<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Unable to set  SSL/TLS Service Profile with Panorama in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/unable-to-set-ssl-tls-service-profile-with-panorama/m-p/603151#M119898</link>
    <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/857727651"&gt;@C.Stuart&lt;/a&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;could you try to set TLSv1.3_Firewall profile from drop down list directly in Template Stack instead of Template to see it can push to Firewall?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Kind Regards&lt;/P&gt;
&lt;P&gt;Pavel&lt;/P&gt;</description>
    <pubDate>Thu, 17 Oct 2024 01:21:39 GMT</pubDate>
    <dc:creator>PavelK</dc:creator>
    <dc:date>2024-10-17T01:21:39Z</dc:date>
    <item>
      <title>Unable to set  SSL/TLS Service Profile with Panorama</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/unable-to-set-ssl-tls-service-profile-with-panorama/m-p/601829#M119734</link>
      <description>&lt;DIV&gt;
&lt;DIV&gt;&lt;SPAN&gt;Hello,&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;BR /&gt;
&lt;DIV&gt;&lt;SPAN&gt;At a bit of a dead end with a template change. Essentially, I am trying to configure the VMSeries Firewalls SSL/TLS Service Profile under:&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;BR /&gt;
&lt;DIV&gt;&lt;SPAN&gt;Device &amp;gt; Setup &amp;gt; Management &amp;gt; General Settings &amp;gt; SSL/TLS Service Profile&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;BR /&gt;
&lt;DIV&gt;&lt;SPAN&gt;I have configured the profile and requisite certificates in my template but when I push the changes, the SSL/TLS Service Profile is never set on the firewall. However, as part of the same template I am changing the Time Zone and this change is effective. Is there something that I am missing when deploying this?&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;BR /&gt;
&lt;DIV&gt;&lt;SPAN&gt;The certificates and profile are pushed to the device as I can manually set the SSL/TLS Service Profile post Panorama Commit and Push. So, if it can be pushed and I can see it and set it manually, why isn't Panorama doing it as part of the template rollout?&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN&gt;Any help appreciated!&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Panorama Template" style="width: 643px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/62969iD4578E3451C07DF1/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="panorama_template.png" alt="Panorama Template" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;Panorama Template&lt;/span&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Profile pushed and selectable on Firewall" style="width: 481px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/62970i312BD3B93B9E48FC/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="fw_profile.png" alt="Profile pushed and selectable on Firewall" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;Profile pushed and selectable on Firewall&lt;/span&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Settings post panorama push" style="width: 481px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/62971i672FD5F5EB3A1783/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="fw_general_settings.png" alt="Settings post panorama push" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;Settings post panorama push&lt;/span&gt;&lt;/span&gt;&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;/DIV&gt;</description>
      <pubDate>Wed, 16 Oct 2024 13:27:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/unable-to-set-ssl-tls-service-profile-with-panorama/m-p/601829#M119734</guid>
      <dc:creator>C.Stuart</dc:creator>
      <dc:date>2024-10-16T13:27:31Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to set  SSL/TLS Service Profile with Panorama</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/unable-to-set-ssl-tls-service-profile-with-panorama/m-p/603151#M119898</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/857727651"&gt;@C.Stuart&lt;/a&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;could you try to set TLSv1.3_Firewall profile from drop down list directly in Template Stack instead of Template to see it can push to Firewall?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Kind Regards&lt;/P&gt;
&lt;P&gt;Pavel&lt;/P&gt;</description>
      <pubDate>Thu, 17 Oct 2024 01:21:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/unable-to-set-ssl-tls-service-profile-with-panorama/m-p/603151#M119898</guid>
      <dc:creator>PavelK</dc:creator>
      <dc:date>2024-10-17T01:21:39Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to set  SSL/TLS Service Profile with Panorama</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/unable-to-set-ssl-tls-service-profile-with-panorama/m-p/603563#M119929</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/857727651"&gt;@C.Stuart&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You may need to Force Template Values, but that is dangerous because all of the template stack configurations will override the local configuration.&amp;nbsp; Let's put that on hold right now.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Instead you may try to delete the command from the CLI.&amp;nbsp; Maybe None is not the default.&amp;nbsp; Don't commit.&amp;nbsp; Then push from Panorama with the Edit Selections &amp;gt; Templates &amp;gt; Merge with Candidate Config box checked.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;</description>
      <pubDate>Thu, 17 Oct 2024 03:28:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/unable-to-set-ssl-tls-service-profile-with-panorama/m-p/603563#M119929</guid>
      <dc:creator>TomYoung</dc:creator>
      <dc:date>2024-10-17T03:28:33Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to set  SSL/TLS Service Profile with Panorama</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/unable-to-set-ssl-tls-service-profile-with-panorama/m-p/604729#M120058</link>
      <description>&lt;P&gt;Hi Both,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you for your responses. It never occurred to me that you could change the settings on the stack (relatively new to Panorama). The changes appear to be reflected in the Template Stack. Regardless, I have set the values on the template stack directly and I still get the same result. Everything except the SSL/TLS Service Profile is set. Just to confirm that it is working, I have also set some additional values that were also applied to the Firewall.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I've attempted to push to the Firewall with the '&lt;SPAN&gt;Merge with Candidate Config' set although this was checked by default anyway. Unchecking, yields the same result as well.&amp;nbsp;&lt;/SPAN&gt;Similarly, I have also gone as far as forcing template values and, unfortunately (somehow), this has not worked either.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Template Stack Settings" style="width: 478px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/63014i28CC780A1947A2D5/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="stack.png" alt="Template Stack Settings" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;Template Stack Settings&lt;/span&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Firewall Settings post-commit" style="width: 480px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/63015i2D64FBD2A77C7BF3/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="firewall.png" alt="Firewall Settings post-commit" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;Firewall Settings post-commit&lt;/span&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Kind regards,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Carl&lt;/P&gt;</description>
      <pubDate>Thu, 17 Oct 2024 09:29:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/unable-to-set-ssl-tls-service-profile-with-panorama/m-p/604729#M120058</guid>
      <dc:creator>C.Stuart</dc:creator>
      <dc:date>2024-10-17T09:29:28Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to set  SSL/TLS Service Profile with Panorama</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/unable-to-set-ssl-tls-service-profile-with-panorama/m-p/606646#M120324</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/857727651"&gt;@C.Stuart&lt;/a&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;thank you for reply.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Could you please confirm PAN-OS version running on Panorama and on Firewall? I came across known issues in some versions where Panorama pushed configuration was not applied in Firewall.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Kind Regards&lt;/P&gt;
&lt;P&gt;Pavel&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 17 Oct 2024 22:07:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/unable-to-set-ssl-tls-service-profile-with-panorama/m-p/606646#M120324</guid>
      <dc:creator>PavelK</dc:creator>
      <dc:date>2024-10-17T22:07:37Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to set  SSL/TLS Service Profile with Panorama</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/unable-to-set-ssl-tls-service-profile-with-panorama/m-p/606851#M120440</link>
      <description>&lt;P&gt;Hi Pavel,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The Firewall is running 10.2.8-h5 and Panorama is running&amp;nbsp;&lt;SPAN&gt;11.1.3.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Kind regards,&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Carl&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 18 Oct 2024 09:22:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/unable-to-set-ssl-tls-service-profile-with-panorama/m-p/606851#M120440</guid>
      <dc:creator>C.Stuart</dc:creator>
      <dc:date>2024-10-18T09:22:52Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to set  SSL/TLS Service Profile with Panorama</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/unable-to-set-ssl-tls-service-profile-with-panorama/m-p/608921#M120565</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/857727651"&gt;@C.Stuart&lt;/a&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;thank you for reply.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I can see below addressed issue in PAN-OS 11.1.4:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;PAN-244746&lt;/STRONG&gt;&lt;BR /&gt;Fixed an issue where changes committed on Panorama were not reflected on the firewall after a successful push.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Also, there is another addressed issue in PAN-OS 11.1.5, however since you are able to push certificates and able to apply them through profile it might not be related:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;PAN-251035&lt;/STRONG&gt;&lt;BR /&gt;Fixed an issue where selective push operations did not push certificate changes to the firewall.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you decide to upgrade Panorama, I would recommend to go straight to 11.1.5 to avoid the upgrade issue discussed in this thread:&amp;nbsp;&lt;A href="https://live.paloaltonetworks.com/t5/panorama-discussions/unable-to-upgrade-panorama-to-11-1-4-h1/td-p/599188" target="_self"&gt;Unable to upgrade Panorama to 11.1.4-H1&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Kind Regards&lt;/P&gt;
&lt;P&gt;Pavel&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 20 Oct 2024 22:23:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/unable-to-set-ssl-tls-service-profile-with-panorama/m-p/608921#M120565</guid>
      <dc:creator>PavelK</dc:creator>
      <dc:date>2024-10-20T22:23:13Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to set  SSL/TLS Service Profile with Panorama</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/unable-to-set-ssl-tls-service-profile-with-panorama/m-p/1226146#M123931</link>
      <description>&lt;P&gt;&amp;nbsp;still see this issue on&amp;nbsp;11.1.5-h1 with f/w on&amp;nbsp;10.2.12-h2.&lt;/P&gt;</description>
      <pubDate>Wed, 09 Apr 2025 21:03:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/unable-to-set-ssl-tls-service-profile-with-panorama/m-p/1226146#M123931</guid>
      <dc:creator>CHKlomp</dc:creator>
      <dc:date>2025-04-09T21:03:45Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to set  SSL/TLS Service Profile with Panorama</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/unable-to-set-ssl-tls-service-profile-with-panorama/m-p/1226147#M123932</link>
      <description>&lt;P&gt;Work-around is to disable TLSv1.3 on the profile.&lt;/P&gt;</description>
      <pubDate>Wed, 09 Apr 2025 21:45:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/unable-to-set-ssl-tls-service-profile-with-panorama/m-p/1226147#M123932</guid>
      <dc:creator>CHKlomp</dc:creator>
      <dc:date>2025-04-09T21:45:22Z</dc:date>
    </item>
  </channel>
</rss>

