Panorama: Bulk Edit Security Policy to update Security Profile Group

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

Panorama: Bulk Edit Security Policy to update Security Profile Group

L2 Linker

Hi,

 

I have about 900 rules spread across 2 different groups within Panorama. I would like to apply a shared Security Profile Group to all these rules where there action is Allow. 

 

I have done some searching around but have not found any answers, however I apologise up front if I have missed a post (or article) where this has already been answered.

 

I am not very familiar with using API's (or through a script or XML) so if that is the answer, if I can please have some helpful beginner information here on how to achieve this through a script that would be great, but if there is a GUI process then that is preferred.

 

Thanks.

Daniel Bostock | Senior IT Operations Engineer, EML Payments | Blog: https://danielbostock.com
3 REPLIES 3

Cyber Elite
Cyber Elite

Daniel

 

What happens if you took a profile (and the group) and cloned them?

I think in the GUI, when you clone, it gives you the option to make that profile shared.

when all profiles are shared, you can clone the group (and also make it shareable)

 

now, you should be able to have a shared profile (and groups) across your 2 device groups.

 

questions?

 

let me know.

Help the community: Like helpful comments and mark solutions

L2 Linker

Hi @DanielBostock 

 

best way to do this really quick is by using expedition tool. There is an option called multi edit and you can apply profile group to all the rules or only for selected rules.

 

Regards,Nagarjuna 

Thanks for the information here guys.

 

I don't know much about expedition at this moment, my 3 second understanding of the tool was it is an import tool for rules from ASA to Palo. Expedition was what was used to get all the rules here in the first place I am now told, I did not know however retroactively rules could be updated or edited with the tool. 

 

I will now spend some time today investigating it further and see how this could resolve the issue for us and respond here after this.

 

Appreciate the help guys!

 

Thanks,

Daniel.

Daniel Bostock | Senior IT Operations Engineer, EML Payments | Blog: https://danielbostock.com
  • 3895 Views
  • 3 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!