<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Understanding on Panorama Templates in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/re-understanding-on-panorama-templates/m-p/264043#M74406</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/91991"&gt;@Sanssj&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It is generally safe to manage everything from Panorama and everything will work in case of Panorama failure.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The local firewall keeps the following configuration files:&lt;/P&gt;&lt;P&gt;“running-config” – this is local firewall configuration&lt;/P&gt;&lt;P&gt;“sp-config” - &amp;nbsp;holds config pushed from Panorama Devcie Groups for each vsys&lt;/P&gt;&lt;P&gt;“template-config” – this is config pushed from Panorama Templates&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When you do config push from Panorama, the relevant firewall config files are updated, but then kept locally and nothing is lost if you lose connectivity to Panorama.&lt;/P&gt;&lt;P&gt;You can override template values locally on the firewall and I am not aware of a way to disable that. “Force template values” will force network and device tab config over the settings locally configured on the firewall, but will not prevent local admins to override the same values again after that.&lt;/P&gt;</description>
    <pubDate>Fri, 31 May 2019 12:15:01 GMT</pubDate>
    <dc:creator>BatD</dc:creator>
    <dc:date>2019-05-31T12:15:01Z</dc:date>
    <item>
      <title>Re: Understanding on Panorama Templates</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/re-understanding-on-panorama-templates/m-p/263846#M74404</link>
      <description>&lt;P&gt;In an event of failure of this stand alone deployed Panorama box (log collection and device management) from where will the firewall gets the the templates(Networ &amp;amp; device settings) information since I dont see this information in the local Firewall device config file.&lt;BR /&gt;is it ideal to manage the devices settings (HA, Admin roles, Authenction profiles,server profiles etc) via Panorama in a stand alone deployment or is it ideal to have them configured locally on the device.&lt;BR /&gt;&lt;BR /&gt;In the same scenario as mentioned above how do we remove the override cog wheel on the local FW device if you decide to manage everthing from Panorama. one way i could think of is " force the template values" (only when there are like to like values on the Template and on the local device) is there any other way.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 31 May 2019 07:14:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/re-understanding-on-panorama-templates/m-p/263846#M74404</guid>
      <dc:creator>Sanssj</dc:creator>
      <dc:date>2019-05-31T07:14:23Z</dc:date>
    </item>
    <item>
      <title>Re: Understanding on Panorama Templates</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/re-understanding-on-panorama-templates/m-p/264043#M74406</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/91991"&gt;@Sanssj&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It is generally safe to manage everything from Panorama and everything will work in case of Panorama failure.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The local firewall keeps the following configuration files:&lt;/P&gt;&lt;P&gt;“running-config” – this is local firewall configuration&lt;/P&gt;&lt;P&gt;“sp-config” - &amp;nbsp;holds config pushed from Panorama Devcie Groups for each vsys&lt;/P&gt;&lt;P&gt;“template-config” – this is config pushed from Panorama Templates&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When you do config push from Panorama, the relevant firewall config files are updated, but then kept locally and nothing is lost if you lose connectivity to Panorama.&lt;/P&gt;&lt;P&gt;You can override template values locally on the firewall and I am not aware of a way to disable that. “Force template values” will force network and device tab config over the settings locally configured on the firewall, but will not prevent local admins to override the same values again after that.&lt;/P&gt;</description>
      <pubDate>Fri, 31 May 2019 12:15:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/re-understanding-on-panorama-templates/m-p/264043#M74406</guid>
      <dc:creator>BatD</dc:creator>
      <dc:date>2019-05-31T12:15:01Z</dc:date>
    </item>
  </channel>
</rss>

