- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
03-01-2023 05:29 PM - edited 03-01-2023 05:33 PM
Hi Guys,
I have a template in Paranoma and I pushed it down to a firewall, the firewall could only get 80% of the template. The Panorama didn't complain as there were no error messages after the push.
The firewall is currently missing interfaces' settings and virtual router settings that I have set up on the template. The Policies and Objects got into the firewall just fine. Any idea the network settings didn't get pushed down to the firewall?
Thanks.
03-01-2023 05:49 PM
Hi @tinhnho ,
Is there a configuration already on the interfaces and virtual routers? If so, Panorama will not overwrite it unless you select Force Template Values. If you are not on site, enable Automated Commit Recovery if you change the network config. In that way, the NGFW will revert the changes if it loses connectivity to Panorama.
Thanks,
Tom
03-01-2023 05:49 PM
Hi @tinhnho ,
Is there a configuration already on the interfaces and virtual routers? If so, Panorama will not overwrite it unless you select Force Template Values. If you are not on site, enable Automated Commit Recovery if you change the network config. In that way, the NGFW will revert the changes if it loses connectivity to Panorama.
Thanks,
Tom
03-01-2023 06:04 PM - edited 03-01-2023 06:06 PM
There was one or two configurations of interfaces and virtual router there before the push I think. Where do I find 'Force Template Values' in Panorama? Yea, i have 'Automated Commit Recovery' enabled.
03-01-2023 06:11 PM
Hi @tinhnho ,
Click on Edit Selections when you Push to Devices. You will see the check box on the lower right.
Thanks,
Tom
03-01-2023 06:20 PM - edited 03-01-2023 06:22 PM
Found it!. I pushed and it failed as it reverted. Should I uncheck 'Automated Commit Recovery' and 'push to Devices' it again?
03-01-2023 06:33 PM
Hi @tinhnho ,
If you do that you may very likely have to drive on site to fix the issue. Since it reverted, you don't know what exactly broke, and you may lose all access. Best to be on site.
Thanks,
Tom
03-01-2023 06:45 PM
I found it, it reverted because it was using different mgmt ip. I've modified the template with a working mgmt ip address and push it again. It works now. Thanks.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!