Panorama 5.1 with fw PanOS 4.1.14

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

Panorama 5.1 with fw PanOS 4.1.14

L4 Transporter

Hello Everyone,

We deploy a panorama 5.1.4 and 2 fws are managed on it, one of the fws is running PanOs5.0.8 and another one is running 4.1.14. We can see the fws normally on Panorama -> Managed devices and Templates tabs. however when I finsh a ldap-server-profile template and click commit button and select the radio Template, I could not see the fw which runs 4.1.14, but another fw could.

panorama managed devices.png

panorama templates.png

panorama comimt template.png

I also see the document "PanoramaAdministratorsGuide_5.1.pdf", on the page 77, the tips as below.

For firewalls running PAN-OS 4.x, the use of Panorama templates is limited to the following:

• Creating response pages

• Defining authentication profiles and sequences

• Creating self-signed certificates on Panorama or importing certificates

• Creating client authentication certificates (known as Certificate Profiles in Panorama 5.0 and later)

• Creating server profiles: SNMP Trap, Syslog, Email, NetFlow, RADIUS, LDAP, and Kerberos

So I could not find the fw running PAN-OS 4.1.14, is the normal beheavy ?  or bug ? anyone knows that?

Thanks.

Joy

1 accepted solution

Accepted Solutions

L6 Presenter

Devices running PAN-OS 4.1 or older does not support Template.  As Steven suggested, you can create a separate template for the 4.x devices and manage 4.x devices separately from the 5.0 devices.  You will need to issue a 'Device Group' commit and choose 'Include Device and Network Templates' to the 4.1 device.  Thanks.

View solution in original post

5 REPLIES 5

L7 Applicator

Does the template have any of objects not supported in PanOS 4.1?

Perhaps including unsupported objects prevents the entire template from being allowed.

Steve Puluka BSEET - IP Architect - DQE Communications (Metro Ethernet/ISP)
ACE PanOS 6; ACE PanOS 7; ASE 3.0; PSE 7.0 Foundations & Associate in Platform; Cyber Security; Data Center

Hello,

Thanks for your reply, but I am very sure that only the ldap server profile that I set including in the template.

Joy

I would try creating a new template with just the ldap server profile and applying this to the PanOS4.1.14 firewall alone.

If this works add the 5.0.8 firewall and see if it goes.

I am thinking that perhaps you can't mix cross major revisions or that there is something corrupt in the original template that prevents the 4.1.14 commit.

Steve Puluka BSEET - IP Architect - DQE Communications (Metro Ethernet/ISP)
ACE PanOS 6; ACE PanOS 7; ASE 3.0; PSE 7.0 Foundations & Associate in Platform; Cyber Security; Data Center

L6 Presenter

Devices running PAN-OS 4.1 or older does not support Template.  As Steven suggested, you can create a separate template for the 4.x devices and manage 4.x devices separately from the 5.0 devices.  You will need to issue a 'Device Group' commit and choose 'Include Device and Network Templates' to the 4.1 device.  Thanks.

Hello,

Thanks for detaiil answers.

Joy

  • 1 accepted solution
  • 2710 Views
  • 5 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!