<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Panorama Template conflicts with base device config in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/panorama-template-conflicts-with-base-device-config/m-p/28903#M21121</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;It does work for the devices in question ( over writing the network parameters, with the new parameters that are pushed from the template ), if you select&amp;nbsp; "Include Device and Network Templates"&amp;nbsp; and "force template values" under the "device group" and "Templates" commits, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="templates.JPG.jpg" class="jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/7854_templates.JPG.jpg" style="width: 620px; height: 386px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="templates-2.JPG.jpg" class="jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/7855_templates-2.JPG.jpg" style="width: 620px; height: 388px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Below thread also talks about the same:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A _jive_internal="true" href="https://live.paloaltonetworks.com/message/24073#24073"&gt;https://live.paloaltonetworks.com/message/24073#24073&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;BR,&lt;/P&gt;&lt;P&gt;karthik &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 23 Aug 2013 19:49:44 GMT</pubDate>
    <dc:creator>kprakash</dc:creator>
    <dc:date>2013-08-23T19:49:44Z</dc:date>
    <item>
      <title>Panorama Template conflicts with base device config</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/panorama-template-conflicts-with-base-device-config/m-p/28902#M21120</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I am in the process of building out my Device Groups and Templates to standardize configurations across all sites. Our sites are standardized in a way that we can actually apply device configurations across multiple sites. After the base templates are applied all I need to do is apply the site specific data such as their local subnets and up addresses. My goal is to standardize configurations and reduce configuration time for rapid deployment.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;However, when trying to achieve this goal I ran into an issue with the base configurations of the PAN devices. Out of the box the device is setup for a vwire with trust and untrust zones setup. This causes a conflict with Panorama. When I go to deploy my template configurations, it errors because the vwire and the trust/untrust zones are being referenced and the Template cannot overwrite those settings, even with a force.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My current solution to the issue was to go into the device and remove the conflicting configurations. Effectively removing all existing configurations from the device to allow the template a fresh start. Originally I was doing this from the GUI, but got lazy and now have a notepad with all the commands I just run from CLI.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Attached are the commands that need to be run:&lt;/P&gt;&lt;P&gt;delete rulebase security rules rule1&lt;/P&gt;&lt;P&gt;delete network virtual-wire default-vwire&lt;/P&gt;&lt;P&gt;delete zone trust&lt;/P&gt;&lt;P&gt;delete zone untrust&lt;/P&gt;&lt;P&gt;delete network interface ethernet ethernet1/1 virtual-wire&lt;/P&gt;&lt;P&gt;delete network interface ethernet ethernet1/2 virtual-wire&lt;/P&gt;&lt;P&gt;delete network interface ethernet ethernet1/1&lt;/P&gt;&lt;P&gt;delete network interface ethernet ethernet1/2&lt;/P&gt;&lt;P&gt;delete network virtual-router default&lt;/P&gt;&lt;P&gt;delete network ike crypto-profiles ike-crypto-profiles default&lt;/P&gt;&lt;P&gt;delete network ike crypto-profiles ipsec-crypto-profiles default&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is there a better way to get around this? Forcing the template won't work because unless the device settings directly conflict with the Panorama settings they will coincide. IE: Panorama will only overwrite on force, not delete.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 23 Aug 2013 14:38:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/panorama-template-conflicts-with-base-device-config/m-p/28902#M21120</guid>
      <dc:creator>Poe</dc:creator>
      <dc:date>2013-08-23T14:38:14Z</dc:date>
    </item>
    <item>
      <title>Re: Panorama Template conflicts with base device config</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/panorama-template-conflicts-with-base-device-config/m-p/28903#M21121</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;It does work for the devices in question ( over writing the network parameters, with the new parameters that are pushed from the template ), if you select&amp;nbsp; "Include Device and Network Templates"&amp;nbsp; and "force template values" under the "device group" and "Templates" commits, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="templates.JPG.jpg" class="jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/7854_templates.JPG.jpg" style="width: 620px; height: 386px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="templates-2.JPG.jpg" class="jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/7855_templates-2.JPG.jpg" style="width: 620px; height: 388px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Below thread also talks about the same:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A _jive_internal="true" href="https://live.paloaltonetworks.com/message/24073#24073"&gt;https://live.paloaltonetworks.com/message/24073#24073&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;BR,&lt;/P&gt;&lt;P&gt;karthik &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 23 Aug 2013 19:49:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/panorama-template-conflicts-with-base-device-config/m-p/28903#M21121</guid>
      <dc:creator>kprakash</dc:creator>
      <dc:date>2013-08-23T19:49:44Z</dc:date>
    </item>
    <item>
      <title>Re: Panorama Template conflicts with base device config</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/panorama-template-conflicts-with-base-device-config/m-p/28904#M21122</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for the reply. Last time I tried this, force template values overwrites existing configurations, but this only works for overridden configuration. For instance if I have a new device the default admin account will be present and if I have 3 administrator accounts in my template, if I override one of the template admin accounts and change his role on the local device. When I force the value it will overwrite the role change on the template admin account but it would not remove the Default admin account. I want to be able to delete the default admin account without having to prep the device before applying the template.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In the switch world I would delete the startup-config and reboot the device and start with a clean slate. I wonder if I can do the same for PAN-OS or if it will brick something or revert back to the default config.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 24 Aug 2013 16:06:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/panorama-template-conflicts-with-base-device-config/m-p/28904#M21122</guid>
      <dc:creator>Poe</dc:creator>
      <dc:date>2013-08-24T16:06:17Z</dc:date>
    </item>
  </channel>
</rss>

