Export/Import Named Configuration Snapshot

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

Export/Import Named Configuration Snapshot

L2 Linker

Hi everyone!

 

Can someone confirm that the subject can only be done by "superuser" account?

I can't find any documentation that says so. I'm wondering because "export device state" is visible for superuser account, when using a "device administrator" (dynamic role), "export device state" is not visible. Both Export and Import named configuration snapshot is available but when I try, it gives me the error "You don't have permission to view this page" / "You do not have permission to do this operation".

1 accepted solution

Accepted Solutions

Cyber Elite
Cyber Elite

Hi @IMTechSupport ,

 

I get the same error trying to export a named configuration snapshot on PAN-OS 10.1.8-h2.  Although that limitation is not listed here -> https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/firewall-administration/manage-firewall-ad... it makes sense because a device admin could import a configuration which changes his/her dynamic role.

 

I did find this article -> https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000CljiCAC&lang=en_US&refURL=....

 

I don't have a lab NGFW at the moment to test the load operations, but the export operations are denied.  It makes sense that load operations don't work either.

 

Thanks,

 

Tom

Help the community: Like helpful comments and mark solutions.

View solution in original post

3 REPLIES 3

L2 Linker

@BPry @TomYoung Hi! Appreciate it if you could share your input on this.

Cyber Elite
Cyber Elite

Hi @IMTechSupport ,

 

I get the same error trying to export a named configuration snapshot on PAN-OS 10.1.8-h2.  Although that limitation is not listed here -> https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/firewall-administration/manage-firewall-ad... it makes sense because a device admin could import a configuration which changes his/her dynamic role.

 

I did find this article -> https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000CljiCAC&lang=en_US&refURL=....

 

I don't have a lab NGFW at the moment to test the load operations, but the export operations are denied.  It makes sense that load operations don't work either.

 

Thanks,

 

Tom

Help the community: Like helpful comments and mark solutions.

Hi @TomYoung ,

 

Thank you for your response. It appears that device admin cannot do it because of the fact that they could possibly grant superuser access or change their roles.
It's just uncommon that there is no documentation. Btw, thanks again!


  • 1 accepted solution
  • 1165 Views
  • 3 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!