<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Adding a sub-interface to an exsiting Security Zone in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/adding-a-sub-interface-to-an-exsiting-security-zone/m-p/239371#M68549</link>
    <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/101322"&gt;@vvadia&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Yes, you can change the zone locally and do a commit. And take the time afterwards to bring the config manually in sync so that you will be able to do the changes again on panorama.&lt;/P&gt;</description>
    <pubDate>Sat, 10 Nov 2018 13:53:31 GMT</pubDate>
    <dc:creator>Remo</dc:creator>
    <dc:date>2018-11-10T13:53:31Z</dc:date>
    <item>
      <title>Adding a sub-interface to an exsiting Security Zone</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/adding-a-sub-interface-to-an-exsiting-security-zone/m-p/239357#M68543</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have a Palo Alto with existing security zones managed via Panorama. I need to add an existing sub-interface to an existing security zone which has been done on Panorama and committed. However, after logging into the firewall node directly the sub-interface does not show it has been assigned to the security zone.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Are templates only used to make firewall nodes aware of zones and assigning interfaces, sub-interfaces to zones has to be done locally on the firewalls?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I've been unable to find any clear documentation on this.&lt;/P&gt;</description>
      <pubDate>Sat, 10 Nov 2018 12:32:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/adding-a-sub-interface-to-an-exsiting-security-zone/m-p/239357#M68543</guid>
      <dc:creator>vvadia</dc:creator>
      <dc:date>2018-11-10T12:32:49Z</dc:date>
    </item>
    <item>
      <title>Re: Adding a sub-interface to an exsiting Security Zone</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/adding-a-sub-interface-to-an-exsiting-security-zone/m-p/239364#M68544</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/101322"&gt;@vvadia&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Local on the firewall, is there only a green or a green and orange gear showing at the interface that you want to change?&lt;/P&gt;</description>
      <pubDate>Sat, 10 Nov 2018 12:39:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/adding-a-sub-interface-to-an-exsiting-security-zone/m-p/239364#M68544</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2018-11-10T12:39:00Z</dc:date>
    </item>
    <item>
      <title>Re: Adding a sub-interface to an exsiting Security Zone</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/adding-a-sub-interface-to-an-exsiting-security-zone/m-p/239365#M68545</link>
      <description>Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/16592"&gt;@Remo&lt;/a&gt; When I log into the firewall locally, I can see there are green &amp;amp; orange gears in "Interfaces" and in "zones" sections. Kind Regards,</description>
      <pubDate>Sat, 10 Nov 2018 12:53:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/adding-a-sub-interface-to-an-exsiting-security-zone/m-p/239365#M68545</guid>
      <dc:creator>vvadia</dc:creator>
      <dc:date>2018-11-10T12:53:01Z</dc:date>
    </item>
    <item>
      <title>Re: Adding a sub-interface to an exsiting Security Zone</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/adding-a-sub-interface-to-an-exsiting-security-zone/m-p/239367#M68546</link>
      <description>&lt;P&gt;This means the config was changed locally. You need to remove the local config override to bring it again in sync with the panorama config. Then you will be able to configure and also push changes to the firewall from panorama.&lt;/P&gt;</description>
      <pubDate>Sat, 10 Nov 2018 13:18:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/adding-a-sub-interface-to-an-exsiting-security-zone/m-p/239367#M68546</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2018-11-10T13:18:04Z</dc:date>
    </item>
    <item>
      <title>Re: Adding a sub-interface to an exsiting Security Zone</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/adding-a-sub-interface-to-an-exsiting-security-zone/m-p/239368#M68547</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Hi&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/16592" target="_blank"&gt;@vsys_remo&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for the explanation, I guess at some point someone else has changed something locally. It does seem that adding IP objects to groups is not impacted by this as I can see that has been updated locally on the firewall, only assigning a zone to an interface is impacted.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For now, reading up on this, there is an element of risk to this, I don't want to be in a situation where I lose the configuration on the firewall. Strategically this does need to get fixed.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;However, for a tactical solution I need to get working asap, would it be ok to manually assign the sub-interface to a zone? Does this only require a save or a local commit as well?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 10 Nov 2018 13:36:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/adding-a-sub-interface-to-an-exsiting-security-zone/m-p/239368#M68547</guid>
      <dc:creator>vvadia</dc:creator>
      <dc:date>2018-11-10T13:36:10Z</dc:date>
    </item>
    <item>
      <title>Re: Adding a sub-interface to an exsiting Security Zone</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/adding-a-sub-interface-to-an-exsiting-security-zone/m-p/239369#M68548</link>
      <description>&lt;P&gt;Actually looking at all the interfaces and sub-interfaces they all have a green/orange cog :s&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 10 Nov 2018 13:44:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/adding-a-sub-interface-to-an-exsiting-security-zone/m-p/239369#M68548</guid>
      <dc:creator>vvadia</dc:creator>
      <dc:date>2018-11-10T13:44:00Z</dc:date>
    </item>
    <item>
      <title>Re: Adding a sub-interface to an exsiting Security Zone</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/adding-a-sub-interface-to-an-exsiting-security-zone/m-p/239371#M68549</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/101322"&gt;@vvadia&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Yes, you can change the zone locally and do a commit. And take the time afterwards to bring the config manually in sync so that you will be able to do the changes again on panorama.&lt;/P&gt;</description>
      <pubDate>Sat, 10 Nov 2018 13:53:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/adding-a-sub-interface-to-an-exsiting-security-zone/m-p/239371#M68549</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2018-11-10T13:53:31Z</dc:date>
    </item>
  </channel>
</rss>

