- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
Enhanced Security Measures in Place: To ensure a safer experience, we’ve implemented additional, temporary security measures for all users.
08-29-2021 11:15 AM
Hello everyone,
I have question. I inherited a few firewalls that are partially managed by Panorama, meaning I have objects and other items pushed to the firewall from Panorama but mostly everything else is local. On the local firewall, contains all firewall rules, zones, interfaces are configured with ip addresses. The other firewalls are fully managed by Panorama. Not ideal but the real problem is I cannot create shared security rules in Panorama for all my firewalls since no zones exist for these few firewalls.
My question is, can I safely create the zones with the same names in Panorama for these device groups and push it out to the firewalls without impacting the interfaces on the local firewall
Once I can get the zones in Panorama, I can slowly create matching firewall rules and get rid of the local rules
08-29-2021 12:27 PM
If you have a zone configured on panorama and on the firewall node, then the one on the firewall will take precedence. Once you are sure the zone configurations are equal on panorama and the firewall node, then you can remove the config from the firewall itself.
08-29-2021 04:34 PM
@JoergSchuetter I do not yet have a zone configured for these particular firewalls in Panorama. I wasn't sure if the commit would fail or if it would cause other issues. Based on your response, it sounds like it would push to the firewall successfully but would be overridden by local config (which is fine). Right now, I'm more concerned with having the ability to create shared security policy rules across all firewalls, so that they are consistent. I believe this will solve that issue
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!