<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ZTP Models can be deployed as a traditional models? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/ztp-models-can-be-deployed-as-a-traditional-models/m-p/396454#M91374</link>
    <description>&lt;P&gt;Hello Nikolay&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We're still waiting for a fix in the next PAN-OS 9.1 release (9.1.9). Apparently, the WebUI Mgmt "Unknown" Issue is related to bug&amp;nbsp;&amp;nbsp;PAN-156264. This behavior doesn't permit add PAs as a managed devices on Panorama in a traditional way.&amp;nbsp;&lt;/P&gt;&lt;P&gt;We tried the&amp;nbsp;PAN-160870&amp;nbsp;Workaround to disable ZTP Pre-configuration but it didn't work after reboot the PAs. Using the ZTP plugin to deploy PAs works, but still keeping requiring the ZTP DG and Template configuration to avoid the PAN-160870 issue&amp;nbsp;after finishing the deployment and it does not make much sense to me.&lt;/P&gt;&lt;P&gt;As soon as I have news I'll let you know.&lt;/P&gt;</description>
    <pubDate>Wed, 07 Apr 2021 20:37:34 GMT</pubDate>
    <dc:creator>egarantiva</dc:creator>
    <dc:date>2021-04-07T20:37:34Z</dc:date>
    <item>
      <title>ZTP Models can be deployed as a traditional models?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ztp-models-can-be-deployed-as-a-traditional-models/m-p/392306#M90884</link>
      <description>&lt;P&gt;Hello guys, I want to know if someone has seen this behavior with Port Management Configuration on ZTP NGFW Models ... The IP address, Netmask and gateway shows an incorrect value 0.0.0.0 or Unknown, but the CLI shows the correct configuration parameters. We previously performed a "request disable-ztp" besides "Disable Device and Network Template" and "Disable Panorama Policy and Objects" on Panorama Settings. We thought that this behavior is causing problems when we trying to add a PA-3260-ZTP as a managed device on Panorama.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="egarantiva_1-1616164599996.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/30441i2F2A1CC2261D03A5/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="egarantiva_1-1616164599996.png" alt="egarantiva_1-1616164599996.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 04 Jun 2021 02:59:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ztp-models-can-be-deployed-as-a-traditional-models/m-p/392306#M90884</guid>
      <dc:creator>egarantiva</dc:creator>
      <dc:date>2021-06-04T02:59:36Z</dc:date>
    </item>
    <item>
      <title>Re: ZTP Models can be deployed as a traditional models?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ztp-models-can-be-deployed-as-a-traditional-models/m-p/392546#M90914</link>
      <description>&lt;P&gt;So from th CLI you see that the firewall is configured correctly right and it has full configuration? I also see that&amp;nbsp; you have GUI picture so you can access the managment ip even if the gui shows no IP? I am asking because when I see&amp;nbsp; unknown fo interfaces I do a factory default reset on the firewall but first I save the config snapshot or/and device state (&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000Clkn" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000Clkn&lt;/A&gt;) and load it again after the reset &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 21 Mar 2021 22:08:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ztp-models-can-be-deployed-as-a-traditional-models/m-p/392546#M90914</guid>
      <dc:creator>nikoolayy1</dc:creator>
      <dc:date>2021-03-21T22:08:30Z</dc:date>
    </item>
    <item>
      <title>Re: ZTP Models can be deployed as a traditional models?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ztp-models-can-be-deployed-as-a-traditional-models/m-p/392728#M90945</link>
      <description>&lt;P&gt;Hi Nikolay&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for your reply. Please let me know if you have seen this behavior of "Unknown Mgmt IP info on GUI" when you're deploying ZTP models in a traditional way. If I reset to factory default a ZTP Model, it comes back to the original ZTP state according to the notes in the procedure "Disable the ZTP state machine on the firewall" and I think the issue is related to this ZTP pre-configured template.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/panorama/9-1/panorama-admin/manage-firewalls/set-up-zero-touch-provisioning/use-the-cli-for-ztp-tasks.html" target="_blank"&gt;https://docs.paloaltonetworks.com/panorama/9-1/panorama-admin/manage-firewalls/set-up-zero-touch-provisioning/use-the-cli-for-ztp-tasks.html&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 22 Mar 2021 16:15:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ztp-models-can-be-deployed-as-a-traditional-models/m-p/392728#M90945</guid>
      <dc:creator>egarantiva</dc:creator>
      <dc:date>2021-03-22T16:15:43Z</dc:date>
    </item>
    <item>
      <title>Re: ZTP Models can be deployed as a traditional models?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ztp-models-can-be-deployed-as-a-traditional-models/m-p/392745#M90948</link>
      <description>&lt;P&gt;We had an issue like that without ZTP deployment but we seen it in the CLI as well so we did factory default reset.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Did you test restarting just the web service or managment server as it seems a GUI issue:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClaGCAS" target="_blank" rel="noopener"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClaGCAS&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000POIHCA4" target="_blank" rel="noopener"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000POIHCA4&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also you can run Validate Changes to see if&amp;nbsp; the ZTP intoduced a bad config(you may need to make a small change before that to be able to validate)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/panorama/8-1/panorama-admin/administer-panorama/preview-validate-or-commit-configuration-changes" target="_blank" rel="noopener"&gt;https://docs.paloaltonetworks.com/panorama/8-1/panorama-admin/administer-panorama/preview-validate-or-commit-configuration-changes&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;There is a bug&amp;nbsp; PAN-160870 when deploying the ZTP firewalls in the normal way so you can check it and test the workaround:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/plugins/vm-series-and-panorama-plugins-release-notes/panorama-plugin-for-zero-touch-provisioning/panorama-plugin-for-zero-touch-provisioning-10/known-issues-in-the-zero-touch-provisioning-100-release.html" target="_blank" rel="noopener"&gt;https://docs.paloaltonetworks.com/plugins/vm-series-and-panorama-plugins-release-notes/panorama-plugin-for-zero-touch-provisioning/panorama-plugin-for-zero-touch-provisioning-10/known-issues-in-the-zero-touch-provisioning-100-release.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Otherwise of that check with the TAC.&lt;/P&gt;</description>
      <pubDate>Mon, 22 Mar 2021 17:20:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ztp-models-can-be-deployed-as-a-traditional-models/m-p/392745#M90948</guid>
      <dc:creator>nikoolayy1</dc:creator>
      <dc:date>2021-03-22T17:20:07Z</dc:date>
    </item>
    <item>
      <title>Re: ZTP Models can be deployed as a traditional models?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ztp-models-can-be-deployed-as-a-traditional-models/m-p/392801#M90957</link>
      <description>&lt;P&gt;Hello Nikolay, thanks for your all advices , we're going to test those suggestions, until we can check with TAC in a Live Meeting. I'll let you know when we have more clues about the issue with these ZTP models.&lt;/P&gt;</description>
      <pubDate>Mon, 22 Mar 2021 19:57:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ztp-models-can-be-deployed-as-a-traditional-models/m-p/392801#M90957</guid>
      <dc:creator>egarantiva</dc:creator>
      <dc:date>2021-03-22T19:57:22Z</dc:date>
    </item>
    <item>
      <title>Re: ZTP Models can be deployed as a traditional models?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ztp-models-can-be-deployed-as-a-traditional-models/m-p/394482#M91146</link>
      <description>&lt;P&gt;Any news about what is the issue as I am also interested in what it could be &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt; ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 26 Mar 2021 19:51:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ztp-models-can-be-deployed-as-a-traditional-models/m-p/394482#M91146</guid>
      <dc:creator>nikoolayy1</dc:creator>
      <dc:date>2021-03-26T19:51:53Z</dc:date>
    </item>
    <item>
      <title>Re: ZTP Models can be deployed as a traditional models?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ztp-models-can-be-deployed-as-a-traditional-models/m-p/396454#M91374</link>
      <description>&lt;P&gt;Hello Nikolay&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We're still waiting for a fix in the next PAN-OS 9.1 release (9.1.9). Apparently, the WebUI Mgmt "Unknown" Issue is related to bug&amp;nbsp;&amp;nbsp;PAN-156264. This behavior doesn't permit add PAs as a managed devices on Panorama in a traditional way.&amp;nbsp;&lt;/P&gt;&lt;P&gt;We tried the&amp;nbsp;PAN-160870&amp;nbsp;Workaround to disable ZTP Pre-configuration but it didn't work after reboot the PAs. Using the ZTP plugin to deploy PAs works, but still keeping requiring the ZTP DG and Template configuration to avoid the PAN-160870 issue&amp;nbsp;after finishing the deployment and it does not make much sense to me.&lt;/P&gt;&lt;P&gt;As soon as I have news I'll let you know.&lt;/P&gt;</description>
      <pubDate>Wed, 07 Apr 2021 20:37:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ztp-models-can-be-deployed-as-a-traditional-models/m-p/396454#M91374</guid>
      <dc:creator>egarantiva</dc:creator>
      <dc:date>2021-04-07T20:37:34Z</dc:date>
    </item>
    <item>
      <title>Re: ZTP Models can be deployed as a traditional models?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ztp-models-can-be-deployed-as-a-traditional-models/m-p/401952#M91762</link>
      <description>&lt;P&gt;I am having a similar issue.&amp;nbsp; As the ISP doesn't provide any DHCP, in the site I am adding the device to, and I have access to the Management network I tried disabling ZTP and adding the Panorama servers manually, but they went into a weird state, where the management interface was still routing to the network, but they wouldn't send any traffic to the Panorama servers.&amp;nbsp; I could still get on the interface to manage it, but it wouldn't respond to pings from panorama, but would from everything else.&amp;nbsp; resetting to factory default and re-enabling DHCP on the management interface and it would respond.&lt;/P&gt;&lt;P&gt;I also tried removing the ZTP template by disabling the panorama templates and policies, but then it wouldn't commit any changes because of a very unhelpful message:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;network  is missing 'interface'&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I didn't realize ZTP would be Mandatory and such a PITA.&amp;nbsp; I wish I had bought the normal ones.&lt;/P&gt;</description>
      <pubDate>Mon, 26 Apr 2021 16:35:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ztp-models-can-be-deployed-as-a-traditional-models/m-p/401952#M91762</guid>
      <dc:creator>Rich.H</dc:creator>
      <dc:date>2021-04-26T16:35:38Z</dc:date>
    </item>
    <item>
      <title>Re: ZTP Models can be deployed as a traditional models?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ztp-models-can-be-deployed-as-a-traditional-models/m-p/404246#M91883</link>
      <description>&lt;P&gt;Hi Rich&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You're right, try to add the ZTP models on Panorama using a traditional way results in a weird "Disconnected" state. Try to&amp;nbsp;remove the ZTP template by disabling the panorama templates and policies(as it says&amp;nbsp; PAN-160870 workaround) causes an Autommit failure after a PA reboot due to "network is missing interface" and some other issues and you will need to do the factory reset to correct that.&amp;nbsp;I figured out the only way to deploy those ZTP models was using the Panorama ZTP Plugin to register and add the PA as a managed device using DHCP via WAN (on eth1/1) and then disable the ztp state (request disable ztp) to be able to reach the PA from mgmt port (being careful to change locally on the PA the "Panorama service route" to mgmt port in the proper moment). Next, from the Panorama and locally on the PA, you should remove the ZTP template and DG from Panorama progressively until you get free the PA of that ZTP configuration.&lt;/P&gt;</description>
      <pubDate>Fri, 30 Apr 2021 15:46:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ztp-models-can-be-deployed-as-a-traditional-models/m-p/404246#M91883</guid>
      <dc:creator>egarantiva</dc:creator>
      <dc:date>2021-04-30T15:46:02Z</dc:date>
    </item>
  </channel>
</rss>

