Why is the firewall displaying "__openconfig" as one of the admin user when it is not configured?
13712
Created On 05/09/24 12:40 PM - Last Modified 03/16/25 19:13 PM
Question
Why is the user named "__openconfig" displayed when running "show admin local all" command?
Environment
- VM Series Firewalls and Panorama
- PANOS 10.1 and above
Answer
- User "__openconfig" with "Device Administrator" role is a result of PANOS OpenConfig Plugin installation.
- For PANOS version is 11.1 and above, the plugin comes prepackaged automatically, in turn, creating the user.
- For PANOS versions prior to 11.1, the plugin needs to be installed manually for the user to be created.
-
OpenConfig plugin version 2.0.1 and later, The plugin is automatically installed on PAN-OS version 11.0.4 and later.
-
OpenConfig plugin version 2.0.2 and later, The plugin is automatically installed on PAN-OS version 10.2.11 and later versions of 10.2.
-
- Seeing messages in the logs such as password changes, authenticated user or unable to create API key for the __openconfig user with IP 127.0.0.1, this is normal.
- You may manually upgrade the openconfig plugin by following these steps.
- If you do not use the OpenConfig plugin, disable or uninstall it by following these steps:
- Select Device > Plugins.
- Locate the installed OpenConfig plugin.
- Remove Config to disable the OpenConfig plugin
OR
Uninstall the OpenConfig plugin.