Can you import objects from a firewall into a new Panorama config to then push to all firewalls?

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

Can you import objects from a firewall into a new Panorama config to then push to all firewalls?

L2 Linker

We are working on configuring Panorama and currently already have 3 firewall HA pairs. We have 4000+ address objects in one of our firewall pairs. Is there a way to import these into Panorama to then push to the other 2 firewall pairs post integration? It would be great to not have to add 4000 address objects to the other two firewalls.

3 accepted solutions

Accepted Solutions

Cyber Elite
Cyber Elite

Hello @MDroyKT

 

thanks for the post!

 

The scenario you described is possible. Below are 2 KB articles that include information to import configuration and then push it back to the Firewall as Panorama managed configuration. Both KBs are a bit dated, however the concept remains the same.

 

https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000CloRCAS

https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClZSCA0

 

Regarding pushing Device Group objects from imported configuration, I would advised to perform following steps.

 

1.) During import of configuration into Panorama, create a Device Group that is position in the Device Group hierarchy that is not device specific, but is logically position to be meant as shared for multiple Firewalls for example based on function of Firewalls or location.

2.) After you complete the import and push the configuration back in step no.1, you can add 2 remaining Firewalls to the same Device Group. If you manage to add them to the same Device Group, the configuration can be shared to them by pushing configuration from Panorama.

 

Kind Regards

Pavel

Help the community: Like helpful comments and mark solutions.

View solution in original post

Cyber Elite
Cyber Elite

Hi @MDroyKT,

 

Here are the steps to add an HA pair to Panorama -> https://docs.paloaltonetworks.com/panorama/10-2/panorama-admin/manage-firewalls/transition-a-firewal....

 

It includes some of the pointers that @PavelK made.  You put the HA pair in the same DG and templates.  Notice that config sync is okay to be enabled afterwards for local changes, just not during the import process.  Config sync does not apply to configs pushed from Panorama.

 

There are a couple of important steps to understand:

 

  1. You must "Export or push device config bundle" (step 6, 5) for the 1st push to the NGFW.  This step actually removes the local Policies and Objects configuration.
  2. If you want the Network and Device configuration managed by Panorama, you must select "Force Template Values" (step 8, 2) in order to override the local configuration.

Thanks,

 

Tom

Help the community: Like helpful comments and mark solutions.

View solution in original post

Cyber Elite
Cyber Elite

Hi @MDroyKT ,

 

Yes, there is a way to do this.  If you checked the box "Import devices's shared objects into Panorama's shared context" during the config import, then your objects will already be in the Shared device group and will be pushed out to all NGFWs.  Another item to note is that the Panorama > Setup > Management > Panorama Settings > "Share Unused Address and Service Objects with Devices" should be checked to share unused objects.  If not, the objects will be pushed once they are used.

 

If you did not do that, you can shift-click the object line (not check box) and bulk move the objects to Shared.  Your policies for the other NGFWs will be in a lower device group and not pushed.

 

Thanks,

 

Tom

Help the community: Like helpful comments and mark solutions.

View solution in original post

7 REPLIES 7

Cyber Elite
Cyber Elite

Hello @MDroyKT

 

thanks for the post!

 

The scenario you described is possible. Below are 2 KB articles that include information to import configuration and then push it back to the Firewall as Panorama managed configuration. Both KBs are a bit dated, however the concept remains the same.

 

https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000CloRCAS

https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClZSCA0

 

Regarding pushing Device Group objects from imported configuration, I would advised to perform following steps.

 

1.) During import of configuration into Panorama, create a Device Group that is position in the Device Group hierarchy that is not device specific, but is logically position to be meant as shared for multiple Firewalls for example based on function of Firewalls or location.

2.) After you complete the import and push the configuration back in step no.1, you can add 2 remaining Firewalls to the same Device Group. If you manage to add them to the same Device Group, the configuration can be shared to them by pushing configuration from Panorama.

 

Kind Regards

Pavel

Help the community: Like helpful comments and mark solutions.

Thank you very much!!

Cyber Elite
Cyber Elite

Hi @MDroyKT,

 

Here are the steps to add an HA pair to Panorama -> https://docs.paloaltonetworks.com/panorama/10-2/panorama-admin/manage-firewalls/transition-a-firewal....

 

It includes some of the pointers that @PavelK made.  You put the HA pair in the same DG and templates.  Notice that config sync is okay to be enabled afterwards for local changes, just not during the import process.  Config sync does not apply to configs pushed from Panorama.

 

There are a couple of important steps to understand:

 

  1. You must "Export or push device config bundle" (step 6, 5) for the 1st push to the NGFW.  This step actually removes the local Policies and Objects configuration.
  2. If you want the Network and Device configuration managed by Panorama, you must select "Force Template Values" (step 8, 2) in order to override the local configuration.

Thanks,

 

Tom

Help the community: Like helpful comments and mark solutions.

Thank you!!

L2 Linker

After getting through an authentication configuration issue, I've finally gotten around to formally planning for this firewall migration. Now that I've taken a closer look, it seems like if I do as you mentioned, @PavelK and @TomYoung, I would have to push both the current Objects AND Policies from my main firewall pair to my other two firewall pairs. The problem is, I only want the Objects to be pushed to the other pairs.....

 

Is there a way to do this?

Cyber Elite
Cyber Elite

Hi @MDroyKT ,

 

Yes, there is a way to do this.  If you checked the box "Import devices's shared objects into Panorama's shared context" during the config import, then your objects will already be in the Shared device group and will be pushed out to all NGFWs.  Another item to note is that the Panorama > Setup > Management > Panorama Settings > "Share Unused Address and Service Objects with Devices" should be checked to share unused objects.  If not, the objects will be pushed once they are used.

 

If you did not do that, you can shift-click the object line (not check box) and bulk move the objects to Shared.  Your policies for the other NGFWs will be in a lower device group and not pushed.

 

Thanks,

 

Tom

Help the community: Like helpful comments and mark solutions.

THANK YOU so much!!

  • 3 accepted solutions
  • 2907 Views
  • 7 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!