<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: backup local config to panorama? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/backup-local-config-to-panorama/m-p/42304#M31090</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;ok i think i have find how to generate the api_KEY:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="active_link" href="http://blog.rootshell.be/2012/03/28/are-you-making-the-most-of-your-security-tools/" title="http://blog.rootshell.be/2012/03/28/are-you-making-the-most-of-your-security-tools/"&gt;http://blog.rootshell.be/2012/03/28/are-you-making-the-most-of-your-security-tools/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have run this on my Linux CentOS box (not over panoramo or PA-2050):&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So i suppose i have to install Perl pack and dev tools on panorama?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When i have run this, i get 403 access denied errors messages:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;[root@XYZ bin]# ./show.sh ../templates/dev2rama/ 10.X.Y.Z The_api_key_generated&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;../templates/dev2rama//show/01_address.xpath&lt;/P&gt;&lt;P&gt;Executing:&amp;nbsp; panxapi -rsx "devices/entry/vsys/entry[@name='vsys1']/address"&lt;/P&gt;&lt;P&gt;show: User not authorized to perform this operation. status="error" code="403"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;../templates/dev2rama//show/02_address-group.xpath&lt;/P&gt;&lt;P&gt;Executing:&amp;nbsp; panxapi -rsx "devices/entry/vsys/entry[@name='vsys1']/address-group"&lt;/P&gt;&lt;P&gt;show: User not authorized to perform this operation. status="error" code="403"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;../templates/dev2rama//show/03_service.xpath&lt;/P&gt;&lt;P&gt;Executing:&amp;nbsp; panxapi -rsx "devices/entry[@name='localhost.localdomain']/vsys/entry[@name='vsys1']/service"&lt;/P&gt;&lt;P&gt;show: User not authorized to perform this operation. status="error" code="403"&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 09 Aug 2012 17:39:39 GMT</pubDate>
    <dc:creator>denisgaron</dc:creator>
    <dc:date>2012-08-09T17:39:39Z</dc:date>
    <item>
      <title>backup local config to panorama?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/backup-local-config-to-panorama/m-p/42300#M31086</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We already have an PA appliance installed.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We buy panorama 1 month later.&amp;nbsp; Mainly because we want to keep logs long time like 2 years of logs.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So we just want to manage Rules set of the PA with panorma, and get all the logs.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;First step i try to do is doing&amp;nbsp; an export/import of the PA to panorama.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There is clear exemple to do that?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For now i only find documentation talking general information of the process, but dont show detail information on how to import/export objects and rules set, from a PA to Panorama.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Maybe there is a Migration Tool that can make this for me?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Its mainly just one rules set that i want to import/export to panorama.&amp;nbsp; Or maybe i will have to redo all those rules manualy in the panorama?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 07 Aug 2012 18:52:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/backup-local-config-to-panorama/m-p/42300#M31086</guid>
      <dc:creator>denisgaron</dc:creator>
      <dc:date>2012-08-07T18:52:49Z</dc:date>
    </item>
    <item>
      <title>Re: backup local config to panorama?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/backup-local-config-to-panorama/m-p/42301#M31087</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Denis,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This document has the required scripts that can help you migrate your config from a standalone PAN to Panorama.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A _jive_internal="true" href="https://live.paloaltonetworks.com/docs/DOC-1911"&gt;https://live.paloaltonetworks.com/docs/DOC-1911&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Sri Darapuneni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 07 Aug 2012 23:53:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/backup-local-config-to-panorama/m-p/42301#M31087</guid>
      <dc:creator>zarina</dc:creator>
      <dc:date>2012-08-07T23:53:27Z</dc:date>
    </item>
    <item>
      <title>Re: backup local config to panorama?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/backup-local-config-to-panorama/m-p/42302#M31088</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;hi Sri,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I new to palo alto.&amp;nbsp; But i know Linux and/or Unix well, and i know firewall like ASA and checkpoint.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So here my question about installing and make work those scripts.&amp;nbsp; I have read the doc, i need some more information, specialy, where I install those Perl package and script.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have to install : &lt;SPAN class="jive-wiki-body-file"&gt;&lt;SPAN class="jive-wiki-body-file-info"&gt;&lt;A _jive_internal="true" href="https://live.paloaltonetworks.com/servlet/JiveServlet/downloadBody/1911-102-1-4690/dev2rama-20110815.tar.gz" rel="nozoom"&gt;dev2rama-20110815.tar.gz&lt;/A&gt; (3.3 K)&amp;nbsp; and&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class="jive-wiki-body-file"&gt;&lt;SPAN class="jive-wiki-body-file-info"&gt;&lt;A _jive_internal="true" href="https://live.paloaltonetworks.com/servlet/JiveServlet/downloadBody/1910-102-3-4711/PAN-perl-20110828.tar.gz" rel="nozoom"&gt;PAN-perl-20110828.tar.gz&lt;/A&gt; (35.6 K) &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="jive-wiki-body-file"&gt;&lt;SPAN class="jive-wiki-body-file-info"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;I install this directly on the PA-2050 appliance?&amp;nbsp; Or i have to use a linux box?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 09 Aug 2012 13:57:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/backup-local-config-to-panorama/m-p/42302#M31088</guid>
      <dc:creator>denisgaron</dc:creator>
      <dc:date>2012-08-09T13:57:38Z</dc:date>
    </item>
    <item>
      <title>Re: backup local config to panorama?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/backup-local-config-to-panorama/m-p/42303#M31089</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi, An on other question;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have install dev2rama on a Linux box. (i still need answer on my precedent message)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I need to understand how to create the api_key.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I need to give that information in the command :&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;./show.sh ../templates/dev2rama/ 10.X.Y.Z api_key&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have seek on knowledge base, and also in palo alto unit GUI.&amp;nbsp; For now i didnt find how to generate the api_key.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thankS!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 09 Aug 2012 16:01:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/backup-local-config-to-panorama/m-p/42303#M31089</guid>
      <dc:creator>denisgaron</dc:creator>
      <dc:date>2012-08-09T16:01:34Z</dc:date>
    </item>
    <item>
      <title>Re: backup local config to panorama?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/backup-local-config-to-panorama/m-p/42304#M31090</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;ok i think i have find how to generate the api_KEY:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="active_link" href="http://blog.rootshell.be/2012/03/28/are-you-making-the-most-of-your-security-tools/" title="http://blog.rootshell.be/2012/03/28/are-you-making-the-most-of-your-security-tools/"&gt;http://blog.rootshell.be/2012/03/28/are-you-making-the-most-of-your-security-tools/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have run this on my Linux CentOS box (not over panoramo or PA-2050):&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So i suppose i have to install Perl pack and dev tools on panorama?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When i have run this, i get 403 access denied errors messages:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;[root@XYZ bin]# ./show.sh ../templates/dev2rama/ 10.X.Y.Z The_api_key_generated&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;../templates/dev2rama//show/01_address.xpath&lt;/P&gt;&lt;P&gt;Executing:&amp;nbsp; panxapi -rsx "devices/entry/vsys/entry[@name='vsys1']/address"&lt;/P&gt;&lt;P&gt;show: User not authorized to perform this operation. status="error" code="403"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;../templates/dev2rama//show/02_address-group.xpath&lt;/P&gt;&lt;P&gt;Executing:&amp;nbsp; panxapi -rsx "devices/entry/vsys/entry[@name='vsys1']/address-group"&lt;/P&gt;&lt;P&gt;show: User not authorized to perform this operation. status="error" code="403"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;../templates/dev2rama//show/03_service.xpath&lt;/P&gt;&lt;P&gt;Executing:&amp;nbsp; panxapi -rsx "devices/entry[@name='localhost.localdomain']/vsys/entry[@name='vsys1']/service"&lt;/P&gt;&lt;P&gt;show: User not authorized to perform this operation. status="error" code="403"&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 09 Aug 2012 17:39:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/backup-local-config-to-panorama/m-p/42304#M31090</guid>
      <dc:creator>denisgaron</dc:creator>
      <dc:date>2012-08-09T17:39:39Z</dc:date>
    </item>
    <item>
      <title>Re: backup local config to panorama?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/backup-local-config-to-panorama/m-p/42305#M31091</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;On 4.1 you may need to run panxapi -k multiple times to get a key which is not url encoded.&amp;nbsp; The history behind this is the XML API documentation does not state the key is returned encoded if encoding is needed and panxapi relies on LWP to do the encoding which will encode % for POST, which can result in double encoding if previously encoded.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;so run panxapi until the key does not contain percent:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;$ panxapi -h 172.29.9.121 -kl admin:admin&lt;/P&gt;&lt;P&gt;keygen: success&lt;/P&gt;&lt;P&gt;API key: "PjA4A1Q2RZrxNcHCnh6PDOHc53F4elJ/%2Bjhg16a8GO0="&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;this key won't work.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;$ panxapi -h 172.29.9.121 -kl admin:admin&lt;/P&gt;&lt;P&gt;keygen: success&lt;/P&gt;&lt;P&gt;API key: "Q8acmLknUVOFt5dXq2LjTfZ8GoyTOZ1UoFPsa7nMIzY="&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;this key will work.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;also, the latest version of PAN-perl is PAN-perl-20120107.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 09 Aug 2012 18:01:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/backup-local-config-to-panorama/m-p/42305#M31091</guid>
      <dc:creator>ksteves1</dc:creator>
      <dc:date>2012-08-09T18:01:48Z</dc:date>
    </item>
    <item>
      <title>Re: backup local config to panorama?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/backup-local-config-to-panorama/m-p/42306#M31092</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;thanks Kevin for help.&amp;nbsp; Yeah indead i have install the latest PAN-perl :&lt;/P&gt;&lt;P&gt;&lt;A __default_attr="2485" __jive_macro_name="document" class="jive_macro jive_macro_document" href="https://live.paloaltonetworks.com/"&gt;&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;but I finaly done more reading on PAN API DOC:&lt;/P&gt;&lt;P&gt;&lt;A __default_attr="1981" __jive_macro_name="document" class="jive_macro jive_macro_document" href="https://live.paloaltonetworks.com/"&gt;&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The problem was in password of the admin account i use.&amp;nbsp; I was using a special char in the passwed.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;you can read in the api doc : "Any special characters in the password must be URL/percent-encoded."&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So i create a new admin, with no_special_char in it.&amp;nbsp; Then Re-use the URL to regen the Api_KEY&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Bingo dev2rama work well now.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I just have to try the rest: getting those rules in Panorama.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;==&amp;gt; Just a side note on those that using CentOS Linux BOX :&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When installing PAN perl pack v.20120107.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- you need perl&amp;nbsp; (yum install perl)&lt;/P&gt;&lt;P&gt;then lib :&lt;/P&gt;&lt;P&gt;# yum install perl-Net-SSLeay&lt;/P&gt;&lt;P&gt;# yum install perl-Crypt-SSLeay&lt;/P&gt;&lt;P&gt;(those differ from unbuntu)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;and &lt;/P&gt;&lt;P&gt;#yum install perl-lib*&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can do cpan stuff like its show in the PAN-perl-Pack doc&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this help. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But i wish Palo Alto add a tools in PANORAMA to retrieve rules in a PA appliance, without having to install dev2rama.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 09 Aug 2012 18:50:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/backup-local-config-to-panorama/m-p/42306#M31092</guid>
      <dc:creator>denisgaron</dc:creator>
      <dc:date>2012-08-09T18:50:30Z</dc:date>
    </item>
  </channel>
</rss>

