How are duplicate shared objects identified in Panorama?

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

How are duplicate shared objects identified in Panorama?

L1 Bithead

I know that when you migrate a firewall into Panorama and you keep the Import device's shared objects into Panorama's shared context box checked, this imports the firewall's objects as shared objects, unless there are duplicates. I'm wondering--how does Panorama identify any duplicates? Is it by the name of the object or other characteristics (such as the IP address itself)?

 

For example: If I have an Address Object on one firewall called "Server-DNS" with IP 8.8.8.8 and an Address Object on a different firewall called "DNS-Server" with the same IP 8.8.8.8, will it identify that as a duplicate? I'm assuming not, since you are able to have multiple Address Objects with the same IP, but would like to verify.

 

Thanks!

1 ACCEPTED SOLUTION

Accepted Solutions

Cyber Elite
Cyber Elite

Hi @MDroyKT ,

 

I have imported multiple NGFW configs into Panorama, and the duplicates are always removed.  I never thought about the specifics until now.  Here is a doc that explains the process -> https://docs.paloaltonetworks.com/panorama/9-1/panorama-admin/manage-firewalls/transition-a-firewall....  Look under the section "Plan how to manage shared settings."  The rules are as follows:

 

  1. If the name and value are the same, it is not imported.
  2. If the name or value differs (assuming one name or value is the same?), the object is imported into the device group and not Shared.
  3. If the object references a shared object or template on the NGFW, it is imported into Shared even if you didn't check the box.

I would love to hear what you find if you import objects with duplicate names and/or values.

 

Thanks,

 

Tom

Help the community: Like helpful comments and mark solutions.

View solution in original post

2 REPLIES 2

Cyber Elite
Cyber Elite

Hi @MDroyKT ,

 

I have imported multiple NGFW configs into Panorama, and the duplicates are always removed.  I never thought about the specifics until now.  Here is a doc that explains the process -> https://docs.paloaltonetworks.com/panorama/9-1/panorama-admin/manage-firewalls/transition-a-firewall....  Look under the section "Plan how to manage shared settings."  The rules are as follows:

 

  1. If the name and value are the same, it is not imported.
  2. If the name or value differs (assuming one name or value is the same?), the object is imported into the device group and not Shared.
  3. If the object references a shared object or template on the NGFW, it is imported into Shared even if you didn't check the box.

I would love to hear what you find if you import objects with duplicate names and/or values.

 

Thanks,

 

Tom

Help the community: Like helpful comments and mark solutions.

Thank you, Tom! It will likely be a few months at least before I get all our firewalls migrated (still in the planning phase for the first firewall migration) but I will make a note to comment back here on it once I do.

 

Thanks,

Michelle

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!