. all good.&lt;/P&gt;
&lt;P&gt;once mgmt IP is configured i can then connect remotely and do the config.&lt;/P&gt;
&lt;P&gt;however, i noticed that there are ztp based config auto configured.. the palo (pan-os 11.0.0 out the box) installs a loopback.900 interface with a 100.64.x.x ip and a ztp vr route&lt;/P&gt;
&lt;P&gt;the service route is also set to custom and i cannot set it to default. i have to change the custom routes individually to default else it tries to talk from the loopback interface.&lt;/P&gt;
&lt;P&gt;i checked also in the cli using 'show system ztp status' and it is showing as being&amp;nbsp; disabled.&lt;/P&gt;
&lt;P&gt;is it normal that it adds some&amp;nbsp; ztp config into the base config or is it maybe a bit buggy?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;so now i have to try and work around the ztp config and override the settings to make changes. bit of a headache.&lt;/P&gt;
&lt;P&gt;any ideas?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;have included some screenshots fyi&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;thanks in adv&lt;/P&gt;</description>
      <pubDate>Wed, 08 May 2024 13:48:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa1410-new-install-with-ztp-disabled-but-still-has-ztp/m-p/586175#M116995</guid>
      <dc:creator>PA_nts</dc:creator>
      <dc:date>2024-05-08T13:48:24Z</dc:date>
    </item>
    <item>
      <title>Re: PA1410 new install with ZTP disabled but still has ztp references.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa1410-new-install-with-ztp-disabled-but-still-has-ztp/m-p/586212#M117002</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/306035"&gt;@PA_nts&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I ran into the same issue a little while ago.&amp;nbsp; Issuing the commands in step 3 should remove the configuration for you.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u0000001UiOCAU&amp;amp;lang=en_US%E2%80%A9" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u0000001UiOCAU&amp;amp;lang=en_US%E2%80%A9&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It used to be that disabling ZTP was all you needed.&amp;nbsp; Weird.&amp;nbsp; This may be a PAN-OS 11 thing.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;</description>
      <pubDate>Wed, 08 May 2024 17:39:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa1410-new-install-with-ztp-disabled-but-still-has-ztp/m-p/586212#M117002</guid>
      <dc:creator>TomYoung</dc:creator>
      <dc:date>2024-05-08T17:39:34Z</dc:date>
    </item>
    <item>
      <title>Re: PA1410 new install with ZTP disabled but still has ztp references.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa1410-new-install-with-ztp-disabled-but-still-has-ztp/m-p/586257#M117011</link>
      <description>&lt;P&gt;Hi Tom,&lt;/P&gt;
&lt;P&gt;Awesome thanks that worked.. using the following commands in step 3:&lt;/P&gt;
&lt;P&gt;admin@FW1&amp;gt; set system setting template enable &lt;BR /&gt;Template already enabled&lt;BR /&gt;admin@FW-1&amp;gt; set system setting template disable &lt;BR /&gt;Template disabled&lt;BR /&gt;admin@FW-1&amp;gt; set system setting shared-policy enable &lt;BR /&gt;Shared policy already enabled&lt;BR /&gt;admin@FW-1&amp;gt; set system setting shared-policy disable &lt;BR /&gt;Shared policy disabled&lt;BR /&gt;&lt;A href="mailto:admin@FW-1&amp;gt;" target="_blank"&gt;admin@FW-1&amp;gt; &lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I was not able to force a commit on CLI.. as the service route still had references to the loopback.&lt;/P&gt;
&lt;P&gt;so I just logged in via GUI again, changed the service route to use mgmt interface for all&amp;nbsp; and was able to commit the policy. but this was on 1/2 FWs only.. the other one was fine. so definitely something weird on 11.0.0 going on.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;we are doing 2 more over the next couple of days.. will try and see how it works on these and post anything of interest.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;thanks&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 09 May 2024 06:17:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa1410-new-install-with-ztp-disabled-but-still-has-ztp/m-p/586257#M117011</guid>
      <dc:creator>PA_nts</dc:creator>
      <dc:date>2024-05-09T06:17:29Z</dc:date>
    </item>
    <item>
      <title>Re: PA1410 new install with ZTP disabled but still has ztp references.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa1410-new-install-with-ztp-disabled-but-still-has-ztp/m-p/586281#M117017</link>
      <description>&lt;P&gt;update on this..&lt;/P&gt;
&lt;P&gt;so today we deployed another FW out the box.. same process, however this time at first logon I did the step3 commands.. all worked but still unable to commit as it removed the interface configs etc and was complaining about invalid config when commiting...&lt;/P&gt;
&lt;P&gt;workaround was to manually add an interface on the device and created a new zone.. once done I was able to commit the policy..&lt;/P&gt;
&lt;P&gt;after that I did the device registration, license and content downloads followed by pan-os upgrade.&lt;/P&gt;
&lt;P&gt;seems to be ok now and ready for action.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 09 May 2024 12:59:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa1410-new-install-with-ztp-disabled-but-still-has-ztp/m-p/586281#M117017</guid>
      <dc:creator>PA_nts</dc:creator>
      <dc:date>2024-05-09T12:59:15Z</dc:date>
    </item>
  </channel>
</rss>

