What is the difference between config lock and commit lock?

What is the difference between config lock and commit lock?

7741
Created On 05/29/23 22:51 PM - Last Modified 08/15/23 18:03 PM


Question


What is the difference between config lock and commit lock?

Environment


  • Palo Alto Firewall or Panorama
  • Supported PANOS


Answer


Config and commit locks are used to prevent collisions that can occur when two administrators are making changes at the same time.

Config lock:

  1. Prevents other admins from changing the configuration.
  2. Blocks other administrators from making changes to the candidate configuration.
  3. It's used when the admin takes a backup of the configuration. So that no one can change the candidate configuration while taking a backup. A custom role administrator who cannot commit changes can set a Config lock and save the changes to the candidate configuration.
  4. This lock will not be get removed after performing a commit. Only a superuser or the administrator who set the lock can remove it.


Commit lock:

  1. Prevents other admins from committing the configuration.
  2. Blocks other administrators from making changes to the running configuration.
  3. It's used when you want only one admin to perform changes to the firewall/panorama.
  4. This lock automatically gets removed after performing a commit.
     


Additional Information


  • Candidate configuration - Configuration which needs to the committed (Changes made to the firewall before performing commit)
  • Running configuration -  Actual configuration controlling the operation of the firewall.


Actions
  • Print
  • Copy Link

    https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u000000bpo7CAA&lang=en_US%E2%80%A9&refURL=http%3A%2F%2Fknowledgebase.paloaltonetworks.com%2FKCSArticleDetail