PCNSE · Question #711
After importing a pre-configured firewall configuration to Panorama, what step is required to ensure a commit/push is successful without duplicating local configurations?
The correct answer is D. Perform the Export or push Device Config Bundle to the newly managed firewall.. When a pre-configured firewall's configuration is imported into Panorama, Panorama now manages the device but the device still has its full local configuration. If a standard commit/push is performed, Panorama would attempt to push its managed configuration on top of the existing
Question
After importing a pre-configured firewall configuration to Panorama, what step is required to ensure a commit/push is successful without duplicating local configurations?
Options
- AEnsure Force Template Values is checked when pushing configuration.
- BPush the Template first, then push Device Group to the newly managed firewall.
- CPush the Device Group first, then push Template to the newly managed firewall.
- DPerform the Export or push Device Config Bundle to the newly managed firewall.
How the community answered
(19 responses)- A11% (2)
- B5% (1)
- C5% (1)
- D79% (15)
Explanation
When a pre-configured firewall's configuration is imported into Panorama, Panorama now manages the device but the device still has its full local configuration. If a standard commit/push is performed, Panorama would attempt to push its managed configuration on top of the existing local configuration, potentially causing duplicates or conflicts. The correct step is to perform an 'Export or push Device Config Bundle', which pushes a complete, unified configuration bundle (merging Panorama-managed and local elements) to the device, replacing the local config cleanly and avoiding duplication. Checking 'Force Template Values' (A) only overrides template values, not the full config. Ordering Template vs. Device Group pushes (B, C) does not solve the duplication problem.
Topics
Community Discussion
No community discussion yet for this question.