Thank you for posting question @Adnan_SA
If your firewall is already managed by Panorama and all configuration under virtual router were configured by Panorama's Template, then you can just navigate in Panorama to: Templates > Network > Virtual Routers > Static Routes > change: Next Hop, then commit to Panorama and push to device > Templates and then select Template Stack to be bound to Firewall.
If your Firewall is managed by Panorama, but you are not using Template to manage virtual router configuration, you can still create a Template with new configuration under: Templates > Network > Virtual Routers > Static Routes > change: Next Hop, then you have 2 options to push this configuration:
- You can select: "Force Template Values", then all your locally configure virtual configuration will be replaced with what you have configured in Template. Proceed with caution while using this as all non Template defined configuration will wipe locally configured configuration causing outage or undesirable outcome. Here is corresponding KB: https://knowledgebase.paloaltonetworks.com/kcSArticleDetail?id=kA10g000000PMj1&refURL=http%3A%2F%2Fknowledgebase.paloaltonetworks.com%2FkcSArticleDetail
- An alternative way is to proceed with the same configuration in Template, but do not select: "Force Template Values", then Template configuration will be pushed to manage Firewall, but will not be applied. This icon will be shown:
in local Firewall and you can click on this icon and override local configuration. In this way you are in control what gets overridden.
There are more ways to go around it, but this might be either overkill or not practical if you are aiming to change only single configuration.
Kind Regards
Pavel
... View more