<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Changing the panorama service route without causing a revert in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/changing-the-panorama-service-route-without-causing-a-revert/m-p/383646#M89986</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;After checking panorama was not communicating over the vpn tunnel even with the service route changed and a any/any rule in place. I created a second rule that specifically targets the panorama servers and the interface for the vpn. &amp;nbsp;Fixed my issue.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thanks for the help&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 03 Feb 2021 16:26:17 GMT</pubDate>
    <dc:creator>calvinmcelroy</dc:creator>
    <dc:date>2021-02-03T16:26:17Z</dc:date>
    <item>
      <title>Changing the panorama service route without causing a revert</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/changing-the-panorama-service-route-without-causing-a-revert/m-p/383500#M89966</link>
      <description>&lt;P&gt;I am running into a problem &amp;nbsp;and looking for any ideas or experience that may provide a solution.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have a firewall that is managed by Panorama and the service route for panorama is set to ‘default’. I want to change this route to communicate to panorama over an IPSec tunnel. This change causes a revert and I guess this is probably expected behavior because the connection is interrupted. How can I accomplish this change without a revert.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have tried doing it from the firewall side and the panorama side. I’ve tried using specific policies that target panorama. I’ve tried every combination of configuration order that I can think of and still coming up short. Does anybody have any resource they could point me to?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 02 Feb 2021 20:40:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/changing-the-panorama-service-route-without-causing-a-revert/m-p/383500#M89966</guid>
      <dc:creator>calvinmcelroy</dc:creator>
      <dc:date>2021-02-02T20:40:01Z</dc:date>
    </item>
    <item>
      <title>Re: Changing the panorama service route without causing a revert</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/changing-the-panorama-service-route-without-causing-a-revert/m-p/383552#M89977</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/170360"&gt;@calvinmcelroy&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;Does your firewall have communication to panorama over the IPSec tunnel? There's a wait incorporated before the revert that would account for the routing change before it reverts the configuration, which makes it possible your change is actually breaking the communication back to panorama long-term.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 03 Feb 2021 04:22:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/changing-the-panorama-service-route-without-causing-a-revert/m-p/383552#M89977</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2021-02-03T04:22:46Z</dc:date>
    </item>
    <item>
      <title>Re: Changing the panorama service route without causing a revert</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/changing-the-panorama-service-route-without-causing-a-revert/m-p/383646#M89986</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;After checking panorama was not communicating over the vpn tunnel even with the service route changed and a any/any rule in place. I created a second rule that specifically targets the panorama servers and the interface for the vpn. &amp;nbsp;Fixed my issue.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thanks for the help&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 03 Feb 2021 16:26:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/changing-the-panorama-service-route-without-causing-a-revert/m-p/383646#M89986</guid>
      <dc:creator>calvinmcelroy</dc:creator>
      <dc:date>2021-02-03T16:26:17Z</dc:date>
    </item>
  </channel>
</rss>

