<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ロックアウト in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/%E3%83%AD%E3%83%83%E3%82%AF%E3%82%A2%E3%82%A6%E3%83%88/m-p/1254743#M126491</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/725580859"&gt;@mori-tetsuya&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It sounds like your recent URL Filtering or Security Policy change accidentally matched and blocked your own administrative management traffic (HTTPS/SSH), locking your environment out upon the commit.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In order to regain access you can physically connect a serial cable directly to the CONSOLE port on the firewall.&lt;/P&gt;
&lt;P&gt;Once you are connected and logged into the CLI via your terminal software (like PuTTY or Tera Term), you can revert the firewall back to the configuration state right before your change.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;First goto configuration mode with the &lt;CODE data-index-in-node="52" data-path-to-node="11,1,2,0,0"&gt;configure&lt;/CODE&gt;&amp;nbsp;command.&amp;nbsp; Then you can load a previous config version with the command &lt;CODE data-index-in-node="52" data-path-to-node="11,1,2,0,0"&gt;load config version &amp;lt;version_number&amp;gt;&lt;/CODE&gt;.&amp;nbsp;&amp;nbsp;If you aren't sure of the version number, type &lt;CODE data-index-in-node="52" data-path-to-node="11,1,2,0,0"&gt;load config&lt;/CODE&gt; and press the &lt;STRONG data-index-in-node="78" data-path-to-node="11,1,2,0,0"&gt;Tab&lt;/STRONG&gt; key to view a chronological list of previous successful commits. Select the one from just before your change.&amp;nbsp; Finally you can commit the rolled-back configuration to production with the &lt;CODE data-index-in-node="52" data-path-to-node="11,1,2,0,0"&gt;commit&lt;/CODE&gt;&amp;nbsp;command.&lt;BR /&gt;&lt;BR /&gt;Hope this helps,&lt;/P&gt;</description>
    <pubDate>Tue, 26 May 2026 08:26:45 GMT</pubDate>
    <dc:creator>kiwi</dc:creator>
    <dc:date>2026-05-26T08:26:45Z</dc:date>
    <item>
      <title>ロックアウト</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/%E3%83%AD%E3%83%83%E3%82%AF%E3%82%A2%E3%82%A6%E3%83%88/m-p/1254612#M126489</link>
      <description>&lt;P&gt;コンソールからポリシーの設定の中で、URLフィルターの設定変更をしていたのですが&lt;/P&gt;
&lt;P&gt;変更をコミットした後から、コンソールへのアクセスが不可となってしまいました。&lt;/P&gt;
&lt;P&gt;変更前のセッションが残っている端末からも同様にアクセス不可の状態です。&lt;/P&gt;
&lt;P&gt;こちらの環境から、変更したポリシーの修正ができなくなってしまったのですが&lt;/P&gt;
&lt;P&gt;何か手立てはないでしょうか&lt;/P&gt;</description>
      <pubDate>Sun, 24 May 2026 08:58:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/%E3%83%AD%E3%83%83%E3%82%AF%E3%82%A2%E3%82%A6%E3%83%88/m-p/1254612#M126489</guid>
      <dc:creator>mori-tetsuya</dc:creator>
      <dc:date>2026-05-24T08:58:31Z</dc:date>
    </item>
    <item>
      <title>Re: ロックアウト</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/%E3%83%AD%E3%83%83%E3%82%AF%E3%82%A2%E3%82%A6%E3%83%88/m-p/1254743#M126491</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/725580859"&gt;@mori-tetsuya&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It sounds like your recent URL Filtering or Security Policy change accidentally matched and blocked your own administrative management traffic (HTTPS/SSH), locking your environment out upon the commit.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In order to regain access you can physically connect a serial cable directly to the CONSOLE port on the firewall.&lt;/P&gt;
&lt;P&gt;Once you are connected and logged into the CLI via your terminal software (like PuTTY or Tera Term), you can revert the firewall back to the configuration state right before your change.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;First goto configuration mode with the &lt;CODE data-index-in-node="52" data-path-to-node="11,1,2,0,0"&gt;configure&lt;/CODE&gt;&amp;nbsp;command.&amp;nbsp; Then you can load a previous config version with the command &lt;CODE data-index-in-node="52" data-path-to-node="11,1,2,0,0"&gt;load config version &amp;lt;version_number&amp;gt;&lt;/CODE&gt;.&amp;nbsp;&amp;nbsp;If you aren't sure of the version number, type &lt;CODE data-index-in-node="52" data-path-to-node="11,1,2,0,0"&gt;load config&lt;/CODE&gt; and press the &lt;STRONG data-index-in-node="78" data-path-to-node="11,1,2,0,0"&gt;Tab&lt;/STRONG&gt; key to view a chronological list of previous successful commits. Select the one from just before your change.&amp;nbsp; Finally you can commit the rolled-back configuration to production with the &lt;CODE data-index-in-node="52" data-path-to-node="11,1,2,0,0"&gt;commit&lt;/CODE&gt;&amp;nbsp;command.&lt;BR /&gt;&lt;BR /&gt;Hope this helps,&lt;/P&gt;</description>
      <pubDate>Tue, 26 May 2026 08:26:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/%E3%83%AD%E3%83%83%E3%82%AF%E3%82%A2%E3%82%A6%E3%83%88/m-p/1254743#M126491</guid>
      <dc:creator>kiwi</dc:creator>
      <dc:date>2026-05-26T08:26:45Z</dc:date>
    </item>
  </channel>
</rss>

