<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Security Profile - Mass change - Is there an easy way? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/security-profile-mass-change-is-there-an-easy-way/m-p/294072#M77646</link>
    <description>&lt;P&gt;That's a great suggestion, but I'm not sure the business side of things here would allow that. I can already hear their concerns going on in my head, but it is worth a shot.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Thanks!&lt;/P&gt;</description>
    <pubDate>Thu, 24 Oct 2019 12:14:55 GMT</pubDate>
    <dc:creator>Gareth.Doyle</dc:creator>
    <dc:date>2019-10-24T12:14:55Z</dc:date>
    <item>
      <title>Security Profile - Mass change - Is there an easy way?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/security-profile-mass-change-is-there-an-easy-way/m-p/293924#M77633</link>
      <description>&lt;P&gt;I received a request to change the current security profile on 3,502 policies (spanning three VSYS) from a shared profile to a local profile. Is there a better way to do this than doing them individually through the GUI?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I don't even want to think about how long this would take if I have to do it through the GUI, not to mention the arthritis I'll have developed in my hand by the end of that.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Wed, 23 Oct 2019 18:28:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/security-profile-mass-change-is-there-an-easy-way/m-p/293924#M77633</guid>
      <dc:creator>Gareth.Doyle</dc:creator>
      <dc:date>2019-10-23T18:28:14Z</dc:date>
    </item>
    <item>
      <title>Re: Security Profile - Mass change - Is there an easy way?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/security-profile-mass-change-is-there-an-easy-way/m-p/293991#M77640</link>
      <description>&lt;P&gt;Have you considered installing Expedition (&lt;A href="https://live.paloaltonetworks.com/t5/Expedition-Migration-Tool/ct-p/migration_tool" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Expedition-Migration-Tool/ct-p/migration_tool&lt;/A&gt;), then connecting Panorama to Expedition. If you don't have Panorama, you could import config of firewalls as well.&amp;nbsp; You can then do a multi-edit on the policies and change the security profile and push back out to Pan. If you just imported the config into Expedition, you could also make the multi-edit changes in Expedition, export config and merge back into firewalls with the security profile change.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We recently used this approach for some migrations for zone, security profiles, and logging profiles.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Good Luck.&lt;/P&gt;</description>
      <pubDate>Thu, 24 Oct 2019 03:46:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/security-profile-mass-change-is-there-an-easy-way/m-p/293991#M77640</guid>
      <dc:creator>brianowen</dc:creator>
      <dc:date>2019-10-24T03:46:22Z</dc:date>
    </item>
    <item>
      <title>Re: Security Profile - Mass change - Is there an easy way?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/security-profile-mass-change-is-there-an-easy-way/m-p/294072#M77646</link>
      <description>&lt;P&gt;That's a great suggestion, but I'm not sure the business side of things here would allow that. I can already hear their concerns going on in my head, but it is worth a shot.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Thu, 24 Oct 2019 12:14:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/security-profile-mass-change-is-there-an-easy-way/m-p/294072#M77646</guid>
      <dc:creator>Gareth.Doyle</dc:creator>
      <dc:date>2019-10-24T12:14:55Z</dc:date>
    </item>
    <item>
      <title>Re: Security Profile - Mass change - Is there an easy way?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/security-profile-mass-change-is-there-an-easy-way/m-p/294481#M77690</link>
      <description>&lt;P&gt;I worked with TAC and found the best way (for me) to do this. I have written out the process below in case someone else may find it useful. Please keep in mind I utilize Panorama, so this is written for that. I can't speak to any differences there may be in syntax between Panorama and doing it directly on a firewall.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1. Log into the Panorama GUI and create a local security profile for the VSYS you are working on.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;2. Log into the Panorama CLI.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;3. Enter command: &lt;EM&gt;set cli config-output-format set&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;4. Enter command: &lt;EM&gt;configure&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;5. Now we need to identify each rule that is utilizing the old security profile (in this case we'll call it OldSecurityProfile) so we run this next command. Please keep in mind that in this example the device-group (or VSYS) we will be working on is called Firewall-123, so wherever you see that referenced will need to be changed to match your needs:&lt;BR /&gt;&lt;EM&gt;show device-group Firewall-123 post-rulebase security rules | match OldSecurityProfile&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;6. After running the previous command we found that the policy "Security Policy Name" is set to use the OldSecurityProfile security profile and we want to change that to the new “New_Security_Profile” security profile.&lt;BR /&gt;&lt;EM&gt;set device-group Firewall-123 post-rulebase security rules "Security Policy Name" profile-setting group OldSecurityProfile&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;7. Now we delete the previous security profile in that rule and set the new security profile with the delete and set commands:&lt;BR /&gt;&lt;EM&gt;delete device-group Firewall-123 post-rulebase security rules&amp;nbsp;"Security Policy Name" profile-setting group OldSecurityProfile&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;set device-group Firewall-123 post-rulebase security rules "Security Policy Name" profile-setting group New_Security_Profile&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;8. Now commit and push to the firewall.&lt;/P&gt;</description>
      <pubDate>Fri, 25 Oct 2019 18:40:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/security-profile-mass-change-is-there-an-easy-way/m-p/294481#M77690</guid>
      <dc:creator>Gareth.Doyle</dc:creator>
      <dc:date>2019-10-25T18:40:00Z</dc:date>
    </item>
  </channel>
</rss>

