- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
01-23-2014 01:39 AM
Hello Everyone,
We deploy a panorama 5.1.4 and 2 fws are managed on it, one of the fws is running PanOs5.0.8 and another one is running 4.1.14. We can see the fws normally on Panorama -> Managed devices and Templates tabs. however when I finsh a ldap-server-profile template and click commit button and select the radio Template, I could not see the fw which runs 4.1.14, but another fw could.
I also see the document "PanoramaAdministratorsGuide_5.1.pdf", on the page 77, the tips as below.
For firewalls running PAN-OS 4.x, the use of Panorama templates is limited to the following:
• Creating response pages
• Defining authentication profiles and sequences
• Creating self-signed certificates on Panorama or importing certificates
• Creating client authentication certificates (known as Certificate Profiles in Panorama 5.0 and later)
• Creating server profiles: SNMP Trap, Syslog, Email, NetFlow, RADIUS, LDAP, and Kerberos
So I could not find the fw running PAN-OS 4.1.14, is the normal beheavy ? or bug ? anyone knows that?
Thanks.
Joy
01-27-2014 07:02 AM
Devices running PAN-OS 4.1 or older does not support Template. As Steven suggested, you can create a separate template for the 4.x devices and manage 4.x devices separately from the 5.0 devices. You will need to issue a 'Device Group' commit and choose 'Include Device and Network Templates' to the 4.1 device. Thanks.
01-25-2014 09:24 AM
Does the template have any of objects not supported in PanOS 4.1?
Perhaps including unsupported objects prevents the entire template from being allowed.
01-25-2014 08:20 PM
Hello,
Thanks for your reply, but I am very sure that only the ldap server profile that I set including in the template.
Joy
01-26-2014 11:36 AM
I would try creating a new template with just the ldap server profile and applying this to the PanOS4.1.14 firewall alone.
If this works add the 5.0.8 firewall and see if it goes.
I am thinking that perhaps you can't mix cross major revisions or that there is something corrupt in the original template that prevents the 4.1.14 commit.
01-27-2014 07:02 AM
Devices running PAN-OS 4.1 or older does not support Template. As Steven suggested, you can create a separate template for the 4.x devices and manage 4.x devices separately from the 5.0 devices. You will need to issue a 'Device Group' commit and choose 'Include Device and Network Templates' to the 4.1 device. Thanks.
02-09-2014 12:12 AM
Hello,
Thanks for detaiil answers.
Joy
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!