Thank you for posting question @JimMcGrady
I tried to simulate this use case with one of the Firewall that is currently not in use. Below are my findings:
When I tried to change Firewalls management interface IP address locally on the Firewall, after I committed changes, the Panorama's Automatic Connection Recovery has kicked in and rolled back the change to the original IP address.
On the second attempt, I disabled the Panorama's Automatic Connection Recovery feature from: Device > Setup > Management > Panorama Settings > [De-select] Enable automated commit recovery, then I tried again to change IP address and after commit was completed it worked well. After approximately 2 minutes, I have seen the Firewall in Panorama with new management IP address.
You might have to restart management process on Firewall to restart log sending if you are using Panorama also for log collection. After this change, I have not seen any issue with Firewalls Device Group / Template Stack. Overall it was smooth.
Outside of Panorama, if you change Firewalls management IP address you might have to reflect this change in your monitoring system, tacacs/radius server, syslog server,...etc.
If my test has not covered the issue you are trying to address or you are looking into something else, let me know.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!