New template stacks after upgrade?

Reply
Highlighted
L4 Transporter

New template stacks after upgrade?

Hi all,

 

I upgraded from an 8.0 release to 8.1.3 to prepare for a migration to some new hardware.  I did a commit after the upgrade to make sure everything was synced up between Panorama and the firewalls and I believe everything went ok.

 

I was making some adjustments at the recommendation of the Best Practices analyzer in Expedition and noticed it failed to commit due to something in a Template Stack.  This confused me a bit since I gave up on Template Stacks over a year ago when I first tried them due to not being able to reference values in a template lower in the stack (common values but they had to be referenced in non-common config areas).

 

I looked again tonight and it appears Panorama created two "_mig" template-stack configs, migrated from each of my two device configs, and moved the devices over to use those.

 

Was this expected behavoir that I missed in the notes somewhere?  If so, is there any issues with moving each firewall back to its original device config and deleting the migrated template-stacks or should we be using template-stacks moving forward?

 

Thanks!

 

*edit* Looking at this a little further, it appears the new template-stacks it created are actually each referencing their corresponding original template files.  The Commit and Push failed due to a missing "device-id" in the HA configuration.


Accepted Solutions
Highlighted
Cyber Elite

This is because of a change in the default behaviour on Panorama with PAN-OS 8.1. Firewalls can  o longer be attached to a template, they must be attached to a template stack (even if you don't add any temolates to the stack). Because of that panorama creates template stacks automatically when you upgrade to 8.1 for all firewalls that aren't added to a template stack yet.

View solution in original post


All Replies
Highlighted
Cyber Elite

i also saw same behaviour once i upgrade Panormama from 8.0.9 to 8.1

waiting for answer 

MP
Highlighted
Cyber Elite

This is because of a change in the default behaviour on Panorama with PAN-OS 8.1. Firewalls can  o longer be attached to a template, they must be attached to a template stack (even if you don't add any temolates to the stack). Because of that panorama creates template stacks automatically when you upgrade to 8.1 for all firewalls that aren't added to a template stack yet.

View solution in original post

Highlighted
Cyber Elite

Many Thanks for reply

MP
Highlighted
L4 Transporter

@vsys_remo any idea why it would be missing data after migrating to a stack?  It seems like if that information was required it would have been in the original template or else I wouldn't have been able to commit.

Highlighted
Cyber Elite

@jsalmans

Right now my only idea is a bug - so during the migration this little part got lost...

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!

The Live Community thanks you for your participation!