<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Template stacks limitations in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/template-stacks-limitations/m-p/153816#M50730</link>
    <description>&lt;P&gt;Hey all,&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;I think I am hitting a limitation on the template-stacks, but maybe there is a nice workaround that you guys can help me with...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Contrary to Device groups, which have "shared" objects, templates use stacks which is a little different.&lt;BR /&gt;The limitation to this seems to be that you can not reference a template value between different templates...&lt;/P&gt;&lt;P&gt;Simple example to explain what I mean:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;create a "shared-template" and add a local admin user&lt;/LI&gt;&lt;LI&gt;create a "FW1-template" add some specific network interfaces&lt;/LI&gt;&lt;LI&gt;create a "FW2-template" add some specific network interfaces&lt;/LI&gt;&lt;LI&gt;create a "FW1-template-stack" which includes the FW1 and shared template =&amp;gt; assign this to your FW-1&lt;/LI&gt;&lt;LI&gt;create a "FW2-template-stack" which includes the FW2 and shared template =&amp;gt; assign this to your FW&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;STRONG&gt;=&amp;gt;&lt;/STRONG&gt; if you commit; the device will receive its unique network interfaces + the shared admin user = this works and looks like template-stacking is the solution to all the "duplicate" objects between FW-templates&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;BUT&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;If we want to do something a bit more advanced (the following is just an example)&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;add an ldap profile to the "shared-template"&lt;/LI&gt;&lt;LI&gt;add an auth profile to the "shared-template" referencing to the ldap-profile above&lt;/LI&gt;&lt;LI&gt;add an admin user which is only allowed to login to FW1 (not FW2) =&amp;gt; This means you would create the admin user in the "FW1-template" an not to the "shared-template".&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;STRONG&gt;=&amp;gt; HERE IS THE ISSUE:&lt;/STRONG&gt; you can not select the ldap-auth-profile, because the auth-profile was created in another template (the "shared-template")&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So you have to be sure that all the components that will ever use a template object will have to be configred within the same template.&amp;nbsp;This limitation becomes difficult fast, because a lot of the template objects are linked ex: ldap profile -&amp;gt; auth-profile =&amp;gt; admin users, but also: group-mapping, globalprotect config, etc... and a lot of these things will have different config on the devices.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Anybody had similar experiences? How did you work around them?&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 24 Apr 2017 10:50:31 GMT</pubDate>
    <dc:creator>mr.linus</dc:creator>
    <dc:date>2017-04-24T10:50:31Z</dc:date>
    <item>
      <title>Template stacks limitations</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/template-stacks-limitations/m-p/153816#M50730</link>
      <description>&lt;P&gt;Hey all,&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;I think I am hitting a limitation on the template-stacks, but maybe there is a nice workaround that you guys can help me with...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Contrary to Device groups, which have "shared" objects, templates use stacks which is a little different.&lt;BR /&gt;The limitation to this seems to be that you can not reference a template value between different templates...&lt;/P&gt;&lt;P&gt;Simple example to explain what I mean:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;create a "shared-template" and add a local admin user&lt;/LI&gt;&lt;LI&gt;create a "FW1-template" add some specific network interfaces&lt;/LI&gt;&lt;LI&gt;create a "FW2-template" add some specific network interfaces&lt;/LI&gt;&lt;LI&gt;create a "FW1-template-stack" which includes the FW1 and shared template =&amp;gt; assign this to your FW-1&lt;/LI&gt;&lt;LI&gt;create a "FW2-template-stack" which includes the FW2 and shared template =&amp;gt; assign this to your FW&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;STRONG&gt;=&amp;gt;&lt;/STRONG&gt; if you commit; the device will receive its unique network interfaces + the shared admin user = this works and looks like template-stacking is the solution to all the "duplicate" objects between FW-templates&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;BUT&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;If we want to do something a bit more advanced (the following is just an example)&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;add an ldap profile to the "shared-template"&lt;/LI&gt;&lt;LI&gt;add an auth profile to the "shared-template" referencing to the ldap-profile above&lt;/LI&gt;&lt;LI&gt;add an admin user which is only allowed to login to FW1 (not FW2) =&amp;gt; This means you would create the admin user in the "FW1-template" an not to the "shared-template".&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;STRONG&gt;=&amp;gt; HERE IS THE ISSUE:&lt;/STRONG&gt; you can not select the ldap-auth-profile, because the auth-profile was created in another template (the "shared-template")&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So you have to be sure that all the components that will ever use a template object will have to be configred within the same template.&amp;nbsp;This limitation becomes difficult fast, because a lot of the template objects are linked ex: ldap profile -&amp;gt; auth-profile =&amp;gt; admin users, but also: group-mapping, globalprotect config, etc... and a lot of these things will have different config on the devices.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Anybody had similar experiences? How did you work around them?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 24 Apr 2017 10:50:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/template-stacks-limitations/m-p/153816#M50730</guid>
      <dc:creator>mr.linus</dc:creator>
      <dc:date>2017-04-24T10:50:31Z</dc:date>
    </item>
    <item>
      <title>Re: Template stacks limitations</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/template-stacks-limitations/m-p/153825#M50731</link>
      <description>&lt;P&gt;this contradicts the nature of 'shared' &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;::edit:: ok i see what you did there, youre not adding the user1 in the shared, but on the firewll&lt;/P&gt;
&lt;P&gt;pre-compilation the templates are standalone and not 'aware' of eachother, so you can't build in one template what is defined in another&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 24 Apr 2017 11:34:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/template-stacks-limitations/m-p/153825#M50731</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2017-04-24T11:34:07Z</dc:date>
    </item>
    <item>
      <title>Re: Template stacks limitations</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/template-stacks-limitations/m-p/153842#M50735</link>
      <description>&lt;P&gt;guess I'll just make a feature request&lt;/P&gt;</description>
      <pubDate>Mon, 24 Apr 2017 14:11:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/template-stacks-limitations/m-p/153842#M50735</guid>
      <dc:creator>mr.linus</dc:creator>
      <dc:date>2017-04-24T14:11:12Z</dc:date>
    </item>
    <item>
      <title>Re: Template stacks limitations</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/template-stacks-limitations/m-p/214523#M62336</link>
      <description>&lt;P&gt;A very simple and yet practical example of this limitation and &lt;U&gt;a workaround&lt;/U&gt; is with Interface Management Profiles.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Say I have three templates (I prefix my templates with "T-")&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;T-ACME-Baseline&lt;/LI&gt;&lt;LI&gt;T-ACME-User&lt;/LI&gt;&lt;LI&gt;T-ACME-Datacenter&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;From those three templates I build two template stacks (note that template stacks cannot have hyphens in their names, I use "TS_") and their constituent templates.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;TS_ACME_User&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;T-ACME-User&lt;/LI&gt;&lt;LI&gt;T-ACME-Baseline&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;TS_ACME_Datacenter&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;T-ACME-Datacenter&lt;/LI&gt;&lt;LI&gt;T-ACME-Baseline&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2018-05-16 21_59_57-Window.png" style="width: 675px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/15173i5FC3ED1372FF9BF7/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="2018-05-16 21_59_57-Window.png" alt="2018-05-16 21_59_57-Window.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The "User" TS is assigned to the ficticious "User" firewall and the "Datacenter" TS to the fictitious "Datacenter" firewall.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Build an Interface Management Profile called "Ping-Only" in T-ACME-Baseline (which is a constituent T of both TS's). Build the Interface configuration in T-ACME-User and T-ACME-Datacenter.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;From T-ACME-User and T-ACME-Datacenter this "Ping-Only" Interface Management Profile is &lt;U&gt;not&lt;/U&gt; visible when building the Interfaces within these templates. However, from the Template Stacks themselves (TS_ACME_User and TS_ACME_Datacenter) "Ping-Only" is visible and can be applied.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When opening up an Interface from the Template &lt;EM&gt;Stack &lt;/EM&gt;itself, the "Ping-Only" profile is present, but Panorama says the entire dialog box is Read Only and &lt;U&gt;won'&lt;/U&gt;t permit clicking OK. See screenshot below.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2018-05-16 22_26_31-Window.png" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/15174iD7FA3DF9074D1995/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="2018-05-16 22_26_31-Window.png" alt="2018-05-16 22_26_31-Window.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Lucky for us we can &lt;U&gt;Override&lt;/U&gt; (note the Panorama Template selected is still the Template Stack).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2018-05-16 22_30_55-Window.png" style="width: 780px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/15175i76C8E9BA00FC7C82/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="2018-05-16 22_30_55-Window.png" alt="2018-05-16 22_30_55-Window.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;After selecting &lt;U&gt;Override&lt;/U&gt; the dialog box is no longer Read Only, "Ping-Only" profile is still visible, select it, click OK, Commit and Push.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Since the Override is within Panorama (and not a local firewall change), it will be &lt;U&gt;unaffected&lt;/U&gt; by a "Force Template Values" push (good).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;With that we are able to build a "Ping-Only" Interface Management Profile in a "Baseline" T, build our Interfaces in other T's, then apply the "Ping-Only" profile in the TS.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have not tried the specific examples you mentioned in the post.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In summary, referencing a specific template's constructions &lt;EM&gt;directly&lt;/EM&gt; in another template is &lt;U&gt;not&lt;/U&gt; possible. However, constructions from a specific template can be combined with another specific template and actually applied using the Override function within the Template Stack.&lt;/P&gt;</description>
      <pubDate>Thu, 17 May 2018 04:00:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/template-stacks-limitations/m-p/214523#M62336</guid>
      <dc:creator>JohnUrbanek</dc:creator>
      <dc:date>2018-05-17T04:00:51Z</dc:date>
    </item>
    <item>
      <title>Re: Template stacks limitations</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/template-stacks-limitations/m-p/214617#M62350</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/48914"&gt;@JohnUrbanek&lt;/a&gt;&lt;/P&gt;&lt;P&gt;The option to override values directly in the template stack is only available since PAN-OS 8.1. But even with this option this does not solve the example mentionned by &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/18483"&gt;@mr.linus&lt;/a&gt;. it is still not possible to reference opjects in one template which exist in another template. And back to the example with the ldap-adminuser: of course it is possible to create the ldap server and authenication profile in one base profile, but then you would have to configure the adminuser on every templatestack or at least some template stacks depending on your configuration. For other examples 8.1 solves the issue like the one with global protect: configure the server and auth profile in the base profile and then configure global protect in the template stack, like in your example. This way you can reference objects from templates that belong to thw template stack.&lt;/P&gt;</description>
      <pubDate>Thu, 17 May 2018 20:00:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/template-stacks-limitations/m-p/214617#M62350</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2018-05-17T20:00:07Z</dc:date>
    </item>
    <item>
      <title>Re: Template stacks limitations</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/template-stacks-limitations/m-p/649046#M122159</link>
      <description>&lt;P&gt;This worked for me. Thank you&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/48914"&gt;@JohnUrbanek&lt;/a&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 22 Nov 2024 09:10:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/template-stacks-limitations/m-p/649046#M122159</guid>
      <dc:creator>RichaSB</dc:creator>
      <dc:date>2024-11-22T09:10:29Z</dc:date>
    </item>
    <item>
      <title>Re: Template stacks limitations</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/template-stacks-limitations/m-p/649758#M122161</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You can do the following:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;on "shared-template" create a LDAP Server profile and an Authentication Profile that use the LDAP Server Profile&lt;/LI&gt;
&lt;LI&gt;on "FW1-template" create a Authentication Profile but configuring only the minimum info needed to activate OK button. That means that you will create a Auth Profile with &lt;STRONG&gt;THE SAME NAME&lt;/STRONG&gt; as the one create on "shared template" and select only type as LDAP.&lt;/LI&gt;
&lt;LI&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="CosminM_0-1732287238231.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/64244i4C1561A3D072251C/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="CosminM_0-1732287238231.png" alt="CosminM_0-1732287238231.png" /&gt;&lt;/span&gt;&lt;/LI&gt;
&lt;LI&gt;then on your "FW1-template" you can use it to authenticate admin users.&lt;/LI&gt;
&lt;LI&gt;when you add these two templates into your stack, it will &lt;STRONG&gt;MERGE&lt;/STRONG&gt; both configs&lt;/LI&gt;
&lt;/OL&gt;</description>
      <pubDate>Fri, 22 Nov 2024 14:56:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/template-stacks-limitations/m-p/649758#M122161</guid>
      <dc:creator>CosminM</dc:creator>
      <dc:date>2024-11-22T14:56:17Z</dc:date>
    </item>
  </channel>
</rss>

