Exporting shared rulebase

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

Exporting shared rulebase

L1 Bithead

I am in the process of converting our Juniper SRX's to Palo Alto's.

 

During the process I reorganized some of the security rules and converted them to shared pre rules.

 

When I export the configuration it doesn't seem to get these rules? It looks like I can only export vsys1 rules?

 

Am I doing something wrong or is this not supported?

 

 

 

1 accepted solution

Accepted Solutions

L6 Presenter

@rwendt if you convert the policy to share ,  you won’t see it in the pan-OS config , so leave it in vsys1 and you can drag it to the shared folder on the panorama config during merge . 

View solution in original post

7 REPLIES 7

L6 Presenter

@rwendt if you convert the policy to share ,  you won’t see it in the pan-OS config , so leave it in vsys1 and you can drag it to the shared folder on the panorama config during merge . 

L1 Bithead

Thanks for the reply ill do that

L1 Bithead

Can you move it back to vsys1 after moving it to shared?

L1 Bithead

Nevermind. I manually changed the values in the mariadb database. 😄

L1 Bithead

@lychiang I don't want all the policies shared, only some of them. It doesn't seem like there is a way to do this. Is shared policies something thats being worked on? It seems kind of pointless to have an option to convert to shared if you can't do anything with them?

@rwendt

When you merged with the PAN-OS base config, you could drag all rules to vsys1 on the right , after you merged,  you could select the rules that you want to convert to share and right click -> Rule action -> Converted to shared . What I trying to say is don't convert the rule to shared before you merge with the PAN-OS base config. 

oh ok that makes sense. I'll give that a try.

Thanks again.

  • 1 accepted solution
  • 4007 Views
  • 7 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!