- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
11-09-2017 12:48 PM
Hello,
I am very new to Palo Alto FWS so please be gentle 🙂
I have been asked to setup two new PA3060 firewalls to be centrally managed by a Panorama server. Both the Panorama and Firewalls are running v8.0.5.
I have successfully followed the PA instructions to import the firewalls and configs into the Panorama.
However, if I create say a new interface, new sub-interface or new static routes into the virtual router, I commit the changes to the Panorama an then attempt a push to device.
The Commit shows as Completed, however when I access the device GUI, the new interfaces and static routes are not populated in the config of the device.
Any and all help is appreciated.
Thanks & Regards
Grant
11-17-2017 12:19 AM
Yes, the devices are already in a device group.
11-20-2017 11:37 AM
Are you getting an error? Or does Panorama give you a completed status message? If the push goes through without error but you aren't seeing the changes, make sure the device isn't overriding Panorama. That will be indicated by a green and yellow gear icon. When it's taking Panorama's settings, the firewall will show you a green gear icon. You'll need to login to the device (firewall) via the WebGUI to check this.
11-20-2017 12:21 PM
Hello,
A check of the Web GUI of the devices shows a green gear icon for those sections affected, namely interfaces, sub-interface and static routes in a non-default VR.
The Push to Device from the Panorama to the devices is not predictable. For example, when setting up a log forwarding profile the commit to the devices fails to both devices. This failed with an error as follows:
A check of the devices shows config has been pushed. The error in this case is as follows:
To ABCFWDRTW1 device
To ABCFWDRTW2
Any thoughts, suggestions are appreciated.
Regards
02-07-2018 10:42 AM
Did you find a solution to this problem?
Appreciate it if you can share!
Regards,
Layale
11-20-2018 01:41 AM
The first time prior to define in Panorama new Template objects you must push the Template from Panorama to the devices with the flag "Force Template values" on (In Edit Selections)
If you don´t do this the first time, all the Template (Network and Device) definitions in the device are marked as "Override" and then the prefered values in the push are the device values.
Values on Override state : PREFERENCE DEVICE VALUES
Values on No-Override State: panorama values
Once you have values on No-Override State you must configure only from Panorama and Panorama values will be /the values on tehe device.
03-18-2020 09:22 AM
yes the devices are configured in the correct device group
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!