I'm attempting my first migration of an ASA to one of my Panorama-managed clusters (1 A/P cluster in a DG/Template) and am following the recent YouTube tutorial for doing so. When I get to the merge step, the API results include a lot items for my other DGs/Templates. I've tried Atomic & Subatomic and it pretty much looks the same (I didn't do a line-for-line comparison by eyeballing the 2 looks identical).
Is this something of concern? Are there certain things to be on the lookout for?
Atomic & Subatomic should looks different , for example : If you are pushing the rules via API calls, when select "Atomic" and click on "Generate API requests", you will see list of API calls based on device group level , so you will see one API call for all security rules per Device Group and that one API call contains all the security rules. When you switch to "Subatomic" mode , click on"Generate API request" again, you should see one API call per security rule on the Device Group, if you have 100 rules in the device group, then you can click to pick and choose which rules out of 100 you want to push back to your PAN-OS device.
Okay, I've finally been able to get back to this. I'm watching the 9 of 9 tutuorial video and I see something I missed before. I didn't notice that while the Panorama Base Configuration appears on the Export right-pane it includes all DGs/Templates.
How do I limit it to just one DG/Template (we have each firewall or firewall cluster in its own DG/Template)?
You can drag the zone, object and policy to the corresponding device group on the right , drag the interface to the corresponding template on the right , then go to API export , click "generate API Request" and only push the config for the specific device group , for example , I can search my device group name -DataCenter , and it will shows all API calls related to that device group as attached screenshot. then you can click on each of them to send API calls to the Panorama.
Oh, that's not what the video said to do - it said to drag everything under vsys1 to the device | vsys1 on the right. Now there is nothing on the left pane for the ASA.
Is there any way to undo this and try again or do I have to start over again?
If I have to start over again, is there any way to make a copy of the project so I don't have to keep re-doing the whole thing?
The video is for firewall to firewall migration, if you have panorama configuration as base config , you have option to drag and drop the objects to the corresponding device group and template , if you have not yet click on "merge", you can click on "reset" button, if merge is your last action, you can go to right upper corner and click on" Undo last change" Other than those conditions, there is no undo function after you merged the config. If you need to restart a new project, when you start a new project , before you ready to drag and drop the objects from source to base config , you can click on the right upper corner "Save snapshot" , then if something goes wrong, you can then load the saved snapshot back.
Understood on the video being made for fw-to-fw - I just guessed wrong 😕
Unfortunately, I was fiddling around with the Merge option some more as the post-merge created duplicates so i messed up the last config change and can't undo.
Hopefully, 3rd time's a charm (or is it 4th - I've lost count, lol) 🙂
Luckily, I had a fairly recent snapshot that I had forgotten I had taken 🙂
So, I'm confused on what I'm supposed to do. Here is what my setup looks like:
So, where do I put each element in the Source pane on the left in the Base Configuration pane on the right?
I tried ASA | Network to Panorama | Template | Firewall (CORE-FW) | Network.
And then I tried ASA | vsys1 | Objects to Panorama | DG | shared, ASA | vsys1 | Policies to Panorama | DG | Firewall (CORE-FW), and finally ASA | vsys1 | Zones to Panorama | Templates | CORE-FW | Nework.
I then hit Merge and go to the API Output Manager and there is no way to select individual DGs:
Do I just check the boxes of the items that are specific to the DG/Template I want to use?
After you merge the config , when you go to "API output manager", click on "Generate API request" the blue button first, and you should see multiple API calls shown in the screen, Then Try put "Core-FW1" in the search box as attached in the screenshot and you will see all API calls related to Core-FW1 device group and template , you will always needs to push the shared first , the ID column shows the order of your API calls, please follow the order to push individual API calls.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!