Fix Missing Configuration Changes from Firewalls in Panorama

Fix Missing Configuration Changes from Firewalls in Panorama

225
Created On 07/28/26 16:30 PM - Last Modified 07/30/26 00:04 AM


Symptom


  • Missing Audit Logs in Panorama: Navigating to Panorama > Monitor > Config for a specific date reveals only baseline entries (such as firewall onboarding), while expected changes to Security Policies, NAT rules, or Objects are missing.

  • Empty Activity Records: No corresponding configuration modification records appear in Panorama's Task Manager or system Audit Logs for the timeframe in question.

  • Unexpected Rule Origin: A firewall rule appears as a Panorama-managed object, but there is no history or trail of someone manually creating or modifying that rule inside Panorama's change logs



Environment


Panorama 

Any Firewall 



Cause


  • Object Re-creation: Rather than updating an existing rule record, the migration process deletes the local rule on the firewall and creates a new, identical rule within Panorama's device group.

  • UUID Split: Because the deletion happens locally on the firewall and the creation happens on Panorama, the action generates two distinct Unique Identifiers (UUIDs).

  • Log Segregation: Panorama’s config log (Panorama > Monitor > Config) only tracks changes originated directly within Panorama. It does not show local deletion events that occurred on the firewall itself prior to or during the migration push, making it appear as though the configuration history is missing.



Resolution


Step 1: Compare Configuration Audits for UUID Mismatches

Check the config-audit entries on both managed devices around the date in question:

  1. On the Firewall: Inspect the local config-audit logs (Device > Audit Logs) for a rule deletion event. Note the rule's local Unique Identifier (UUID).

  2. On Panorama: Inspect Panorama’s config-audit logs (Panorama > Monitor > Config) for a rule creation event on the same date under the corresponding Device Group. Note the newly assigned UUID.Note : If the rule parameters match but the UUIDs differ between the firewall deletion log and the Panorama creation log, a local-to-Panorama migration occurred.

Step 2: Validate Rule Parameters

Ensure the migrated rule's definition remained intact by cross-referencing the parameters between the deleted local rule and the new Panorama rule:

  • Name & Action: Verify the rule name and action (e.g., allow / deny).

  • Zones & Addresses: Confirm Source/Destination zones, Source/Destination IP objects, and Services match.

  • Security Profiles: Check that attached profiles or Profile Groups (e.g., Security Profile Group) are identical.



Actions
  • Print
  • Copy Link

    https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA1Ki000000kCAUKA2&lang=en_US&refURL=http%3A%2F%2Fknowledgebase.paloaltonetworks.com%2FKCSArticleDetail