<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Panorama 8.0.2 Managing PAN-OS 7.1.10 - Aggregate Ethernet AEx has no member interfaces in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/panorama-8-0-2-managing-pan-os-7-1-10-aggregate-ethernet-aex-has/m-p/163115#M52840</link>
    <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/36590"&gt;@acc6d0b3610eec313831f7900fdbd235&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Do you see the same warning also locally on the firewall for the commit-all job?&lt;/P&gt;&lt;P&gt;Did you (or another admin accidentially) push the configuration already when you haven't added the interfaces to the AE group, so that this warning is not from rhe newest commit-all?&lt;/P&gt;</description>
    <pubDate>Sat, 24 Jun 2017 19:39:36 GMT</pubDate>
    <dc:creator>Remo</dc:creator>
    <dc:date>2017-06-24T19:39:36Z</dc:date>
    <item>
      <title>Panorama 8.0.2 Managing PAN-OS 7.1.10 - Aggregate Ethernet AEx has no member interfaces</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/panorama-8-0-2-managing-pan-os-7-1-10-aggregate-ethernet-aex-has/m-p/163108#M52839</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am currently working with customer, who had an existing Panorama implementation that was upgraded from 7.1.7 to 8.0.2. The reason for the upgrade was due to the certificate expiration, take too place on June 16. The new HA pair I am implementing are running PAN-OS 7.1.10.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I need to configure an aggregate interface in the HA pair for their DMZ switch. We do not need sub-interface (Tagging) as it will be a direct connection. I did create the AE3, and then added the E1/1 and E1/2 to the AE group. I configured the AE3 as Layer 3 with an IP address as it will be the default gateway for the servers sitting in the DMZ. LACP is also enabled in the aggregate group.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When I push the policy template from Panorama to the HA pair, Panorama returns the following warning: &lt;STRONG&gt;"Aggregate Ethernet AE3 has no member interfaces".&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="Screen Shot 2017-06-24 at 11.13.40 AM.png" style="width: 500px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/9920i6A3E818C699BDDBC/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Screen Shot 2017-06-24 at 11.13.40 AM.png" alt="Screen Shot 2017-06-24 at 11.13.40 AM.png" /&gt;&lt;/span&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;When I log in the Active firewall, and look at the interface list, I can see that the template was applied and the interfaces are associated to AE3.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screen Shot 2017-06-24 at 11.28.55 AM.png" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/9921i94CFEFCE84206166/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Screen Shot 2017-06-24 at 11.28.55 AM.png" alt="Screen Shot 2017-06-24 at 11.28.55 AM.png" /&gt;&lt;/span&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;Does anyone have any idea what the problem may be?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 24 Jun 2017 18:33:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/panorama-8-0-2-managing-pan-os-7-1-10-aggregate-ethernet-aex-has/m-p/163108#M52839</guid>
      <dc:creator>acc6d0b3610eec313831f7900fdbd235</dc:creator>
      <dc:date>2017-06-24T18:33:54Z</dc:date>
    </item>
    <item>
      <title>Re: Panorama 8.0.2 Managing PAN-OS 7.1.10 - Aggregate Ethernet AEx has no member interfaces</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/panorama-8-0-2-managing-pan-os-7-1-10-aggregate-ethernet-aex-has/m-p/163115#M52840</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/36590"&gt;@acc6d0b3610eec313831f7900fdbd235&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Do you see the same warning also locally on the firewall for the commit-all job?&lt;/P&gt;&lt;P&gt;Did you (or another admin accidentially) push the configuration already when you haven't added the interfaces to the AE group, so that this warning is not from rhe newest commit-all?&lt;/P&gt;</description>
      <pubDate>Sat, 24 Jun 2017 19:39:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/panorama-8-0-2-managing-pan-os-7-1-10-aggregate-ethernet-aex-has/m-p/163115#M52840</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2017-06-24T19:39:36Z</dc:date>
    </item>
    <item>
      <title>Re: Panorama 8.0.2 Managing PAN-OS 7.1.10 - Aggregate Ethernet AEx has no member interfaces</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/panorama-8-0-2-managing-pan-os-7-1-10-aggregate-ethernet-aex-has/m-p/163118#M52841</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/16592"&gt;@Remo&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for the hints. You are completely right.&amp;nbsp;I was not seen the same error locally, but I did notice some disparaty between the template and the local configuration.&lt;/P&gt;&lt;P&gt;When I tried to push the configuration locally, it pointed some lose sub-interfaces in the VR that did not exist in the template and locally either.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I had to&amp;nbsp;remove them from the VR, as well as from the zone configuration. Also, because the VR and the Zone had been overriden, I had to revert it to Panorama to apply the correct changes.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Because of the above issues, although in the template I had the zone and virtual-router assigned, this part of the configuration was not being pushed to the appliance.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Panorama Template Configuration&lt;/STRONG&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="Screen Shot 2017-06-24 at 12.14.59 PM.png" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/9922i14A7A814FCB070D7/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Screen Shot 2017-06-24 at 12.14.59 PM.png" alt="Screen Shot 2017-06-24 at 12.14.59 PM.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;PA1 Interface Configuration&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="Screen Shot 2017-06-24 at 11.28.55 AM.png" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/9923i661A1BCAB89F04C2/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Screen Shot 2017-06-24 at 11.28.55 AM.png" alt="Screen Shot 2017-06-24 at 11.28.55 AM.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;I am trying to find out, what happend with the previous option "Force Template Values" that is present on Panorama PAN-OS 7.1.x. I don't see this option in the 8.0.x.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/16592"&gt;@Remo&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 24 Jun 2017 19:46:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/panorama-8-0-2-managing-pan-os-7-1-10-aggregate-ethernet-aex-has/m-p/163118#M52841</guid>
      <dc:creator>acc6d0b3610eec313831f7900fdbd235</dc:creator>
      <dc:date>2017-06-24T19:46:49Z</dc:date>
    </item>
    <item>
      <title>Re: Panorama 8.0.2 Managing PAN-OS 7.1.10 - Aggregate Ethernet AEx has no member interfaces</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/panorama-8-0-2-managing-pan-os-7-1-10-aggregate-ethernet-aex-has/m-p/163120#M52843</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/36590"&gt;@acc6d0b3610eec313831f7900fdbd235&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I also noticed this behaviour also with PAN-OS 8.0.2 firewalls, that the panorama push state does not always show the same as locally and I dven had the other situation where I had all good in panorama but some warnings locally.&lt;/P&gt;&lt;P&gt;At least your problem is solved now &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Remo&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;PS: The option " Force template values" will be shown when you click "edit selection" in the push/commit-and-push window&lt;/P&gt;</description>
      <pubDate>Sat, 24 Jun 2017 20:13:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/panorama-8-0-2-managing-pan-os-7-1-10-aggregate-ethernet-aex-has/m-p/163120#M52843</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2017-06-24T20:13:43Z</dc:date>
    </item>
  </channel>
</rss>

