<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Clear Config on new Palo in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/clear-config-on-new-palo/m-p/155302#M51102</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/39511"&gt;@Ken_Hansen&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;It's mostly industry standard at this point to have a bare bones configuration on the device to aid in setup and configuration for those new to the platform. The thought process goes that someone that is setting up the device for the first time may not be comfortable on the cli so they need to provide access to the GUI without needing any intitial config being done in the CLI interface.&lt;/P&gt;&lt;P&gt;Bootstrap is meant exactly for these types of situations where you can essentially&amp;nbsp;pre-build the&amp;nbsp;device to&amp;nbsp;be able to reach Panorama, and then use&amp;nbsp;Panorama to actually get it into the proper groups and push the config that they actually require in that&amp;nbsp;location. &amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 05 May 2017 18:30:57 GMT</pubDate>
    <dc:creator>BPry</dc:creator>
    <dc:date>2017-05-05T18:30:57Z</dc:date>
    <item>
      <title>Clear Config on new Palo</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/clear-config-on-new-palo/m-p/155253#M51075</link>
      <description>&lt;P&gt;Good Morning. Is there an easy way to clear out all configuration settings on a new Palo without having to go through the CLI to clear each item individually, or doing the same in the GUI? It is time-consuming to have to go in and delete the default Vwire, zones, and everything else that comes with a new appliance. Better yet, is it possible to order a new appliance without any configuration at all? We have appliances shipped directly to our remote locations and we build the configs in Panorama. However, pushing the configs always fails if we don't clear all of the factory settings first. To be honest, I really don't see any value in having any configuration whatsoever preinstalled on a new appliance.&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Fri, 05 May 2017 14:11:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/clear-config-on-new-palo/m-p/155253#M51075</guid>
      <dc:creator>Ken_Hansen</dc:creator>
      <dc:date>2017-05-05T14:11:32Z</dc:date>
    </item>
    <item>
      <title>Re: Clear Config on new Palo</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/clear-config-on-new-palo/m-p/155264#M51079</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You could remove all the config on the gui/cli and save the config. On the next one you ship out to site you just load in the config with items removed.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I will say though, the bootstrapping feature is available for situations like yours, do take a look:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.paloaltonetworks.com/documentation/71/pan-os/newfeaturesguide/management-features/bootstrapping-firewalls-for-rapid-deployment" target="_blank"&gt;https://www.paloaltonetworks.com/documentation/71/pan-os/newfeaturesguide/management-features/bootstrapping-firewalls-for-rapid-deployment&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;hope this helps,&lt;/P&gt;&lt;P&gt;Ben&lt;/P&gt;</description>
      <pubDate>Fri, 05 May 2017 14:41:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/clear-config-on-new-palo/m-p/155264#M51079</guid>
      <dc:creator>bmorris1</dc:creator>
      <dc:date>2017-05-05T14:41:26Z</dc:date>
    </item>
    <item>
      <title>Re: Clear Config on new Palo</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/clear-config-on-new-palo/m-p/155291#M51095</link>
      <description>&lt;P&gt;Will the bootstrap method delete the preconfigured items? We can't push our new to a new device from Panorama until they have been deleted from the device itself. I have not yet tried pushing a config from an appliance that has had everything already removed, but we are looking to eliminate as much extra work as necessary.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any idea why Palo is insistent on sending these devices out with an initial configuration? I can understand delivering a preconfigured unit for a demo or PoC trial, but not for a purchased production unit. I'd also really like to be able to delete the two default policies, which serve no purpose in a production environment.&lt;/P&gt;</description>
      <pubDate>Fri, 05 May 2017 16:31:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/clear-config-on-new-palo/m-p/155291#M51095</guid>
      <dc:creator>Ken_Hansen</dc:creator>
      <dc:date>2017-05-05T16:31:22Z</dc:date>
    </item>
    <item>
      <title>Re: Clear Config on new Palo</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/clear-config-on-new-palo/m-p/155302#M51102</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/39511"&gt;@Ken_Hansen&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;It's mostly industry standard at this point to have a bare bones configuration on the device to aid in setup and configuration for those new to the platform. The thought process goes that someone that is setting up the device for the first time may not be comfortable on the cli so they need to provide access to the GUI without needing any intitial config being done in the CLI interface.&lt;/P&gt;&lt;P&gt;Bootstrap is meant exactly for these types of situations where you can essentially&amp;nbsp;pre-build the&amp;nbsp;device to&amp;nbsp;be able to reach Panorama, and then use&amp;nbsp;Panorama to actually get it into the proper groups and push the config that they actually require in that&amp;nbsp;location. &amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 05 May 2017 18:30:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/clear-config-on-new-palo/m-p/155302#M51102</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2017-05-05T18:30:57Z</dc:date>
    </item>
    <item>
      <title>Re: Clear Config on new Palo</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/clear-config-on-new-palo/m-p/155304#M51103</link>
      <description>&lt;P&gt;I'm curious how preconfiguring Vwire interfaces and zones helps with an initial setup, not to mention security policies that I would be willing to bet the vast majority of companies put at the bottom of the rule set below their Cleanup (explicit deny) rule.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 05 May 2017 18:37:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/clear-config-on-new-palo/m-p/155304#M51103</guid>
      <dc:creator>Ken_Hansen</dc:creator>
      <dc:date>2017-05-05T18:37:43Z</dc:date>
    </item>
    <item>
      <title>Re: Clear Config on new Palo</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/clear-config-on-new-palo/m-p/155311#M51106</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/39511"&gt;@Ken_Hansen&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;My next setup I'll have to pay attention to the default config more, I don't recall seeing a vwire setup on initial boot.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 05 May 2017 20:40:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/clear-config-on-new-palo/m-p/155311#M51106</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2017-05-05T20:40:55Z</dc:date>
    </item>
    <item>
      <title>Re: Clear Config on new Palo</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/clear-config-on-new-palo/m-p/155319#M51111</link>
      <description>&lt;P&gt;it puts 1/1 and 1/2 into a vwire group. so if you were a soho, you could plug your router into 1/1 and your trusted switch into 1/2.&lt;/P&gt;</description>
      <pubDate>Fri, 05 May 2017 21:15:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/clear-config-on-new-palo/m-p/155319#M51111</guid>
      <dc:creator>bradk14</dc:creator>
      <dc:date>2017-05-05T21:15:59Z</dc:date>
    </item>
    <item>
      <title>Re: Clear Config on new Palo</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/clear-config-on-new-palo/m-p/172225#M54369</link>
      <description>&lt;P&gt;I worked through the bootstrap process yesterday without success. I'm still troubleshooting to see if I can isolate the issue. I posted another discussion on it this morning. In short, the process of preparing the USB is failing.&lt;/P&gt;</description>
      <pubDate>Fri, 18 Aug 2017 14:08:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/clear-config-on-new-palo/m-p/172225#M54369</guid>
      <dc:creator>Ken_Hansen</dc:creator>
      <dc:date>2017-08-18T14:08:31Z</dc:date>
    </item>
  </channel>
</rss>

