- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
05-13-2025 10:24 PM - edited 05-13-2025 10:38 PM
Need your help we setup a new PA850 to replace our PRIMARY FW in EUR. Now the config has been push to the device however, i'm seeing the eth1/1 is disabled for some reason.
Is there a command that I can forcefully enable it? even on GUI it shows RED status.
I tried to disabled or re-enable it on CLI and I got this error
set failed, may need to override template object ethernet1/1 first
05-15-2025 07:16 PM
Hi @weezy ,
Thanks for info, Looks like configuration has been pushed from panorama. if you are enforcing the config from panorama then you can make the changes at panorama template or you can override the config locally at firewall and then make necessary changes as per your requirement.
ukn/ukn/down(power-down) is when you set the Link-State to Disable
disabled/down: You've disabled the interface.
forced/ukn: You've forced the speed/duplex setting and the status of the interface is unknown. Usually caused by unsupported SFPs or if you statically set the link-state to up but the interface is unplugged.
forced/down: You've forced the speed/duplex settings and the interface is down.
05-19-2025 12:58 AM
@weezy Did you remember to disable ZTP mode after the first boot?
by default new devices boot up in ZTP mode which reserves interface 1/1 for ZTP. this will also block it from being used for anything else
you can disable that using the following command:
set system ztp disable
after a reboot you should be good to go
05-19-2025 08:43 PM
Our SR. Engr check it and he said that the device on the other end which is cisco core switch interface is on error disabled state so he bounce it and he said that it was up now.
is that also possible too?
05-19-2025 08:44 PM
after I disable ZTP mode, can I reboot the PA?
05-22-2025 12:34 AM
yes, reboot is required when you disable ZTP
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!