I have been looking through posts but cannot seem to find what I am looking for.
There are some Management Interface Permitted IPs on our Firewalls that do not match the Template that we have for them in Panorama. Is there a CLI command where I can export the Permitted IP list for a firewalls' Management access? From the GUI there doesn't seem to be an export function either.
I just need to compare what is on the Firewalls vs. what is listed in Panorama as it would appear people have overwritten the template.
Hi @NelsonE3 ,
By default the Management Interface Settings DO override what is sent by Panorama. You should see the orange gear on top of the green one to indicate override. Mousing over the gear will also confirm.
You can run these commands from the CLI to see what is configured locally:
> set cli config-output-format set
# show deviceconfig system permitted-ip
The Panorama pushed config will NOT show there. If you delete the local configuration, the Panorama configuration should then show up.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!