01-20-2015 01:27 PM
I recently upgraded Panorama to 6.1.1 from 5.0.11. When I did so, RANCID was no longer able to log into Panorama and do its configuration tracking.
I tracked down the problem to a superreader not being able to issue the "set cli pager off" command. This worked in 5.0.11. It still works on a firewall running 6.1.1, just not on Panorama. In 6.1.1 on Panorama, the "set" command is totally restricted. On a PA-4060, I get what I expect, only the "set cli" and "set password" commands are available.
I can temporarily give the account RANCID uses superuser permissions, but there isn't a reason this account needs write permissions.
Am I the only one having this problem? Something about my Panorama setup? Or can other reproduce this? Any idea at which version this was broken?
03-26-2015 02:10 PM
For the record, I did go to PAN support with this. They provided a patched version of Panorama, 6.1.2-h1, with the fix. I assume that the fix will be present in future releases.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!