<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: What does not get uploaded in Config that needs changed via CLI? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/what-does-not-get-uploaded-in-config-that-needs-changed-via-cli/m-p/34860#M25581</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;As a rule I've found that anything on the Device tab or any configuration that can only be input through the CLI needs to be checked that its HA synchronized or configuration exported. The obvious stuff is the device addresses etc. but some of the other stuff is less obvious such as how certificates are handled. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 28 Oct 2013 16:45:00 GMT</pubDate>
    <dc:creator>SMF</dc:creator>
    <dc:date>2013-10-28T16:45:00Z</dc:date>
    <item>
      <title>What does not get uploaded in Config that needs changed via CLI?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/what-does-not-get-uploaded-in-config-that-needs-changed-via-cli/m-p/34859#M25580</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We have a PA-500 that has a bad hard drive in it. We copied the config from the bad device and transferred it to the new RMA device they have sent us. on the GUI all the settings have transferred over just fine and nothing looks different. But when the device is in place we have network issues and it is looking like packets are being dropped (some users can get to say google.com while the person next to them cant.) I have worked with about 6 different engineers on this issue and finally have had one notice one difference. The difference had to do with the "show running tcp state". The "bypass-exceed-oo-queue" = NO on the new device BUT was set to YES on the old device. So it does not look like this setting is transferred when you upload the config to a new device. My question is what else is not transferred from the old device to the new one? The engineer was able to see this difference while comparing the two tech support files. Is there anything else that needs to be manually changed on the new device? I am afraid to send the defective device back if we still need to look at settings on it and make changes on the new one to match. Any help/advice would be great, and by the way we are using PAN OS v4.1.13. Thanks in advance. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 16 Oct 2013 21:35:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/what-does-not-get-uploaded-in-config-that-needs-changed-via-cli/m-p/34859#M25580</guid>
      <dc:creator>lucius.l.rusher</dc:creator>
      <dc:date>2013-10-16T21:35:37Z</dc:date>
    </item>
    <item>
      <title>Re: What does not get uploaded in Config that needs changed via CLI?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/what-does-not-get-uploaded-in-config-that-needs-changed-via-cli/m-p/34860#M25581</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;As a rule I've found that anything on the Device tab or any configuration that can only be input through the CLI needs to be checked that its HA synchronized or configuration exported. The obvious stuff is the device addresses etc. but some of the other stuff is less obvious such as how certificates are handled. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 28 Oct 2013 16:45:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/what-does-not-get-uploaded-in-config-that-needs-changed-via-cli/m-p/34860#M25581</guid>
      <dc:creator>SMF</dc:creator>
      <dc:date>2013-10-28T16:45:00Z</dc:date>
    </item>
    <item>
      <title>Re: What does not get uploaded in Config that needs changed via CLI?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/what-does-not-get-uploaded-in-config-that-needs-changed-via-cli/m-p/34861#M25582</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;There are some configuration-settings which can be configured from operational mode and therefore not resides in the configuration-file.&lt;/P&gt;&lt;P&gt;For example you can configure "tcp-non-syn-check" in following two ways:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1.&lt;/P&gt;&lt;P&gt;set session tcp-reject-non-syn &amp;lt;yes|no&amp;gt;&amp;nbsp; -&amp;gt; active but not in the config-file....&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2.&lt;/P&gt;&lt;P&gt;config&lt;/P&gt;&lt;P&gt;set deviceconfig setting session tcp-reject-non-syn &amp;lt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;yes|no&amp;gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;commit&amp;nbsp; -&amp;gt;&amp;nbsp;&amp;nbsp; active an in the config-file...&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;As far as I know the only way to configure the bypass-exceed-oo-queue is the following:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;config&lt;/P&gt;&lt;P&gt;set deviceconfig setting tcp bypass-exceed-oo-queue &amp;lt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;yes|no&amp;gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;commit&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Though this setting should had definitely resided in the config-file....is the setting really not available under deviceconfig-stanza in the exported config-file..?&lt;/P&gt;&lt;P&gt;If no indeed a very odd behaviour. Any statements from PAN-support yet?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regarding the gerneral PAN tcp handling the following document is maybe helpful for you:&lt;/P&gt;&lt;P&gt;&lt;A _jive_internal="true" href="https://live.paloaltonetworks.com/docs/DOC-1731"&gt;https://live.paloaltonetworks.com/docs/DOC-1731&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;CU&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 31 Oct 2013 10:20:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/what-does-not-get-uploaded-in-config-that-needs-changed-via-cli/m-p/34861#M25582</guid>
      <dc:creator>indup089</dc:creator>
      <dc:date>2013-10-31T10:20:21Z</dc:date>
    </item>
  </channel>
</rss>

