- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
06-07-2024 10:14 AM
Best regard
Equipment
I have 2 specific doubts that I would like the community to clarify for me.
1. I have a device managed by Panorama, due to an incident that occurred, local configurations were made on the device, and several interfaces and policies were configured. As all the administration is being carried out in the panorama and when the management is recovered again from the panorama, the existing template is totally different from the config that is in Palo Alto, the following questions arise: How to make the configuration that was done locally synchronize with the panorama? What is the best way to carry out this process? Is it necessary to remove the panorama device and add it again? If the device is removed from Panorama, it will bring me to the existing configuration in the template. When carrying out this process, is the configuration that I made locally not deleted?
2. The second scenario I have is the following: I have 5 teams managed by Panorama. All 5 teams have a totally different DG and Template. I made a correct configuration on 1 computer and on the other computer I made a wrong configuration (due to human error or it was not required). I applied all the changes in a single commit and push. Realizing that I made a mistake, I would like to restore the previous configuration on the computer on which the configuration was unsuccessful, but not on the computer on which the configuration was successful. The question is: How should this backup restoration process be carried out solely and exclusively on the computer on which the configuration was incorrect? Should it be done locally on the computer? (Taking into account that if I export the config from the computer I only get a few xml lines) (I assume there were many configurations and I don't remember all of them, therefore I want to load a backup). I have tried to carry out this process by loading version in panorama, but doing so would also eliminate the device whose configuration was correct and in summary>manage>backups for a strange reason an extremely old version appears, which would not help me either.
I look forward to your questions, suggestions and/or answers.
08-20-2024 01:31 AM
Hi @afalfaro
Below are my inputs to your questions.
Refer this article to know more about it.
Now if your issue is fixed and you want everything to be running smoothly from Panorama. Then you can replicate all the changes on the Panorama template stacks as that of local firewall.
Once you have all the desired configuration available on the Panorama, you need to push a configuration with FORCE TEMPLATE VALUES checked. This commit will override all the local settings/configuration This includes locally configured objects as well as objects pushed from Panorama that were locally overwritten. If an object is locally configured on the firewall, but is not configured in a template or template stack, then it remains unchanged on the firewall and is not deleted. The setting is disabled by default and must be enabled (checked) on each push from Panorama to managed firewalls.
NOTE- You need to make sure all the desired configuration is done on the Panorama first before pushing it to the local firewalls.
2. For your 2nd question, the way to handle it is reverting configuration based on the administrator. You can revert changes by selecting specific user/admin who made wrong changes.
So, only those specific changes will be reverted.
Kindly refer this article to get more information.
Revert Firewall Configuration Changes (paloaltonetworks.com)
Hope it helps!
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!