<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Import existing config into Panorama woes in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/import-existing-config-into-panorama-woes/m-p/289817#M77036</link>
    <description>&lt;P&gt;We have a handful of standalone PAs that we want to import into Panorama.&amp;nbsp; &amp;nbsp;However in our first interation it failed with the following errors and I am not sure why.&amp;nbsp; The entire process isn't made clear to me either via PA (like a lot of their stuff but I digress) so I was wondering if anyone has done this and can help point me in the right direction?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Commit/validation fails on the following items on the firewall after import/export back to it from the Panorama:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;Validation Error:
log-settings -&amp;gt; profiles -&amp;gt; Forward to Panorama and Email -&amp;gt; match-list -&amp;gt; test-Alerts -&amp;gt; send-email 'Test Alerts' is not a valid reference
log-settings -&amp;gt; profiles -&amp;gt; Forward to Panorama and Email -&amp;gt; match-list -&amp;gt; test-Alerts -&amp;gt; send-email is invalid
log-settings -&amp;gt; profiles -&amp;gt; Forward to Panorama and Email -&amp;gt; match-list is invalid
log-settings -&amp;gt; profiles is invalid
log-settings is invalid
shared is invalid
rulebase -&amp;gt; security -&amp;gt; rules -&amp;gt; outbound-block-all -&amp;gt; from 'trust' is not an allowed keyword
rulebase -&amp;gt; security -&amp;gt; rules -&amp;gt; outbound-block-all -&amp;gt; from 'trust' is not a valid reference
rulebase -&amp;gt; security -&amp;gt; rules -&amp;gt; outbound-block-all -&amp;gt; from is invalid
rulebase -&amp;gt; security -&amp;gt; rules -&amp;gt; outbound-block-all -&amp;gt; to 'untrust' is not an allowed keyword
rulebase -&amp;gt; security -&amp;gt; rules -&amp;gt; outbound-block-all -&amp;gt; to 'untrust' is not a valid reference
rulebase -&amp;gt; security -&amp;gt; rules -&amp;gt; outbound-block-all -&amp;gt; to is invalid
rulebase -&amp;gt; security -&amp;gt; rules -&amp;gt; untrust-block-all -&amp;gt; from 'untrust' is not an allowed keyword
rulebase -&amp;gt; security -&amp;gt; rules -&amp;gt; untrust-block-all -&amp;gt; from 'untrust' is not a valid reference
rulebase -&amp;gt; security -&amp;gt; rules -&amp;gt; untrust-block-all -&amp;gt; from is invalid
rulebase -&amp;gt; security -&amp;gt; rules is invalid
rulebase -&amp;gt; security is invalid
rulebase is invalid
vsys is invalid
devices is invalid
In VSYS vsys1 from zone trust of type unknown and to zone untrust of type unknown are incompatible in security rule outbound-block-all
Configuration is invalid&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="pan-post.JPG" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/21530iD6276493764D80C8/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="pan-post.JPG" alt="pan-post.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;2 errors when trying to do this, both of which appear to be originating from the PAN &amp;gt; FW.&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;The first one is a log setting on the 'outbound-block-all' rule on the PAN.&amp;nbsp; That specific log settings doesn't exist on the FW.&amp;nbsp;&lt;/LI&gt;&lt;LI&gt;Again same rule that is already on the PAN in 'Post Rules,' its shared between all of our existing DGs on the PAN.&amp;nbsp; &amp;nbsp;The only difference between the zones on the FW and the PAN is the first letter is capitalized which I assume is why it chokes?&amp;nbsp;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;I changed the zone names to match on the FW but not sure what to do about the log/email settings?&amp;nbsp; Also not sure why its complaining about 'shared' as well.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 24 Sep 2019 14:25:55 GMT</pubDate>
    <dc:creator>drewdown</dc:creator>
    <dc:date>2019-09-24T14:25:55Z</dc:date>
    <item>
      <title>Import existing config into Panorama woes</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/import-existing-config-into-panorama-woes/m-p/289817#M77036</link>
      <description>&lt;P&gt;We have a handful of standalone PAs that we want to import into Panorama.&amp;nbsp; &amp;nbsp;However in our first interation it failed with the following errors and I am not sure why.&amp;nbsp; The entire process isn't made clear to me either via PA (like a lot of their stuff but I digress) so I was wondering if anyone has done this and can help point me in the right direction?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Commit/validation fails on the following items on the firewall after import/export back to it from the Panorama:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;Validation Error:
log-settings -&amp;gt; profiles -&amp;gt; Forward to Panorama and Email -&amp;gt; match-list -&amp;gt; test-Alerts -&amp;gt; send-email 'Test Alerts' is not a valid reference
log-settings -&amp;gt; profiles -&amp;gt; Forward to Panorama and Email -&amp;gt; match-list -&amp;gt; test-Alerts -&amp;gt; send-email is invalid
log-settings -&amp;gt; profiles -&amp;gt; Forward to Panorama and Email -&amp;gt; match-list is invalid
log-settings -&amp;gt; profiles is invalid
log-settings is invalid
shared is invalid
rulebase -&amp;gt; security -&amp;gt; rules -&amp;gt; outbound-block-all -&amp;gt; from 'trust' is not an allowed keyword
rulebase -&amp;gt; security -&amp;gt; rules -&amp;gt; outbound-block-all -&amp;gt; from 'trust' is not a valid reference
rulebase -&amp;gt; security -&amp;gt; rules -&amp;gt; outbound-block-all -&amp;gt; from is invalid
rulebase -&amp;gt; security -&amp;gt; rules -&amp;gt; outbound-block-all -&amp;gt; to 'untrust' is not an allowed keyword
rulebase -&amp;gt; security -&amp;gt; rules -&amp;gt; outbound-block-all -&amp;gt; to 'untrust' is not a valid reference
rulebase -&amp;gt; security -&amp;gt; rules -&amp;gt; outbound-block-all -&amp;gt; to is invalid
rulebase -&amp;gt; security -&amp;gt; rules -&amp;gt; untrust-block-all -&amp;gt; from 'untrust' is not an allowed keyword
rulebase -&amp;gt; security -&amp;gt; rules -&amp;gt; untrust-block-all -&amp;gt; from 'untrust' is not a valid reference
rulebase -&amp;gt; security -&amp;gt; rules -&amp;gt; untrust-block-all -&amp;gt; from is invalid
rulebase -&amp;gt; security -&amp;gt; rules is invalid
rulebase -&amp;gt; security is invalid
rulebase is invalid
vsys is invalid
devices is invalid
In VSYS vsys1 from zone trust of type unknown and to zone untrust of type unknown are incompatible in security rule outbound-block-all
Configuration is invalid&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="pan-post.JPG" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/21530iD6276493764D80C8/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="pan-post.JPG" alt="pan-post.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;2 errors when trying to do this, both of which appear to be originating from the PAN &amp;gt; FW.&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;The first one is a log setting on the 'outbound-block-all' rule on the PAN.&amp;nbsp; That specific log settings doesn't exist on the FW.&amp;nbsp;&lt;/LI&gt;&lt;LI&gt;Again same rule that is already on the PAN in 'Post Rules,' its shared between all of our existing DGs on the PAN.&amp;nbsp; &amp;nbsp;The only difference between the zones on the FW and the PAN is the first letter is capitalized which I assume is why it chokes?&amp;nbsp;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;I changed the zone names to match on the FW but not sure what to do about the log/email settings?&amp;nbsp; Also not sure why its complaining about 'shared' as well.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 24 Sep 2019 14:25:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/import-existing-config-into-panorama-woes/m-p/289817#M77036</guid>
      <dc:creator>drewdown</dc:creator>
      <dc:date>2019-09-24T14:25:55Z</dc:date>
    </item>
    <item>
      <title>Re: Import existing config into Panorama woes</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/import-existing-config-into-panorama-woes/m-p/289850#M77042</link>
      <description>&lt;P&gt;Drewdown,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;not sure if you fixed this already...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;2 errors when trying to do this, both of which appear to be originating from the PAN &amp;gt; FW.&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;The first one is a log setting on the 'outbound-block-all' rule on the PAN.&amp;nbsp; That specific log settings doesn't exist on the FW.&amp;nbsp;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;I&lt;STRONG&gt; think you may have to turn off log forwarding on the panorama&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;&lt;DIV class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&lt;STRONG&gt;Before importing the security policies, you need to disable logging to Panorama. On the firewall, either modify your log forwarding profile to remove Panorama, or edit each security policy and set the log forwarding profile to none:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;DIV class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;UL&gt;&lt;LI&gt;Again same rule that is already on the PAN in 'Post Rules,' its shared between all of our existing DGs on the PAN.&amp;nbsp; &amp;nbsp;The only difference between the zones on the FW and the PAN is the first letter is capitalized which I assume is why it chokes?&amp;nbsp;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;STRONG&gt;The name zone name makes a difference and should be the same&lt;/STRONG&gt;.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 24 Sep 2019 17:25:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/import-existing-config-into-panorama-woes/m-p/289850#M77042</guid>
      <dc:creator>MichaelShelton</dc:creator>
      <dc:date>2019-09-24T17:25:37Z</dc:date>
    </item>
    <item>
      <title>Re: Import existing config into Panorama woes</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/import-existing-config-into-panorama-woes/m-p/289854#M77043</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/120793"&gt;@MichaelShelton&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I changed the zone names on the FW to all lowercase and committed it but when I did that the tunnel between that FW and our on-prem FW went down.&amp;nbsp; I had to bounce the tunnel to get it passing traffic again....odd but whatever.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As far as the logging goes I am not logging anything to Panorama on the FW.&amp;nbsp; &amp;nbsp;Those 'Test-Alerts' are configured on the Panorama and pushed to my other managed PANs.&amp;nbsp; &amp;nbsp;On the FW I am trying to import logging is only set to 'Log at Session End' and Forwarding set to 'none' on every policy.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Are you are saying to disable the log settings on the 2 shared POST security policies on the PANORAMA?&amp;nbsp; This stuff is so cryptic, sometimes I love PAN and other times I want to beat it like a red headed stepchild.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 24 Sep 2019 17:50:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/import-existing-config-into-panorama-woes/m-p/289854#M77043</guid>
      <dc:creator>drewdown</dc:creator>
      <dc:date>2019-09-24T17:50:13Z</dc:date>
    </item>
  </channel>
</rss>

