Panorama slowly driving me insane.

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

Panorama slowly driving me insane.

L2 Linker

I'm wondering if anyone can explain this to me.

 

I've recently started working with Panorama. When I import devices I follow this process:

 

  1. Add device, and input the serial number of the device and commit.
  2. Wait for it to connect.
  3. Import device configuration into panorama. (I've tried both selecting import shared objects and not selecting it)
  4. If I just try to push to device next after the import, I get an error saying "invalid device name" and the commit immeadiately fails. If I commit to panorama prior to pushing to device, that error goes away.
  5. But..... Every device I import, all the existing policy rules fail because it says there is a duplicate and I have to rename the rule in Panorama, commit and repush, which duplicates the rule on the device and I have then delete the old rules.

Someone please tell me how to make this stop. The next 4 devices I have already have 50+ policy rules, I can't be renaming all of them. All I really even want Panorama for is backups and updates.

 

Thanks.

2 REPLIES 2

L2 Linker

I had similar issues when I moved from stand alone firewalls to panorama. It was a major pain but now that everything is moved over and I push everything out through panorama I love it. 

 

 

L7 Applicator
  1. Step 1 to 3 from your list
  2. Commit to panorama
  3. Export device config bundle. Choose only export
  4. Go to the CLI of the firewall into configure mode and enter "load device-state"
  5. Do a configuration push from panorama and check the option "merge with candidate config"

 

This works perfectly fine for single firewalls. For HA clusters there are some more steps ...

  • 2115 Views
  • 2 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!