Panorama: Bulk Edit Security Policy to update Security Profile Group

Reply
L0 Member

Panorama: Bulk Edit Security Policy to update Security Profile Group

Hi,

 

I have about 900 rules spread across 2 different groups within Panorama. I would like to apply a shared Security Profile Group to all these rules where there action is Allow. 

 

I have done some searching around but have not found any answers, however I apologise up front if I have missed a post (or article) where this has already been answered.

 

I am not very familiar with using API's (or through a script or XML) so if that is the answer, if I can please have some helpful beginner information here on how to achieve this through a script that would be great, but if there is a GUI process then that is preferred.

 

Thanks.

L4 Transporter

Re: Panorama: Bulk Edit Security Policy to update Security Profile Group

Daniel

 

What happens if you took a profile (and the group) and cloned them?

I think in the GUI, when you clone, it gives you the option to make that profile shared.

when all profiles are shared, you can clone the group (and also make it shareable)

 

now, you should be able to have a shared profile (and groups) across your 2 device groups.

 

questions?

 

let me know.

L2 Linker

Re: Panorama: Bulk Edit Security Policy to update Security Profile Group

Hi @DanielBostock 

 

best way to do this really quick is by using expedition tool. There is an option called multi edit and you can apply profile group to all the rules or only for selected rules.

 

Regards,Nagarjuna 

L0 Member

Re: Panorama: Bulk Edit Security Policy to update Security Profile Group

Thanks for the information here guys.

 

I don't know much about expedition at this moment, my 3 second understanding of the tool was it is an import tool for rules from ASA to Palo. Expedition was what was used to get all the rules here in the first place I am now told, I did not know however retroactively rules could be updated or edited with the tool. 

 

I will now spend some time today investigating it further and see how this could resolve the issue for us and respond here after this.

 

Appreciate the help guys!

 

Thanks,

Daniel.

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!

The Live Community thanks you for your participation!