Expedition - Panorama managed device

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

Expedition - Panorama managed device

L1 Bithead

I finally got Expedition working and retrieved Panorama configuration successfully. When creating a project, should I add the firewall or Panorama ? Also, after cleaning up the config to the point it is ready to be deployed how can I push the config to the managed device through Panorama ?

 

I know Panorama have a configuration for device group and template so I am not sure how to see that on Expedition.

 

Thanks in advance,

Hugo

5 REPLIES 5

L4 Transporter

Hello @Hugo_Nacif 

It depends where your configuration is stored, are you managing the firewall from the panorama or firewall directly? Depending on the answer depends on what should be imported into expedition.

I am managing the firewall from Panorama.

Hello @Hugo_Nacif 

 

Import the panorama configuration and you can import it via API or XML. Here is a video series if it helps you in your endeavors. Also as a part of that playlist it shows how to address other issues within the configuration you may have.

 

https://www.youtube.com/watch?v=RMHfO4MA0jw&list=PLD6FJ8WNiIqVez8EBeoyRsnQcKTA5FuZ-&index=8

Hi @azuniga , thanks for the link. It helped me understand a bit more. If I merge and set as output using Panorama would overwrite the existing firewall rules on the device group I set ? I have some rules for Panorama on these devices already and that is not listed on Juniper's ruleset. I wonder if that would be a potential problem as it can interrupt Panorama from sending new configs to them.

Hello @Hugo_Nacif 

 

I would always import the latest panorama configuration and merge it from there, if you export it as an XML and import into panorama then yes it will overwrite your configuration. You can import the XML and perform a partial load configuration only importing the changes you want, or you can perform an API push which will only import the changes made within expedition. So you have multiple options on how you would like to import that configuration.

  • 4121 Views
  • 5 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!