Requirement is to push cfs settings from one firewall to a group of Firewalls in NSM.

Description

We will be using NSM template export option as NSM does not has reverse or forward inheritance as we used to have in GMS

That means, first we need to make the required CFS object or Profile updates on one of the firewalls of the group from NSM, later we need to Export the configuration of this firewall into a Template and then push the required changes from this template to the rest of the firewalls in the group.

Resolution

 

We are trying to add new CFS URI Objects to the Existing CFS URI List Group already present on the firewall from NSM using templates for a group of firewalls.

 

1) Make the required changes to one of the firewalls from the group in which we want to push the change:

  •  Inventory --> Firewall View -->Click on the firewall name -->Objects -->URI List -->URI List Objects -->We have an existing URI object available on the firewall with name "CFS Object" which has "yahoo.com". Click on Edit on this Object and Add  the object "google.com" to it.

Image

 

  • After this change, go to the "Commit & Deploy" section under Manager View and Click on "Deploy Now" to push the change to the firewall.

 

Image

 

 

2) Under Manager View -->Firewall -->Inventory -->Click on the Actions tab for the same firewall and choose "Export to Template". Give a name to this template and make sure you have "Skip Default Configuration" enabled. Save it.

 

Image

 

3) Go to the Templates under Manager View --> Click on Actions tab for the Exported Template --> Click on View Template configuration.

 

Image

 

4) Select all configuration except for the URI object that you want to update and delete the rest from the template. This is to avoid overwriting all other configurations of the source firewall exported to the template.

Image

5) Apply the template to the firewall or group of firewalls.

Image

 

Image

 

 

6) Commit the change for pushing the template configuration to the firewall.

Image

 

 

Related Articles

  • Analytics On-Prem vs NSM Feature Matrix
    Read More
  • Analytics On-Prem End of Life and NSM Transition FAQ
    Read More
  • NSM On-Prem: Backups over SCP to Windows OpenSSH Server
    Read More
not finding your answers?