<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Panorama commit procedure in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/panorama-commit-procedure/m-p/7953#M5873</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello minow,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To the best of my knowledge, the commit from Panorama to device works as follows :-&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;While commiting the config, the commit process should be first completed on Panorama.&lt;/P&gt;&lt;P&gt;Once the commit is completed, you can proceed with the commit of device group. While pushing the config to the device group you have the following options and their meaning as below&lt;/P&gt;&lt;P&gt;It is recommended to Preview your changes to be sure that the changes being pushed is what is required. Additionally you can put a commit lock to avoid administrators overstepping on one another&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-weight: bold;"&gt;&lt;A name="1314698"&gt;&lt;/A&gt;Merge with Candidate Config&lt;/SPAN&gt;—Choose this option to cause the device to include its local candidate configuration when the commit is invoked from Panorama. If this option is not checked, the device local candidate config is not included.And this will require a separate commit to get the local device changes pushed. It is recommended to leave this option unchecked when you have local administrators making changes on a device and you don’t want to include their changes when pushing a configuration from Panorama.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-weight: bold;"&gt;&lt;A name="1360409"&gt;&lt;/A&gt;Include Device and Network Templates&lt;/SPAN&gt;—This option is available when committing a Device Group from Panorama and is a combo operation that will include both the device and network template changes. The template that will be applied to the device is the template that the device belongs to as defined in &lt;SPAN style="font-weight: bold;"&gt;Panorama &amp;gt; Templates&lt;/SPAN&gt;. You can also select Commit Type Template to commit templates to devices. This is termed as full commit. Alternatively, you have is a partial commit, wherein you can choose not to push your template values and push only the Policy and objects.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;During the commit process, the entire config is pushed during the commit and not just the changes.&lt;/P&gt;&lt;P&gt;The commit process runs in two phases. Phase 1 is verification/validation of the config and Phase 2 as push of new configuration flash.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Below are some of the engines that process the commit change during the 2 phases&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;routed - This engine verifies and handles Routing configuration&lt;/P&gt;&lt;P&gt;ha_agent - This is necessary for HA config for HA control and Data Plane.&lt;/P&gt;&lt;P&gt;device - This engine handles the changes related management portal / Device Tab&lt;/P&gt;&lt;P&gt;ikemgr - This is used for the VPN settings&lt;/P&gt;&lt;P&gt;keymgr - This is generally used in Operational mode i.e, generating keys to provide access to device or handling Key management &lt;/P&gt;&lt;P&gt;logrcvr - This engine handles the process for local logs and log forwarding to syslog.&lt;/P&gt;&lt;P&gt;dhcpd - This is used for assignment of DHCP pool and its related config.&lt;/P&gt;&lt;P&gt;sslvpn - As the name specifies this is used to handle ssl vpn related config.&lt;/P&gt;&lt;P&gt;useridd - This is used to maintain the user - id cache and relevant config to agents and mapping of Ip to user and user to group.&lt;/P&gt;&lt;P&gt;authd -&amp;nbsp; This process handles the authentication of the user and service accounts used for cofnigurations&lt;/P&gt;&lt;P&gt;dagger - this is used to kill a process and generally used in Ops mode only.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Of the above the major commit time is used for Device and User-id Module as general observation.&lt;/P&gt;&lt;P&gt;In case more details are required you can always run the below command before initiating the commit process from Panorama,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;tail follow yes mp-log ms-log.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This command will help you how the commit is actually handled, After issuing this command run a commit from PAN. Similar what has been said earlier will be observed.&lt;/P&gt;&lt;P&gt;Hope this helps &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://live.paloaltonetworks.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Girish Vyas &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 30 Oct 2014 06:45:41 GMT</pubDate>
    <dc:creator>gvyas</dc:creator>
    <dc:date>2014-10-30T06:45:41Z</dc:date>
    <item>
      <title>Panorama commit procedure</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/panorama-commit-procedure/m-p/7947#M5867</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;hey&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;does anyone have a document that describes "step by step" the commit procedure of the panorama?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;just had a quick talk with support and apparently the commits from panorama are calculating directly to the running configuration&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 10 Aug 2014 07:10:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/panorama-commit-procedure/m-p/7947#M5867</guid>
      <dc:creator>minow</dc:creator>
      <dc:date>2014-08-10T07:10:14Z</dc:date>
    </item>
    <item>
      <title>Re: Panorama commit procedure</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/panorama-commit-procedure/m-p/7948#M5868</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Minow,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It would better &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;to commit&lt;/SPAN&gt;&lt;/SPAN&gt; the Panorama configuration local to the Panorama first &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;( &lt;/SPAN&gt;&lt;/SPAN&gt;Panorama-Candidate configuration)&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;. Then, you may proceed for a "device-group" commit to push that change into the multiple PAN firewall.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Example:&lt;/P&gt;&lt;P&gt;&lt;IMG __jive_id="14880" alt="Panorama-Commit.jpg" class="image-0 jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/14880_Panorama-Commit.jpg" style="height: 386px; width: 620px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;Reff&lt;/SPAN&gt; DOC: &lt;A href="https://live.paloaltonetworks.com/docs/DOC-5057"&gt;Panorama Administrator's Guide 5.1 (English)&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Hope this helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 11 Aug 2014 04:59:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/panorama-commit-procedure/m-p/7948#M5868</guid>
      <dc:creator>HULK</dc:creator>
      <dc:date>2014-08-11T04:59:37Z</dc:date>
    </item>
    <item>
      <title>Re: Panorama commit procedure</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/panorama-commit-procedure/m-p/7949#M5869</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;yes this one i know... you better commit on panorama after any changes at least for versions up to 6.0.3&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;me question was how the device itself handles the commit that comes from panorama... it is very unclear... if you will look at the configuration files on the devices there are a lot&lt;/P&gt;&lt;P&gt;running config&lt;/P&gt;&lt;P&gt;candidate config&lt;/P&gt;&lt;P&gt;template config&lt;/P&gt;&lt;P&gt;merge config&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt; which have lets say the final "running config"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;it is very confusing how the device will compile / merge / calculate the config that comes from panorama&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 12 Aug 2014 19:43:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/panorama-commit-procedure/m-p/7949#M5869</guid>
      <dc:creator>minow</dc:creator>
      <dc:date>2014-08-12T19:43:09Z</dc:date>
    </item>
    <item>
      <title>Re: Panorama commit procedure</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/panorama-commit-procedure/m-p/7950#M5870</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; background-color: #e3f3ff;"&gt;Hi Dor, &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; background-color: #e3f3ff;"&gt;In 6.0 commit process from Panorama should be performed the following way: &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; background-color: #e3f3ff;"&gt;- if "Merge with Candidate Config" option is disabled then config sent from Panorama is merged directly with local running-config on the firewall and then applied (committed) on MP and DP &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; background-color: #e3f3ff;"&gt;- if "Merge with Candidate Config" option is enabled config sent from Panorama is merged with candidate config and intermediate commit is done on candidate config. Then running-config is totally replaced by candidate-config. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; background-color: #e3f3ff;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; background-color: #e3f3ff;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 17 Aug 2014 09:27:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/panorama-commit-procedure/m-p/7950#M5870</guid>
      <dc:creator>djoksimovic</dc:creator>
      <dc:date>2014-08-17T09:27:22Z</dc:date>
    </item>
    <item>
      <title>Re: Panorama commit procedure</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/panorama-commit-procedure/m-p/7951#M5871</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;on the second option i do not agree..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;if we are talkin gabout the "template" config then yes but it depands on the force template values and whether this was already configured on the local device&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;if we are talking about the device-group then for sure the pushed configuration is merged with the runing-config.&lt;/P&gt;&lt;P&gt;for example:&lt;/P&gt;&lt;P&gt;i copied all the rules, obejcts to panorma and then deleted all of them from the device candidate config.&lt;/P&gt;&lt;P&gt;pushed policy to the device and the commit failed on duplicated objects&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 17 Aug 2014 10:54:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/panorama-commit-procedure/m-p/7951#M5871</guid>
      <dc:creator>minow</dc:creator>
      <dc:date>2014-08-17T10:54:33Z</dc:date>
    </item>
    <item>
      <title>Re: Panorama commit procedure</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/panorama-commit-procedure/m-p/7952#M5872</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;i have been told that since 6.0, if you copy the rule from the local device to panorama and they have the same name and you removed it from the candidate config.... commit should work fine and not alert for duplicates.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;been tried and test migration like this:&lt;/P&gt;&lt;P&gt;Template:&lt;/P&gt;&lt;P&gt;1) show all relevant configuration in "set" mode,&lt;/P&gt;&lt;P&gt;2) put them on the right location of the template&lt;/P&gt;&lt;P&gt;3) commit with "force template values"&lt;/P&gt;&lt;P&gt;4) commit without "force template values" this is very important if you will have connection problem with panorama you could just overwrite configuration locally without disabling panorama's template&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Device group:&lt;/P&gt;&lt;P&gt;1) copy all objects from the local device to the "shared" on panorma&lt;/P&gt;&lt;P&gt;2) copy the ruleset from the local device to panorama by editing the relevant location in the XML file and then importing on panorma&lt;/P&gt;&lt;P&gt;3) deleting all the rules and objects that I copied&lt;/P&gt;&lt;P&gt;4) commiting from panorma&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;finelaysing::&lt;/P&gt;&lt;P&gt;1) use the "show" command in the configureation mode and see what configuration I had missed locally on the device&lt;/P&gt;&lt;P&gt;2) if found something so migrate if to panorama &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 28 Aug 2014 06:46:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/panorama-commit-procedure/m-p/7952#M5872</guid>
      <dc:creator>minow</dc:creator>
      <dc:date>2014-08-28T06:46:59Z</dc:date>
    </item>
    <item>
      <title>Re: Panorama commit procedure</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/panorama-commit-procedure/m-p/7953#M5873</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello minow,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To the best of my knowledge, the commit from Panorama to device works as follows :-&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;While commiting the config, the commit process should be first completed on Panorama.&lt;/P&gt;&lt;P&gt;Once the commit is completed, you can proceed with the commit of device group. While pushing the config to the device group you have the following options and their meaning as below&lt;/P&gt;&lt;P&gt;It is recommended to Preview your changes to be sure that the changes being pushed is what is required. Additionally you can put a commit lock to avoid administrators overstepping on one another&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-weight: bold;"&gt;&lt;A name="1314698"&gt;&lt;/A&gt;Merge with Candidate Config&lt;/SPAN&gt;—Choose this option to cause the device to include its local candidate configuration when the commit is invoked from Panorama. If this option is not checked, the device local candidate config is not included.And this will require a separate commit to get the local device changes pushed. It is recommended to leave this option unchecked when you have local administrators making changes on a device and you don’t want to include their changes when pushing a configuration from Panorama.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-weight: bold;"&gt;&lt;A name="1360409"&gt;&lt;/A&gt;Include Device and Network Templates&lt;/SPAN&gt;—This option is available when committing a Device Group from Panorama and is a combo operation that will include both the device and network template changes. The template that will be applied to the device is the template that the device belongs to as defined in &lt;SPAN style="font-weight: bold;"&gt;Panorama &amp;gt; Templates&lt;/SPAN&gt;. You can also select Commit Type Template to commit templates to devices. This is termed as full commit. Alternatively, you have is a partial commit, wherein you can choose not to push your template values and push only the Policy and objects.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;During the commit process, the entire config is pushed during the commit and not just the changes.&lt;/P&gt;&lt;P&gt;The commit process runs in two phases. Phase 1 is verification/validation of the config and Phase 2 as push of new configuration flash.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Below are some of the engines that process the commit change during the 2 phases&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;routed - This engine verifies and handles Routing configuration&lt;/P&gt;&lt;P&gt;ha_agent - This is necessary for HA config for HA control and Data Plane.&lt;/P&gt;&lt;P&gt;device - This engine handles the changes related management portal / Device Tab&lt;/P&gt;&lt;P&gt;ikemgr - This is used for the VPN settings&lt;/P&gt;&lt;P&gt;keymgr - This is generally used in Operational mode i.e, generating keys to provide access to device or handling Key management &lt;/P&gt;&lt;P&gt;logrcvr - This engine handles the process for local logs and log forwarding to syslog.&lt;/P&gt;&lt;P&gt;dhcpd - This is used for assignment of DHCP pool and its related config.&lt;/P&gt;&lt;P&gt;sslvpn - As the name specifies this is used to handle ssl vpn related config.&lt;/P&gt;&lt;P&gt;useridd - This is used to maintain the user - id cache and relevant config to agents and mapping of Ip to user and user to group.&lt;/P&gt;&lt;P&gt;authd -&amp;nbsp; This process handles the authentication of the user and service accounts used for cofnigurations&lt;/P&gt;&lt;P&gt;dagger - this is used to kill a process and generally used in Ops mode only.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Of the above the major commit time is used for Device and User-id Module as general observation.&lt;/P&gt;&lt;P&gt;In case more details are required you can always run the below command before initiating the commit process from Panorama,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;tail follow yes mp-log ms-log.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This command will help you how the commit is actually handled, After issuing this command run a commit from PAN. Similar what has been said earlier will be observed.&lt;/P&gt;&lt;P&gt;Hope this helps &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://live.paloaltonetworks.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Girish Vyas &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 30 Oct 2014 06:45:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/panorama-commit-procedure/m-p/7953#M5873</guid>
      <dc:creator>gvyas</dc:creator>
      <dc:date>2014-10-30T06:45:41Z</dc:date>
    </item>
  </channel>
</rss>

