<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Assigning security profile to multiple security rules in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/assigning-security-profile-to-multiple-security-rules/m-p/227886#M65549</link>
    <description>&lt;P&gt;Or Panorama if you have it.&lt;/P&gt;</description>
    <pubDate>Wed, 22 Aug 2018 14:09:40 GMT</pubDate>
    <dc:creator>OtakarKlier</dc:creator>
    <dc:date>2018-08-22T14:09:40Z</dc:date>
    <item>
      <title>Assigning security profile to multiple security rules</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/assigning-security-profile-to-multiple-security-rules/m-p/227865#M65543</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp; when you have 100-200 security rule and need to assign a threat security profile to all the rules, what do you do?&lt;/P&gt;&lt;P&gt;Does anyone know an easy way of doing it? I can either script it via XML API but there should be an easier way I think.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thanks.&lt;/P&gt;</description>
      <pubDate>Wed, 22 Aug 2018 12:28:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/assigning-security-profile-to-multiple-security-rules/m-p/227865#M65543</guid>
      <dc:creator>tirexxerit</dc:creator>
      <dc:date>2018-08-22T12:28:51Z</dc:date>
    </item>
    <item>
      <title>Re: Assigning security profile to multiple security rules</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/assigning-security-profile-to-multiple-security-rules/m-p/227876#M65545</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;If they already have assigned a Group or Profile, you can just modify it, that way it will get applied. If you currently do not have any applied and need to apply one you can either do it by the XML method you mentioned, or I think there could be a way to script it via the API, but thats an area where I dont delve into. But I'm sure others may have another method.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Wed, 22 Aug 2018 13:24:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/assigning-security-profile-to-multiple-security-rules/m-p/227876#M65545</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2018-08-22T13:24:20Z</dc:date>
    </item>
    <item>
      <title>Re: Assigning security profile to multiple security rules</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/assigning-security-profile-to-multiple-security-rules/m-p/227884#M65548</link>
      <description>&lt;P&gt;No profile is attached actually and need to assign group profile to multiple firewalls.&lt;/P&gt;&lt;P&gt;There is a nice feature on URL filtering profile for example. You choose the action and say apply the action to all categories&lt;/P&gt;&lt;P&gt;which is quite handy but couldn't see such for security rules yet. Maybe on the roadmap.&lt;/P&gt;&lt;P&gt;If there is no built-in method, then I need to look into API.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thanks.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 22 Aug 2018 13:42:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/assigning-security-profile-to-multiple-security-rules/m-p/227884#M65548</guid>
      <dc:creator>tirexxerit</dc:creator>
      <dc:date>2018-08-22T13:42:41Z</dc:date>
    </item>
    <item>
      <title>Re: Assigning security profile to multiple security rules</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/assigning-security-profile-to-multiple-security-rules/m-p/227886#M65549</link>
      <description>&lt;P&gt;Or Panorama if you have it.&lt;/P&gt;</description>
      <pubDate>Wed, 22 Aug 2018 14:09:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/assigning-security-profile-to-multiple-security-rules/m-p/227886#M65549</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2018-08-22T14:09:40Z</dc:date>
    </item>
    <item>
      <title>Re: Assigning security profile to multiple security rules</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/assigning-security-profile-to-multiple-security-rules/m-p/227892#M65551</link>
      <description>&lt;P&gt;I don't recall that panorama has such feature. If you don't mean assigning to device group and pushing it to multiple devices.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 22 Aug 2018 14:24:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/assigning-security-profile-to-multiple-security-rules/m-p/227892#M65551</guid>
      <dc:creator>tirexxerit</dc:creator>
      <dc:date>2018-08-22T14:24:35Z</dc:date>
    </item>
    <item>
      <title>Re: Assigning security profile to multiple security rules</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/assigning-security-profile-to-multiple-security-rules/m-p/227893#M65552</link>
      <description>&lt;P&gt;Sorry I didnt specify. If you have Panorama, you could make all the changes there and push those changes out to the different managed firewalls. However you would still need to assign the profiles to the different policies.&lt;/P&gt;</description>
      <pubDate>Wed, 22 Aug 2018 14:26:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/assigning-security-profile-to-multiple-security-rules/m-p/227893#M65552</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2018-08-22T14:26:39Z</dc:date>
    </item>
    <item>
      <title>Re: Assigning security profile to multiple security rules</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/assigning-security-profile-to-multiple-security-rules/m-p/227895#M65553</link>
      <description>&lt;P&gt;I've done this two ways, depending on how many times it will need to be done.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The way i've done it when tehre are many firewalls or device groups to update is via scripting and teh XML API - I pull the policies with powershell, iterate through the policies adding the profiles or profile group, then push them back to teh firewall or panorama.&amp;nbsp; it's pretty quick.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If there is only one or two to do:&lt;/P&gt;&lt;P&gt;log into the CLI&lt;/P&gt;&lt;P&gt;issue the command "set cli config-output-format set" so that when you view the configuration it give set commands&lt;/P&gt;&lt;P&gt;enter edit mode&lt;/P&gt;&lt;P&gt;"show vsys vsys1 rulebase security | match 'action allow'" - this should give you a "list" of your rules, copy that to a text editor, so you can repalce "action allow" with 'profile-setting group "&amp;lt;your profile group&amp;gt;"' or the appropriate command to set the profile(s) you want.&lt;/P&gt;&lt;P&gt;paste the commands back into the firewall - be aware the buffer is relatively small, take 10-15 lines at a time&lt;/P&gt;</description>
      <pubDate>Wed, 22 Aug 2018 14:59:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/assigning-security-profile-to-multiple-security-rules/m-p/227895#M65553</guid>
      <dc:creator>JoeAndreini</dc:creator>
      <dc:date>2018-08-22T14:59:46Z</dc:date>
    </item>
    <item>
      <title>Re: Assigning security profile to multiple security rules</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/assigning-security-profile-to-multiple-security-rules/m-p/227911#M65558</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/80006"&gt;@tirexxerit&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;In addition to the method already specified by&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/83021"&gt;@JoeAndreini&lt;/a&gt;:&lt;/P&gt;&lt;P&gt;1)&amp;nbsp;You could use Expedition (The migration tool) and do this easily. Depending on experiance with the API or modifying the XML this would actually be my preffered method.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;2) You could modify the XML directly and simply look in every entry within &amp;lt;security&amp;gt; and ensure that it has a &amp;lt;profile-setting&amp;gt; element. If you're comfortable with XML this is my preffered method.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;API scripts are great but you have to be very careful that it doesn't actually give a bad result on the rules. Making a script that accounts for these expections with the API can be a bit of a pain.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 22 Aug 2018 16:47:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/assigning-security-profile-to-multiple-security-rules/m-p/227911#M65558</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2018-08-22T16:47:52Z</dc:date>
    </item>
    <item>
      <title>Re: Assigning security profile to multiple security rules</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/assigning-security-profile-to-multiple-security-rules/m-p/227978#M65572</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/83021"&gt;@JoeAndreini&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;be aware the buffer is relatively small, take 10-15 lines at a time&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;... or if you're using a SSH client that has this feature, set a delay of 150ms between the commands&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 22 Aug 2018 22:07:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/assigning-security-profile-to-multiple-security-rules/m-p/227978#M65572</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2018-08-22T22:07:06Z</dc:date>
    </item>
    <item>
      <title>Re: Assigning security profile to multiple security rules</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/assigning-security-profile-to-multiple-security-rules/m-p/227986#M65574</link>
      <description>&lt;P&gt;or use scripting-mode :&lt;EM&gt; set cli scripting-mode on&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I never remember this exact command and often&amp;nbsp;just paste 20 lines at a time rather than google it..&lt;/P&gt;</description>
      <pubDate>Wed, 22 Aug 2018 22:39:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/assigning-security-profile-to-multiple-security-rules/m-p/227986#M65574</guid>
      <dc:creator>JoeAndreini</dc:creator>
      <dc:date>2018-08-22T22:39:24Z</dc:date>
    </item>
  </channel>
</rss>

