SCM Essentials - No interfaces in Routing and Zones

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

SCM Essentials - No interfaces in Routing and Zones

L1 Bithead

Hi There,
Sorry if this is a stupid question, its my first palo alto deployment in Strata Cloud manager.

I have configured several layer3 interfaces and sub-interfaces and pushed them down to the firewall.

jordan_1-1753334441395.png

jordan_2-1753334462421.png

However when I go to create Zones and attach them to a Virtual Router, I have no options for interfaces.

jordan_3-1753334512602.png

jordan_5-1753334584956.png

 

I tried manually typing out the interface name and its showing as not a valid reference.

jordan_4-1753334538040.png

 

I have no issues when trying to configure locally.

jordan_6-1753334633077.png

 

 

Just unsure if I'm missing something.

5 REPLIES 5

L1 Bithead

Did you ever resolve this?  I am having the same issue.

Hey @MHebert2022 


Yes I did, the issue stems from no variable being created when creating the interface in the folder/firewall configuration. If you do the base config (i just done type, name, tag) in a snippet and then associate the snippet to the firewall, it creates a variable that can then be assigned to the routing objects in the firewall config.

Palo Alto support were great in solving this behavior and assured me that it is, in fact, a stupid behavior.

 

Hit me up if you need screenshots etc,

Jordan 🙂 

L1 Bithead

Thanks for the quick response, and perfect timing, as I am trying to fix this right now.  I will definitely take you up on the screen shot. Thanks!

 

L1 Bithead

Sorry for the delay, I'm in NZ, i was asleep.
Here we go!!
In the config scope, change to snippets and add a new snippet.

jordan_2-1755295480454.pngjordan_3-1755295509051.png


In the snippet configuration, head over to network and interfaces.

jordan_4-1755295589205.png

Add the new interfaces.

jordan_5-1755295620076.png


From the new interface/sub interface etc, setup any settings required. From here i create the interface (which creates the variable $ether1-20), the comment and the management profile. I do the rest (ip, port specific settings, zone, router etc) at the firewall config level.

jordan_6-1755295809766.png

The Variable created $ether1-20 is what gets assigned to the VR and zones either in the snippet config or in the firewall config.

 

From the snippet overview, change the settings for the snippet association and assign it to the firewall your configuring.

jordan_7-1755295953989.pngjordan_8-1755296003954.png

Once associated, you will see the snippet config changes made show on the candidate config for the associated firewalls, and then you can add the new interfaces to zones and VR's by the associated variable.

jordan_9-1755296146563.png

 

 

L1 Bithead

Thank you so much!  This is great!

  • 412 Views
  • 5 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!