<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Total Objects and Device Groups in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/total-objects-and-device-groups/m-p/256625#M72822</link>
    <description>&lt;P&gt;That works only if we're deleting from the local firewalls, but we're trying to delete panorama objects and its impossible to tell if they're used locally on the firewalls, unless we go through each of the objects manually on the local devices (which we're trying to avoid).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;That was the original thing we attempted, but we were running into SO many objects still used on the local devices, that it just wasn't feasable anymore.&lt;/P&gt;</description>
    <pubDate>Mon, 08 Apr 2019 16:15:50 GMT</pubDate>
    <dc:creator>mjanik01</dc:creator>
    <dc:date>2019-04-08T16:15:50Z</dc:date>
    <item>
      <title>Total Objects and Device Groups</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/total-objects-and-device-groups/m-p/256109#M72655</link>
      <description>&lt;P&gt;Hello! I want to start this off for apologizing if i do anything wrong here or miss any processes as this is my first post.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I had the question for the community to see if anyone has ever ran into something like this, or what my best course of action would be.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We started migrating our environment off of the PA-500's to PA-220's (in the effort to keep cost down in very small sites that we have), but one thing that we didn't expect to run into is hitting the object limit of only 2500 objects.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So the steps we have taken so far are to create two device groups, one for the larger devices in our environment and one for the smaller...but now we have the task of converting the objects that aren't in use on the smaller devices to the larger device group, and also out of our shared group.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Does anyone know of a quicker or more efficient way to handle this instead of having to manually go through each object, do a global find, and create a new object and rule while deleting the old one.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any help in the right direction would be greatly apprecaited.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you!&lt;/P&gt;&lt;P&gt;-Matt&lt;/P&gt;</description>
      <pubDate>Thu, 04 Apr 2019 16:54:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/total-objects-and-device-groups/m-p/256109#M72655</guid>
      <dc:creator>mjanik01</dc:creator>
      <dc:date>2019-04-04T16:54:45Z</dc:date>
    </item>
    <item>
      <title>Re: Total Objects and Device Groups</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/total-objects-and-device-groups/m-p/256118#M72657</link>
      <description>&lt;P&gt;Export the objects via CLI to text, you can use that to create a script to create or remove them on whichever host you like.&lt;/P&gt;</description>
      <pubDate>Thu, 04 Apr 2019 17:34:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/total-objects-and-device-groups/m-p/256118#M72657</guid>
      <dc:creator>BoDollis</dc:creator>
      <dc:date>2019-04-04T17:34:38Z</dc:date>
    </item>
    <item>
      <title>Re: Total Objects and Device Groups</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/total-objects-and-device-groups/m-p/256463#M72759</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/59517"&gt;@mjanik01&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In panorama there is an option called "Share unused address and service objects with devices". If you disable this option panorama pushes only the required objects to the firewalls.&lt;/P&gt;&lt;P&gt;--&amp;gt; &lt;A href="https://docs.paloaltonetworks.com/panorama/8-0/panorama-admin/manage-firewalls/manage-device-groups/manage-unused-shared-objects" target="_blank"&gt;https://docs.paloaltonetworks.com/panorama/8-0/panorama-admin/manage-firewalls/manage-device-groups/manage-unused-shared-objects&lt;/A&gt;&lt;/P&gt;&lt;P&gt;(This requires that you also manage the policies in panorama and not only the objects because only this way panorama is able to know whitch objects need to be pushed)&lt;/P&gt;</description>
      <pubDate>Sat, 06 Apr 2019 22:17:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/total-objects-and-device-groups/m-p/256463#M72759</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2019-04-06T22:17:50Z</dc:date>
    </item>
    <item>
      <title>Re: Total Objects and Device Groups</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/total-objects-and-device-groups/m-p/256605#M72814</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/16592"&gt;@Remo&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Does disabling this option remove the unused objects from the devices?&lt;/P&gt;</description>
      <pubDate>Mon, 08 Apr 2019 15:24:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/total-objects-and-device-groups/m-p/256605#M72814</guid>
      <dc:creator>cenectro</dc:creator>
      <dc:date>2019-04-08T15:24:26Z</dc:date>
    </item>
    <item>
      <title>Re: Total Objects and Device Groups</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/total-objects-and-device-groups/m-p/256609#M72817</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Part of the problem is we still have local policies on our firewalls (we are currently in the process of trying to clean that up, migrating everything into panorama but there ARE still objects used in local policies.&lt;/P&gt;</description>
      <pubDate>Mon, 08 Apr 2019 15:33:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/total-objects-and-device-groups/m-p/256609#M72817</guid>
      <dc:creator>mjanik01</dc:creator>
      <dc:date>2019-04-08T15:33:28Z</dc:date>
    </item>
    <item>
      <title>Re: Total Objects and Device Groups</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/total-objects-and-device-groups/m-p/256622#M72820</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/108057"&gt;@cenectro&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Disabling that option removes the unused objects from the firewall and will stop sharing the objects that aren't used in policies with the device.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 08 Apr 2019 16:01:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/total-objects-and-device-groups/m-p/256622#M72820</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2019-04-08T16:01:09Z</dc:date>
    </item>
    <item>
      <title>Re: Total Objects and Device Groups</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/total-objects-and-device-groups/m-p/256623#M72821</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/59517"&gt;@mjanik01&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;For the local objects, the firewall won't allow you to remove an address object if you attempt to delete it if it's still being used in policy. So you could actually attempt to mass delete any object that is on the firewall and as long as it doesn't throw an error it shouldn't be utilized in policy at all.&lt;/P&gt;&lt;P&gt;The only time I've seen this cause any issues is if you have a dested address-group as a member of an address-group. The firewall at that point isn't smart enough to realize that it's an in-use address object.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 08 Apr 2019 16:05:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/total-objects-and-device-groups/m-p/256623#M72821</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2019-04-08T16:05:10Z</dc:date>
    </item>
    <item>
      <title>Re: Total Objects and Device Groups</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/total-objects-and-device-groups/m-p/256625#M72822</link>
      <description>&lt;P&gt;That works only if we're deleting from the local firewalls, but we're trying to delete panorama objects and its impossible to tell if they're used locally on the firewalls, unless we go through each of the objects manually on the local devices (which we're trying to avoid).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;That was the original thing we attempted, but we were running into SO many objects still used on the local devices, that it just wasn't feasable anymore.&lt;/P&gt;</description>
      <pubDate>Mon, 08 Apr 2019 16:15:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/total-objects-and-device-groups/m-p/256625#M72822</guid>
      <dc:creator>mjanik01</dc:creator>
      <dc:date>2019-04-08T16:15:50Z</dc:date>
    </item>
    <item>
      <title>Re: Total Objects and Device Groups</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/total-objects-and-device-groups/m-p/256626#M72823</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/59517"&gt;@mjanik01&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Got it. I assumed that the local objects would only be used in local policy on the firewalls themselves. If you've mixed Panorama objects with local policies things get much more complicated.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;A faster way of doing this would be to dump the XML configuration files and dumping the Panorama objects. This would give you a list of searchable objects at least, instead of having to be logged into every single device.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 08 Apr 2019 16:24:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/total-objects-and-device-groups/m-p/256626#M72823</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2019-04-08T16:24:34Z</dc:date>
    </item>
    <item>
      <title>Re: Total Objects and Device Groups</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/total-objects-and-device-groups/m-p/256630#M72825</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/108057"&gt;@cenectro&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Script it!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Foreach $object in $panoramaobjects {&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;Foreach $firewall in $firewalls {&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; If ($object is in use) {&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Write-to-log ($object is used on $firewall)&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; }&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;}&lt;/P&gt;&lt;P&gt;}&lt;/P&gt;</description>
      <pubDate>Mon, 08 Apr 2019 17:19:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/total-objects-and-device-groups/m-p/256630#M72825</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2019-04-08T17:19:27Z</dc:date>
    </item>
    <item>
      <title>Re: Total Objects and Device Groups</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/total-objects-and-device-groups/m-p/257233#M72970</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Forgive my ignorance here (as i'm no programmer or anything by any means),&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;but trying to follow that logic in what you put below, i feel thats the opposite of what we want. we want to know which objects are NOT in use, by both panorama and the local firewalls themselves (which is the part of this thats a giant pain).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you!&lt;/P&gt;</description>
      <pubDate>Thu, 11 Apr 2019 14:08:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/total-objects-and-device-groups/m-p/257233#M72970</guid>
      <dc:creator>mjanik01</dc:creator>
      <dc:date>2019-04-11T14:08:37Z</dc:date>
    </item>
    <item>
      <title>Re: Total Objects and Device Groups</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/total-objects-and-device-groups/m-p/257299#M72993</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/59517"&gt;@mjanik01&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Yo're right. It should be more like this pseudocode:&lt;/P&gt;&lt;P&gt;Foreach $object in $panoramaobjects {&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;Foreach $firewall in $firewalls {&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; If ($object is not in use)&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Delete-fw-object($object,$firewall)&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Delete-panlrama-object($object,$panorama)&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; }&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;}&lt;/P&gt;&lt;P&gt;}&lt;/P&gt;</description>
      <pubDate>Thu, 11 Apr 2019 17:02:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/total-objects-and-device-groups/m-p/257299#M72993</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2019-04-11T17:02:25Z</dc:date>
    </item>
  </channel>
</rss>

