<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Can Panorama managed devices be configured via the CLI? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/can-panorama-managed-devices-be-configured-via-the-cli/m-p/386278#M90225</link>
    <description>&lt;P&gt;Wow, sorry for the late reply to this - it seems I either missed the notification of your reply, or it didn't get swent.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for that - so it seems if I have to do the text based configurations, I can - but will the firewall sync this back to Panorama once it's done?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can you point me to a Panorama adoption or getting started guide? I've built the server, but I haven't yet imported into it - mainly because I've been too busy, but also because I'm wary of breaking things.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for your reply!&lt;/P&gt;</description>
    <pubDate>Wed, 17 Feb 2021 04:40:40 GMT</pubDate>
    <dc:creator>darren_g</dc:creator>
    <dc:date>2021-02-17T04:40:40Z</dc:date>
    <item>
      <title>Can Panorama managed devices be configured via the CLI?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/can-panorama-managed-devices-be-configured-via-the-cli/m-p/360380#M88091</link>
      <description>&lt;DIV class="lia-message-body lia-component-message-view-widget-body lia-component-body-signature-highlight-escalation lia-component-message-view-widget-body-signature-highlight-escalation"&gt;&lt;DIV class="lia-message-body-content"&gt;&lt;P&gt;Hey folks.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm adding a Panorama server into my infrastructure to enable zero touch SDWAN provisioning, and since I've never done Panorama before, I've got a question.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can panorama managed devices be configured via the CLI?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The reason I ask this is that I do a fair bit of work with AWS and VPC's - and configuring a new VPC into AWS is mostly done via a script that AWS provides which you modify to suit your environment and cut and paste into your firewall via CLI to configure the IPSec tunnels and routing involved.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I *could* go through the script and add the required sections via the GUI - but doing it via CLI is so much easier.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So once I add my firewalls into Panorama, does anyone know if can I still do the configuration via CLI? or will I be forced to transpose everything into the GUI and push it to the firewalls that way?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for any insight&lt;/P&gt;&lt;/DIV&gt;&lt;/DIV&gt;</description>
      <pubDate>Tue, 03 Nov 2020 03:36:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/can-panorama-managed-devices-be-configured-via-the-cli/m-p/360380#M88091</guid>
      <dc:creator>darren_g</dc:creator>
      <dc:date>2020-11-03T03:36:12Z</dc:date>
    </item>
    <item>
      <title>Re: Can Panorama managed devices be configured via the CLI?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/can-panorama-managed-devices-be-configured-via-the-cli/m-p/360456#M88099</link>
      <description>&lt;P&gt;Good Day&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For the most part... 99% of what you can do in the GUI can be done in the CLI.&lt;/P&gt;
&lt;P&gt;That being said... it is much easier to use the GUI, especially when this product is designed to create "snippets" or templates, as they are called in Panorama.&amp;nbsp;&amp;nbsp; These templates are whatever configuration (limited to Network and Device tabs on FWs).&amp;nbsp; So think about login banner, domain name, dynamic update scheduling, authentication servers, interface management profiles, etc)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In addition, the Panorama also is used for Device Groups (Policy and Object tabs in FWs), so think in terms of shared best practice policies, shared objects, shared content ID profiles, etc.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;So yes, it is all possible to do via the command line or API commands if you like.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks for the question.&amp;nbsp; Anything else?&lt;/P&gt;</description>
      <pubDate>Tue, 03 Nov 2020 13:27:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/can-panorama-managed-devices-be-configured-via-the-cli/m-p/360456#M88099</guid>
      <dc:creator>S.Cantwell</dc:creator>
      <dc:date>2020-11-03T13:27:41Z</dc:date>
    </item>
    <item>
      <title>Re: Can Panorama managed devices be configured via the CLI?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/can-panorama-managed-devices-be-configured-via-the-cli/m-p/386278#M90225</link>
      <description>&lt;P&gt;Wow, sorry for the late reply to this - it seems I either missed the notification of your reply, or it didn't get swent.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for that - so it seems if I have to do the text based configurations, I can - but will the firewall sync this back to Panorama once it's done?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can you point me to a Panorama adoption or getting started guide? I've built the server, but I haven't yet imported into it - mainly because I've been too busy, but also because I'm wary of breaking things.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for your reply!&lt;/P&gt;</description>
      <pubDate>Wed, 17 Feb 2021 04:40:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/can-panorama-managed-devices-be-configured-via-the-cli/m-p/386278#M90225</guid>
      <dc:creator>darren_g</dc:creator>
      <dc:date>2021-02-17T04:40:40Z</dc:date>
    </item>
    <item>
      <title>Re: Can Panorama managed devices be configured via the CLI?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/can-panorama-managed-devices-be-configured-via-the-cli/m-p/386320#M90231</link>
      <description>&lt;P&gt;Darren&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks for returning to us!&amp;nbsp; We missed you.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I wanted to clarify m y statement, that when a device is under Panorama control, the configuration items I was discussing was ON the Panorama, and then you push your changes to the FW.&amp;nbsp; The FW does not sync it changes to the Panorama, but the other way away... it synchs changes FROM the Panorama.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As for the link.. here it is..&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/panorama/10-0/panorama-admin/set-up-panorama.html" target="_blank"&gt;https://docs.paloaltonetworks.com/panorama/10-0/panorama-admin/set-up-panorama.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Have a great day.&lt;/P&gt;</description>
      <pubDate>Wed, 17 Feb 2021 12:16:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/can-panorama-managed-devices-be-configured-via-the-cli/m-p/386320#M90231</guid>
      <dc:creator>S.Cantwell</dc:creator>
      <dc:date>2021-02-17T12:16:32Z</dc:date>
    </item>
    <item>
      <title>Re: Can Panorama managed devices be configured via the CLI?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/can-panorama-managed-devices-be-configured-via-the-cli/m-p/386405#M90247</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/2280"&gt;@darren_g&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You still can configure firewall that is managed by Panorama, but the config you apply stays locally. It will not sync with Panorama.&lt;/P&gt;&lt;P&gt;In addition when you put Panorama to the equasion you need to start imagine the firewall configuration as to separate parts&lt;/P&gt;&lt;P&gt;- rules, objects and anything related to policies (policy and objects tabs in fw gui)&lt;/P&gt;&lt;P&gt;- network and device config (network and device tabs in the fw gui)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Config under network and device can have only one value, so if you configure something via Panorama, you can override it locally&lt;/P&gt;&lt;P&gt;Config under policy and object can have many values, so any rule created locally will mix with the rules received from the Panorama. But as you can imagine you cannot have two objects or rules with same name, so if you try to configure something locally that is already pushed by panorama the commit will fail.&lt;/P&gt;</description>
      <pubDate>Wed, 17 Feb 2021 16:09:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/can-panorama-managed-devices-be-configured-via-the-cli/m-p/386405#M90247</guid>
      <dc:creator>aleksandar.astardzhiev</dc:creator>
      <dc:date>2021-02-17T16:09:45Z</dc:date>
    </item>
  </channel>
</rss>

