<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Major flaw in Panorama: can't configure anything without a real firewall added! in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/major-flaw-in-panorama-can-t-configure-anything-without-a-real/m-p/257100#M72936</link>
    <description>&lt;P&gt;1.&amp;nbsp; Create a Template.&amp;nbsp; Add some network interfaces and zones and related stuff to it.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;2.&amp;nbsp; Create a Device Group.&amp;nbsp; Add some Address Objects to it, that you'll be referenceing in your Security/NAT Policies later.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;3.&amp;nbsp; Try to create a Security/NAT Policy ... and notice how none of your Zones are available!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;There's nothing in Panorama that links Templates with Devices Groups (except for the physical firewall / managed device), which makes it pretty much useless for pre-planning and pre-configuring things before your actual firewalls arrive.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What's even worse, is that if you have actual firewalls assigned to your Devices Groups and Templates, and you remove the last firewall from a Device Group (or Template), you will never be able to commit any changes from that point onward if you have used anything from the Network tab in the Policy tab.&amp;nbsp; You get nothing but "invalid references".&amp;nbsp; You basically have to clear out the Policy tab completely whenever you remove the last device from a Device Group.&amp;nbsp; You can't keep an empty group around for future use!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;There *really* needs to be a way to link Device Groups and Templates without requiring an actual, in production physical firewall.&amp;nbsp; One should not need to wait until the hardware is there to start preparing the config for it.&amp;nbsp; This means I can't use the next 3 months to pre-configure things before we get the firewall for a new school in July, and will instead have to rush through everything in August.&amp;nbsp; Here I thought Panorama was supposed to make my life easier.&amp;nbsp; &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So, how is one supposed to write Security Policies (part of Device Group) without having access to Zones (required entry) from a Template?&amp;nbsp; I just spent the day configuring everything under Device tab, Network tab, and Objects tab, only to discover it was wasted time as I can't use any of that stuff under the Policies tab as I don't have any managed devices yet to link them together!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Tested with Panorama 7.1, 8.1, and 9.0.&lt;/P&gt;</description>
    <pubDate>Wed, 10 Apr 2019 22:41:52 GMT</pubDate>
    <dc:creator>fjwcash</dc:creator>
    <dc:date>2019-04-10T22:41:52Z</dc:date>
    <item>
      <title>Major flaw in Panorama: can't configure anything without a real firewall added!</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/major-flaw-in-panorama-can-t-configure-anything-without-a-real/m-p/257100#M72936</link>
      <description>&lt;P&gt;1.&amp;nbsp; Create a Template.&amp;nbsp; Add some network interfaces and zones and related stuff to it.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;2.&amp;nbsp; Create a Device Group.&amp;nbsp; Add some Address Objects to it, that you'll be referenceing in your Security/NAT Policies later.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;3.&amp;nbsp; Try to create a Security/NAT Policy ... and notice how none of your Zones are available!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;There's nothing in Panorama that links Templates with Devices Groups (except for the physical firewall / managed device), which makes it pretty much useless for pre-planning and pre-configuring things before your actual firewalls arrive.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What's even worse, is that if you have actual firewalls assigned to your Devices Groups and Templates, and you remove the last firewall from a Device Group (or Template), you will never be able to commit any changes from that point onward if you have used anything from the Network tab in the Policy tab.&amp;nbsp; You get nothing but "invalid references".&amp;nbsp; You basically have to clear out the Policy tab completely whenever you remove the last device from a Device Group.&amp;nbsp; You can't keep an empty group around for future use!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;There *really* needs to be a way to link Device Groups and Templates without requiring an actual, in production physical firewall.&amp;nbsp; One should not need to wait until the hardware is there to start preparing the config for it.&amp;nbsp; This means I can't use the next 3 months to pre-configure things before we get the firewall for a new school in July, and will instead have to rush through everything in August.&amp;nbsp; Here I thought Panorama was supposed to make my life easier.&amp;nbsp; &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So, how is one supposed to write Security Policies (part of Device Group) without having access to Zones (required entry) from a Template?&amp;nbsp; I just spent the day configuring everything under Device tab, Network tab, and Objects tab, only to discover it was wasted time as I can't use any of that stuff under the Policies tab as I don't have any managed devices yet to link them together!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Tested with Panorama 7.1, 8.1, and 9.0.&lt;/P&gt;</description>
      <pubDate>Wed, 10 Apr 2019 22:41:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/major-flaw-in-panorama-can-t-configure-anything-without-a-real/m-p/257100#M72936</guid>
      <dc:creator>fjwcash</dc:creator>
      <dc:date>2019-04-10T22:41:52Z</dc:date>
    </item>
    <item>
      <title>Re: Major flaw in Panorama: can't configure anything without a real firewall added!</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/major-flaw-in-panorama-can-t-configure-anything-without-a-real/m-p/257407#M73016</link>
      <description>&lt;P&gt;Hey&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/42838"&gt;@fjwcash&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I was able to reproduce the same behaviour as you, and find a fix!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1. Go to Panorama -&amp;gt; Managed Devices -&amp;gt; Summary&lt;/P&gt;&lt;P&gt;2. Add a new serial number (it doesn't even have to be a valid one just spam some numbers)&lt;/P&gt;&lt;P&gt;3. Associate your fake FW to the device group and template&lt;/P&gt;&lt;P&gt;4. Commit to Panorama&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You can now reference your zones in the policy.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;Luke.&lt;/P&gt;</description>
      <pubDate>Fri, 12 Apr 2019 12:43:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/major-flaw-in-panorama-can-t-configure-anything-without-a-real/m-p/257407#M73016</guid>
      <dc:creator>LukeBullimore</dc:creator>
      <dc:date>2019-04-12T12:43:18Z</dc:date>
    </item>
    <item>
      <title>Re: Major flaw in Panorama: can't configure anything without a real firewall added!</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/major-flaw-in-panorama-can-t-configure-anything-without-a-real/m-p/257438#M73025</link>
      <description>&lt;P&gt;Huh, didn't even think to try faking a serial number.&amp;nbsp; It's not pretty, but it does "work".&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'll have to play around with that to see how to match things up between the two groups (Templates/Devices Groups) to get inheritance working properly.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for the hint!&lt;/P&gt;</description>
      <pubDate>Fri, 12 Apr 2019 15:21:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/major-flaw-in-panorama-can-t-configure-anything-without-a-real/m-p/257438#M73025</guid>
      <dc:creator>fjwcash</dc:creator>
      <dc:date>2019-04-12T15:21:42Z</dc:date>
    </item>
    <item>
      <title>Re: Major flaw in Panorama: can't configure anything without a real firewall added!</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/major-flaw-in-panorama-can-t-configure-anything-without-a-real/m-p/257487#M73037</link>
      <description>&lt;P&gt;Even if you cannot choose the zones, you can still enter the names manually. The names will only be choosable when - as you noticed - a device is added to the devicegroup/template. The same "problem" occurs when you create policies in a parent device group where the devices are attached to child devicegroups. There you have to enter the names manually but it works as it should and the policies of the parent device groups arw also applied to the devices in the child device groups.&lt;/P&gt;</description>
      <pubDate>Fri, 12 Apr 2019 18:45:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/major-flaw-in-panorama-can-t-configure-anything-without-a-real/m-p/257487#M73037</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2019-04-12T18:45:07Z</dc:date>
    </item>
    <item>
      <title>Re: Major flaw in Panorama: can't configure anything without a real firewal</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/major-flaw-in-panorama-can-t-configure-anything-without-a-real/m-p/348416#M86729</link>
      <description>&lt;P data-unlink="true"&gt;To update this thread, in 8.1/9.0 and later code versions, there are now mechanisms called &lt;A href="https://docs.paloaltonetworks.com/panorama/8-1/panorama-admin/manage-firewalls/manage-device-groups/add-a-device-group" target="_blank" rel="noopener"&gt;Reference Templates&lt;/A&gt; (See step 4)&amp;nbsp;in each Device Group (DG) where you can specify templates to be used in the DG config. This ensures Zones, server profiles, etc, are usable in DG config.&lt;/P&gt;</description>
      <pubDate>Fri, 11 Sep 2020 00:09:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/major-flaw-in-panorama-can-t-configure-anything-without-a-real/m-p/348416#M86729</guid>
      <dc:creator>chmotley</dc:creator>
      <dc:date>2020-09-11T00:09:48Z</dc:date>
    </item>
    <item>
      <title>Re: Major flaw in Panorama: can't configure anything without a real firewal</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/major-flaw-in-panorama-can-t-configure-anything-without-a-real/m-p/348671#M86758</link>
      <description>&lt;P&gt;There is no Reference Template section in Panorama 8.1.15-h3. whether creating a new Device Group, or editing an existing one.&lt;/P&gt;</description>
      <pubDate>Fri, 11 Sep 2020 18:38:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/major-flaw-in-panorama-can-t-configure-anything-without-a-real/m-p/348671#M86758</guid>
      <dc:creator>fjwcash</dc:creator>
      <dc:date>2020-09-11T18:38:33Z</dc:date>
    </item>
  </channel>
</rss>

