<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Integrating Panorama with existing PAN Firewalls? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/integrating-panorama-with-existing-pan-firewalls/m-p/69488#M40314</link>
    <description>&lt;P&gt;I recommend getting comfortable with doing large load config partial's of xml configs and using a text editor like notepad ++ to find replace and add something simply to the end or beginning of the object names in order to avoid duplicates. &amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;once you have everything managed by the pan you can delete and/or rename objects, it is also my understanding that newer versions of the migration tool will enable this feature pretty seamlessly. &amp;nbsp;assuming the vm/tool is approved to run on customers network.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;on a side note, if the devices dont exist at all in panorama yet, if you have panorama 7.x.x you can import the device under setup and operations and I've had great luck with that. &amp;nbsp;if you have issues committing with this method due to duplicate names you can delete many of the objects locally and leave as a candidate config then when you push from pano make sure you have 'merge with candidate config' checked off.&lt;/P&gt;</description>
    <pubDate>Tue, 15 Dec 2015 14:39:34 GMT</pubDate>
    <dc:creator>AJR15</dc:creator>
    <dc:date>2015-12-15T14:39:34Z</dc:date>
    <item>
      <title>Integrating Panorama with existing PAN Firewalls?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/integrating-panorama-with-existing-pan-firewalls/m-p/69317#M40262</link>
      <description>&lt;P&gt;I've inherited an environment where Panorama was an afterthought for 60+ PAN firewalls. Finally convinced management to buy Panorama&amp;nbsp;after we terminated&amp;nbsp;the reason for this mess and had to change passwords on 60+ firewalls individually.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The problem I'm running into is that almost every firewall has different polcies, objects, network profiles and everything else. I can import the device configuration to Panorama, but then I end up with 60+ device groups. Trying to move the devices into a device group and applying the settings fails due to the existing objects.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Whats the best way to handle this? Having 60+ device groups defeats the purpose of central management. I do have the device and network templates working as they should.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 10 Dec 2015 14:03:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/integrating-panorama-with-existing-pan-firewalls/m-p/69317#M40262</guid>
      <dc:creator>WillWylie</dc:creator>
      <dc:date>2015-12-10T14:03:30Z</dc:date>
    </item>
    <item>
      <title>Re: Integrating Panorama with existing PAN Firewalls?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/integrating-panorama-with-existing-pan-firewalls/m-p/69392#M40276</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The import is just the initial step of managing your firewalls centrally from Panorama. It's up to you to create the proper device groups. Do you have the exact error message for the existing objects? Do you still have local objects on your firewalls?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Benjamin&lt;/P&gt;</description>
      <pubDate>Fri, 11 Dec 2015 19:02:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/integrating-panorama-with-existing-pan-firewalls/m-p/69392#M40276</guid>
      <dc:creator>BenjAudy.MTL</dc:creator>
      <dc:date>2015-12-11T19:02:50Z</dc:date>
    </item>
    <item>
      <title>Re: Integrating Panorama with existing PAN Firewalls?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/integrating-panorama-with-existing-pan-firewalls/m-p/69402#M40279</link>
      <description>&lt;P&gt;I feel your pain. &amp;nbsp;I've done a number of conversions from local to Panorama device groups and they are not at all fun and a whole lot of work. &amp;nbsp;But in the end the effort is worth it.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Start with deciding how many groups the 60 devices can be reasonably divided into. &amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Collect all the common across all group settings.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Create a naming convention so that all objects will be consistently created.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Determine if all policy can be held in the group of if some local policies will be required. &amp;nbsp;And if they are needed then choose the pre or post common rule set model for the group.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I tended to create most objects as global so they could be used across the groups.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Start with a small device and make the naming convention changes and system harminizations. &amp;nbsp;Once ready I used this process to get the devices into Panorama.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I would run these procedures with a lab PA and lab Panorama until the scripts were well honed&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;create a rollback file for both the device an panorama before starting so there is an easy fallback point&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Create the Panorama group&lt;/P&gt;
&lt;P&gt;Export the local configuration and create backup snapshots&lt;/P&gt;
&lt;P&gt;Import the local configuration as a file to panorama. &amp;nbsp;This will just be used as a source to import objects to global.&lt;/P&gt;
&lt;P&gt;Use load config partial [filename] to pull objects from this file into the shared objects in Panorama&lt;/P&gt;
&lt;P&gt;object order:&lt;/P&gt;
&lt;P&gt;tags&lt;/P&gt;
&lt;P&gt;addresses&lt;/P&gt;
&lt;P&gt;address groups&lt;/P&gt;
&lt;P&gt;services&lt;/P&gt;
&lt;P&gt;service groups&lt;/P&gt;
&lt;P&gt;custom applications&lt;/P&gt;
&lt;P&gt;profiles&lt;/P&gt;
&lt;P&gt;profile groups&lt;/P&gt;
&lt;P&gt;Security policies&lt;/P&gt;
&lt;P&gt;nat policies&lt;/P&gt;
&lt;P&gt;application override policies&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;delete all the local cofiguration objects but do not commit&lt;/P&gt;
&lt;P&gt;Add the device to panorama&lt;/P&gt;
&lt;P&gt;commit and override from panorama&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Schedule the migrations.&lt;/P&gt;</description>
      <pubDate>Fri, 11 Dec 2015 23:47:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/integrating-panorama-with-existing-pan-firewalls/m-p/69402#M40279</guid>
      <dc:creator>pulukas</dc:creator>
      <dc:date>2015-12-11T23:47:41Z</dc:date>
    </item>
    <item>
      <title>Re: Integrating Panorama with existing PAN Firewalls?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/integrating-panorama-with-existing-pan-firewalls/m-p/69426#M40294</link>
      <description>&lt;P&gt;Pulukas is giving serious hints.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Yet if you don't feel like doing this alone, you should try to contact your PAN sales to get in touch with our Professional Services. They can help you to draft a safe plan with procedures and even execute it.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thx&lt;/P&gt;</description>
      <pubDate>Mon, 14 Dec 2015 09:09:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/integrating-panorama-with-existing-pan-firewalls/m-p/69426#M40294</guid>
      <dc:creator>cpainchaud</dc:creator>
      <dc:date>2015-12-14T09:09:17Z</dc:date>
    </item>
    <item>
      <title>Re: Integrating Panorama with existing PAN Firewalls?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/integrating-panorama-with-existing-pan-firewalls/m-p/69488#M40314</link>
      <description>&lt;P&gt;I recommend getting comfortable with doing large load config partial's of xml configs and using a text editor like notepad ++ to find replace and add something simply to the end or beginning of the object names in order to avoid duplicates. &amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;once you have everything managed by the pan you can delete and/or rename objects, it is also my understanding that newer versions of the migration tool will enable this feature pretty seamlessly. &amp;nbsp;assuming the vm/tool is approved to run on customers network.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;on a side note, if the devices dont exist at all in panorama yet, if you have panorama 7.x.x you can import the device under setup and operations and I've had great luck with that. &amp;nbsp;if you have issues committing with this method due to duplicate names you can delete many of the objects locally and leave as a candidate config then when you push from pano make sure you have 'merge with candidate config' checked off.&lt;/P&gt;</description>
      <pubDate>Tue, 15 Dec 2015 14:39:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/integrating-panorama-with-existing-pan-firewalls/m-p/69488#M40314</guid>
      <dc:creator>AJR15</dc:creator>
      <dc:date>2015-12-15T14:39:34Z</dc:date>
    </item>
  </channel>
</rss>

