<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: moving away from a disconnected panorama in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/moving-away-from-a-disconnected-panorama/m-p/152338#M50396</link>
    <description>&lt;P&gt;Great! can I use that to just create a basic policy to allow all for example?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.paloaltonetworks.com/documentation/60/pan-os/pan-os/getting-started/set-up-basic-security-policies" target="_blank"&gt;https://www.paloaltonetworks.com/documentation/60/pan-os/pan-os/getting-started/set-up-basic-security-policies&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 12 Apr 2017 15:36:44 GMT</pubDate>
    <dc:creator>JasonY</dc:creator>
    <dc:date>2017-04-12T15:36:44Z</dc:date>
    <item>
      <title>moving away from a disconnected panorama</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/moving-away-from-a-disconnected-panorama/m-p/152331#M50392</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;we recently got disconnected from the parent company and I ended up with all the network access and policies that I can't edit, and i'm afraid to touch the disconnect from panorma without asking first...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If I disconnected, will the policies becames local ann I can edit them? &amp;nbsp;or what's the best scenario?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm database developer that inherited a user/pass to our firewall/router/vpn &amp;nbsp;and many blocked policies that we need to loosen.. for a PA500&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;any help is appreciated please.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;&lt;P&gt;Jason&lt;/P&gt;</description>
      <pubDate>Wed, 12 Apr 2017 15:26:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/moving-away-from-a-disconnected-panorama/m-p/152331#M50392</guid>
      <dc:creator>JasonY</dc:creator>
      <dc:date>2017-04-12T15:26:34Z</dc:date>
    </item>
    <item>
      <title>Re: moving away from a disconnected panorama</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/moving-away-from-a-disconnected-panorama/m-p/152334#M50393</link>
      <description>&lt;P&gt;There are a couple of options.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;First (and probably most preferable in your case) is to determine whether the Panorama policies are Pre-Rules or Post-Rules. If they are Post-Rules, you should be able to create your own policies on the local firewall which will effectively override Panorama rules as it's a top-down, first match approach.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If that's not an option, you can indeed prevent Panorama from affecting local policies, at which point you should have the option to import/copy the Panorama policies into the local firewall.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I would advise reading this document before making that decision: &lt;A href="https://live.paloaltonetworks.com/t5/Management-Articles/Disable-Panorama-Policy-and-Objects-Disable-Device-and-Network/ta-p/76539" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Management-Articles/Disable-Panorama-Policy-and-Objects-Disable-Device-and-Network/ta-p/76539&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 12 Apr 2017 15:17:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/moving-away-from-a-disconnected-panorama/m-p/152334#M50393</guid>
      <dc:creator>bradk14</dc:creator>
      <dc:date>2017-04-12T15:17:01Z</dc:date>
    </item>
    <item>
      <title>Re: moving away from a disconnected panorama</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/moving-away-from-a-disconnected-panorama/m-p/152336#M50394</link>
      <description>&lt;P&gt;Hi and Thanks&amp;nbsp;&lt;SPAN class=""&gt;for stepping in, which option won't drop the netowrk or at least would bring it down for couple of minutes, also which one is revirsable if something went wrong?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;I'd think option#1 will be better, but how to tell the post or Pre rules?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 12 Apr 2017 15:25:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/moving-away-from-a-disconnected-panorama/m-p/152336#M50394</guid>
      <dc:creator>JasonY</dc:creator>
      <dc:date>2017-04-12T15:25:14Z</dc:date>
    </item>
    <item>
      <title>Re: moving away from a disconnected panorama</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/moving-away-from-a-disconnected-panorama/m-p/152337#M50395</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;Hi and Thanks&amp;nbsp;&lt;SPAN class=""&gt;for stepping in, which option won't drop the netowrk or at least would bring it down for couple of minutes, also which one is revirsable if something went wrong?&lt;/SPAN&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;neither should bring the network down. what you are effectively doing is taking away Panorama's ability to dictate policies with the second option, but it's still actually connected and reporting to Panorama as far as I know.&lt;/P&gt;&lt;BLOCKQUOTE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;I'd think option#1 will be better, but how to tell the post or Pre rules?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;easiest way is to create a local policy. if it shows up at the top, then you can override Panorama as you wish. if it's at the bottom, Panorama will enforce its rules first. And of course it can end up in the middle if Panorama is using both pre and Post rules.&lt;/P&gt;</description>
      <pubDate>Wed, 12 Apr 2017 15:30:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/moving-away-from-a-disconnected-panorama/m-p/152337#M50395</guid>
      <dc:creator>bradk14</dc:creator>
      <dc:date>2017-04-12T15:30:35Z</dc:date>
    </item>
    <item>
      <title>Re: moving away from a disconnected panorama</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/moving-away-from-a-disconnected-panorama/m-p/152338#M50396</link>
      <description>&lt;P&gt;Great! can I use that to just create a basic policy to allow all for example?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.paloaltonetworks.com/documentation/60/pan-os/pan-os/getting-started/set-up-basic-security-policies" target="_blank"&gt;https://www.paloaltonetworks.com/documentation/60/pan-os/pan-os/getting-started/set-up-basic-security-policies&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 12 Apr 2017 15:36:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/moving-away-from-a-disconnected-panorama/m-p/152338#M50396</guid>
      <dc:creator>JasonY</dc:creator>
      <dc:date>2017-04-12T15:36:44Z</dc:date>
    </item>
    <item>
      <title>Re: moving away from a disconnected panorama</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/moving-away-from-a-disconnected-panorama/m-p/152339#M50397</link>
      <description>&lt;P&gt;you could, just to see where it ends up in the list, but I wouldn't advise performing a commit with it in a production environment. if you're just trying to test the waters, I would impose limits on some level such as limiting source zone/ip to your own. Remember it's a top-down approach, so if you put a generic allow any rule at the top, it means your firewall is effectively not doing anything and will allow all traffic to and from anywhere (though as a safeguard, you are forced to actively choose the ANY option for the destination zone and source zone if that's your aim).&lt;/P&gt;</description>
      <pubDate>Wed, 12 Apr 2017 15:47:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/moving-away-from-a-disconnected-panorama/m-p/152339#M50397</guid>
      <dc:creator>bradk14</dc:creator>
      <dc:date>2017-04-12T15:47:01Z</dc:date>
    </item>
    <item>
      <title>Re: moving away from a disconnected panorama</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/moving-away-from-a-disconnected-panorama/m-p/152359#M50401</link>
      <description>&lt;P&gt;thank you so much, that worked !! &amp;nbsp;it was on the top, I commited and everything worked again, now i'll start to figure out how to&amp;nbsp;play wit the policies&lt;/P&gt;</description>
      <pubDate>Wed, 12 Apr 2017 18:01:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/moving-away-from-a-disconnected-panorama/m-p/152359#M50401</guid>
      <dc:creator>JasonY</dc:creator>
      <dc:date>2017-04-12T18:01:48Z</dc:date>
    </item>
  </channel>
</rss>

