<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Firewall Policy Management: Tufin cannot detect PAN interfaces in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/firewall-policy-management-tufin-cannot-detect-pan-interfaces/m-p/23774#M17331</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Everybody,&lt;/P&gt;&lt;P&gt;I am running a PoC with Tufin SecureTrack and have some problems with PAN firewalls (PA-500 and PA-2020 running PANOS 4.1.7, PA-5050 running 4.1.12).&lt;/P&gt;&lt;P&gt;In a nutshell sounds like Tufin detects only the interfaces that in PAN XML configuration file are listed within the default vsys:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp; &lt;/TD&gt;&lt;TD&gt;&amp;lt;vsys&amp;gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/TD&gt;&lt;TD&gt;&amp;lt;entry name="vsys1"&amp;gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;... &lt;/P&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/TD&gt;&lt;TD&gt;&amp;lt;import&amp;gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/TD&gt;&lt;TD&gt;&amp;lt;network&amp;gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/TD&gt;&lt;TD&gt;&amp;lt;interface&amp;gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/TD&gt;&lt;TD&gt;&amp;lt;member&amp;gt;tunnel.1&amp;lt;/member&amp;gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/TD&gt;&lt;TD&gt;&amp;lt;member&amp;gt;tunnel.2&amp;lt;/member&amp;gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/TD&gt;&lt;TD&gt;&amp;lt;member&amp;gt;tunnel.3&amp;lt;/member&amp;gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/TD&gt;&lt;TD&gt;&amp;lt;/interface&amp;gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/TD&gt;&lt;TD&gt;&amp;lt;/network&amp;gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/TD&gt;&lt;TD&gt;&amp;lt;/import&amp;gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;...&lt;/P&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp; &lt;/TD&gt;&lt;TD&gt;&amp;lt;/vsys&amp;gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;whilst all ethernet interfaces are ignored, even if corresponding routes are properly detected; of course this causes a mess with the network topology...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I wonder whether it is safe - i.e. does not turn my firewall into a brick or causes any problem to the user traffic - to edit PAN XML file and just write down missing ethernet interfaces within vsys1: does anybody have any hints or experience with Tufin?&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Bucche&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 05 Sep 2013 10:39:00 GMT</pubDate>
    <dc:creator>Bucche</dc:creator>
    <dc:date>2013-09-05T10:39:00Z</dc:date>
    <item>
      <title>Firewall Policy Management: Tufin cannot detect PAN interfaces</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/firewall-policy-management-tufin-cannot-detect-pan-interfaces/m-p/23774#M17331</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Everybody,&lt;/P&gt;&lt;P&gt;I am running a PoC with Tufin SecureTrack and have some problems with PAN firewalls (PA-500 and PA-2020 running PANOS 4.1.7, PA-5050 running 4.1.12).&lt;/P&gt;&lt;P&gt;In a nutshell sounds like Tufin detects only the interfaces that in PAN XML configuration file are listed within the default vsys:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp; &lt;/TD&gt;&lt;TD&gt;&amp;lt;vsys&amp;gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/TD&gt;&lt;TD&gt;&amp;lt;entry name="vsys1"&amp;gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;... &lt;/P&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/TD&gt;&lt;TD&gt;&amp;lt;import&amp;gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/TD&gt;&lt;TD&gt;&amp;lt;network&amp;gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/TD&gt;&lt;TD&gt;&amp;lt;interface&amp;gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/TD&gt;&lt;TD&gt;&amp;lt;member&amp;gt;tunnel.1&amp;lt;/member&amp;gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/TD&gt;&lt;TD&gt;&amp;lt;member&amp;gt;tunnel.2&amp;lt;/member&amp;gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/TD&gt;&lt;TD&gt;&amp;lt;member&amp;gt;tunnel.3&amp;lt;/member&amp;gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/TD&gt;&lt;TD&gt;&amp;lt;/interface&amp;gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/TD&gt;&lt;TD&gt;&amp;lt;/network&amp;gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/TD&gt;&lt;TD&gt;&amp;lt;/import&amp;gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;...&lt;/P&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp; &lt;/TD&gt;&lt;TD&gt;&amp;lt;/vsys&amp;gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;whilst all ethernet interfaces are ignored, even if corresponding routes are properly detected; of course this causes a mess with the network topology...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I wonder whether it is safe - i.e. does not turn my firewall into a brick or causes any problem to the user traffic - to edit PAN XML file and just write down missing ethernet interfaces within vsys1: does anybody have any hints or experience with Tufin?&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Bucche&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 05 Sep 2013 10:39:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/firewall-policy-management-tufin-cannot-detect-pan-interfaces/m-p/23774#M17331</guid>
      <dc:creator>Bucche</dc:creator>
      <dc:date>2013-09-05T10:39:00Z</dc:date>
    </item>
    <item>
      <title>Re: Firewall Policy Management: Tufin cannot detect PAN interfaces</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/firewall-policy-management-tufin-cannot-detect-pan-interfaces/m-p/23775#M17332</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Sounds like nobody else is interested in this issue, but just in case someone else will work with Tufin in the future...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can safely edit XML configuration file and add/reorder missing interfaces (I haven't tried to remove an interface yet, but I guess it works); just for the record, missing interfaces were created before a PANOS upgrade, the only ones listed into VSYS were those we added after such upgrade.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Tufin needs a little bit of hammering:&amp;nbsp; according to Tufin support, SecureTrack should have detected the new interfaces after a restart of the corresponding service&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;[root@tufin]#&amp;nbsp; st stat | grep &amp;lt;FW-NAME&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;lt;FW-NAME&amp;gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.0.1&amp;nbsp; 23&amp;nbsp;&amp;nbsp;&amp;nbsp; Palo Alto Networks&amp;nbsp;&amp;nbsp;&amp;nbsp; -&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; evaluation&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Started&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Once you know the id of the firewall, e.g. 23, you restart corresponding process&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;[root@tufin]# st restart 23&lt;/P&gt;&lt;P&gt;Stopping SecureTrack process for server &amp;lt;FW-NAME&amp;gt; - 10.0.0.1 (Id: 23)&lt;/P&gt;&lt;P&gt;SecureTrack process stopped for server 10.0.0.1 (Id: 23)&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Error: Can't connect to remote host using URL '&lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="https://localhost/securetrack/api/devices/deviceChanged"&gt;https://localhost/securetrack/api/devices/deviceChanged&lt;/A&gt;&lt;SPAN&gt;'. reason: Operation timed out after 300000 milliseconds with 0 bytes received&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Since I got above error message and Tufin did not detect newer configuration, I restarted again the service corresponding to &amp;lt;FW-NAME&amp;gt; from GUI (Settings-Administration menu) and the interfaces were properly detected, as well as the new configuration file.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In order to fix Tufin network topology, however, I had to restart Tufin server (shutdown -r) and now I can see &amp;lt;FW-NAME&amp;gt; in SecureTrack map.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So long&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 09 Sep 2013 15:29:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/firewall-policy-management-tufin-cannot-detect-pan-interfaces/m-p/23775#M17332</guid>
      <dc:creator>Bucche</dc:creator>
      <dc:date>2013-09-09T15:29:47Z</dc:date>
    </item>
  </channel>
</rss>

