cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Who rated this post

Community Team Member

Hi @alirezabtf ,

 

Technically, you can try to do it that way as @nohash4u describes.

 

However, I usually advise against the all-at-once approach because of how the firewall handles the cutover. I've seen scenarios where it didn't go right so if this is a production firewall with live users, I would use more of a Side-by-Side method (adding the new zones to the rules first, then swapping, like you mentioned).

 

Why: 
Even if the push is successful, renaming a zone is a disruptive event.  When you rename a zone in Panorama and push it, the firewall sees the old ID go away and a new ID created.  The result is that active sessions currently flowing through those zones will be dropped and users will have to reconnect.

 

I believe the process is explained in detail in this post:

https://live.paloaltonetworks.com/t5/general-topics/zone-rename-effects-on-panorama-and-managed-devi...

 

Hope this jelps !

 

Cheers,

 

LIVEcommunity team member, CISSP
Cheers,
Kiwi
Please help out other users and “Accept as Solution” if a post helps solve your problem !

Read more about how and why to accept solutions.
Who rated this post