Discussion:
[rancid] Palo Alto Networks
Nate Beck
2008-05-06 18:51:35 UTC
Permalink
Has anyone on the list worked with Palo Alto Network firewalls and Rancid? I was wondering if anyone has created a *login for them.

Thanks

-------------------
Nathan Beck
Sr. IT Engineer
Jive Software
503.972.9024

[cid:3292919495_689721]
Guillaume Dupuis
2012-03-29 12:53:33 UTC
Permalink
Nate Beck <Nate.Beck <at> jivesoftware.com> writes:

>
>
> Has anyone on the list worked with Palo Alto Network firewalls and Rancid?  I
was wondering if anyone has created a *login for them.
> Thanks-------------------
> Nathan BeckSr. IT Engineer
> Jive Software
> 503.972.9024

Hi Nate,

Did you find a *login script for PAN?

Thanks,

Guillaume Dupuis
Kishore Rajani
2013-09-23 13:52:06 UTC
Permalink
HI,

did you manage to get the RANCID running with PAN?

Regards,
Kishore

On Thursday, 29 March 2012 13:53:33 UTC+1, Guillaume Dupuis wrote:
>
> Nate Beck <Nate.Beck <at> jivesoftware.com> writes:
>
> >
> >
> > Has anyone on the list worked with Palo Alto Network firewalls and
> Rancid? I
> was wondering if anyone has created a *login for them.
> > Thanks-------------------
> > Nathan BeckSr. IT Engineer
> > Jive Software
> > 503.972.9024
>
> Hi Nate,
>
> Did you find a *login script for PAN?
>
> Thanks,
>
> Guillaume Dupuis
>
> _______________________________________________
> Rancid-discuss mailing list
> Rancid-***@shrubbery.net <javascript:>
> http://www.shrubbery.net/mailman/listinfo.cgi/rancid-discuss
>
>
Hughes, Doug
2013-09-24 16:25:44 UTC
Permalink
Yes, I have working panlogin and panrancid and have contributed them upstream. Have you not been able to get them to work?


From: rancid-discuss-***@shrubbery.net [mailto:rancid-discuss-***@shrubbery.net] On Behalf Of Kishore Rajani
Sent: Monday, September 23, 2013 9:52 AM
To: rancid-***@googlegroups.com
Cc: ***@novidys.com; rancid-***@shrubbery.net
Subject: Re: [rancid] Palo Alto Networks

HI,

did you manage to get the RANCID running with PAN?

Regards,
Kishore

On Thursday, 29 March 2012 13:53:33 UTC+1, Guillaume Dupuis wrote:
Nate Beck <Nate.Beck <at> jivesoftware.com<http://jivesoftware.com>> writes:

>
>
> Has anyone on the list worked with Palo Alto Network firewalls and Rancid? I
was wondering if anyone has created a *login for them.
> Thanks-------------------
> Nathan BeckSr. IT Engineer
> Jive Software
> 503.972.9024

Hi Nate,

Did you find a *login script for PAN?

Thanks,

Guillaume Dupuis

_______________________________________________
Rancid-discuss mailing list
Rancid-***@shrubbery.net<javascript:>
http://www.shrubbery.net/mailman/listinfo.cgi/rancid-discuss
Ryan Milton
2013-09-24 20:57:32 UTC
Permalink
I would certainly be interested in adding PAN devices to Rancid. I thought that they couldn’t be read. That is what I’ve found with my HP switches—but that is another matter. Any ideas on getting PAN devices read by Rancid would be useful.

Regards,
Ryan Milton

From: rancid-discuss-***@shrubbery.net [mailto:rancid-discuss-***@shrubbery.net] On Behalf Of Hughes, Doug
Sent: Tuesday, September 24, 2013 12:26 PM
To: Kishore Rajani; rancid-***@googlegroups.com
Cc: ***@novidys.com; rancid-***@shrubbery.net
Subject: Re: [rancid] Palo Alto Networks

Yes, I have working panlogin and panrancid and have contributed them upstream. Have you not been able to get them to work?


From: rancid-discuss-***@shrubbery.net<mailto:rancid-discuss-***@shrubbery.net> [mailto:rancid-discuss-***@shrubbery.net] On Behalf Of Kishore Rajani
Sent: Monday, September 23, 2013 9:52 AM
To: rancid-***@googlegroups.com<mailto:rancid-***@googlegroups.com>
Cc: ***@novidys.com<mailto:***@novidys.com>; rancid-***@shrubbery.net<mailto:rancid-***@shrubbery.net>
Subject: Re: [rancid] Palo Alto Networks

HI,

did you manage to get the RANCID running with PAN?

Regards,
Kishore

On Thursday, 29 March 2012 13:53:33 UTC+1, Guillaume Dupuis wrote:
Nate Beck <Nate.Beck <at> jivesoftware.com<http://jivesoftware.com>> writes:

>
>
> Has anyone on the list worked with Palo Alto Network firewalls and Rancid? I
was wondering if anyone has created a *login for them.
> Thanks-------------------
> Nathan BeckSr. IT Engineer
> Jive Software
> 503.972.9024

Hi Nate,

Did you find a *login script for PAN?

Thanks,

Guillaume Dupuis

_______________________________________________
Rancid-discuss mailing list
Rancid-***@shrubbery.net<javascript:>
http://www.shrubbery.net/mailman/listinfo.cgi/rancid-discuss
Hughes, Doug
2013-09-24 21:01:39 UTC
Permalink
Sure they can. I do it for 3 of them right now.

Attached. Set your ‘switch type’ to paloalto. Works with names or IP addresses.

From: Ryan Milton [mailto:***@mvsusa.com]
Sent: Tuesday, September 24, 2013 4:58 PM
To: Hughes, Doug; Kishore Rajani; rancid-***@googlegroups.com
Cc: ***@novidys.com; rancid-***@shrubbery.net
Subject: RE: [rancid] Palo Alto Networks

I would certainly be interested in adding PAN devices to Rancid. I thought that they couldn’t be read. That is what I’ve found with my HP switches—but that is another matter. Any ideas on getting PAN devices read by Rancid would be useful.

Regards,
Ryan Milton

From: rancid-discuss-***@shrubbery.net<mailto:rancid-discuss-***@shrubbery.net> [mailto:rancid-discuss-***@shrubbery.net] On Behalf Of Hughes, Doug
Sent: Tuesday, September 24, 2013 12:26 PM
To: Kishore Rajani; rancid-***@googlegroups.com<mailto:rancid-***@googlegroups.com>
Cc: ***@novidys.com<mailto:***@novidys.com>; rancid-***@shrubbery.net<mailto:rancid-***@shrubbery.net>
Subject: Re: [rancid] Palo Alto Networks

Yes, I have working panlogin and panrancid and have contributed them upstream. Have you not been able to get them to work?


From: rancid-discuss-***@shrubbery.net<mailto:rancid-discuss-***@shrubbery.net> [mailto:rancid-discuss-***@shrubbery.net] On Behalf Of Kishore Rajani
Sent: Monday, September 23, 2013 9:52 AM
To: rancid-***@googlegroups.com<mailto:rancid-***@googlegroups.com>
Cc: ***@novidys.com<mailto:***@novidys.com>; rancid-***@shrubbery.net<mailto:rancid-***@shrubbery.net>
Subject: Re: [rancid] Palo Alto Networks

HI,

did you manage to get the RANCID running with PAN?

Regards,
Kishore

On Thursday, 29 March 2012 13:53:33 UTC+1, Guillaume Dupuis wrote:
Nate Beck <Nate.Beck <at> jivesoftware.com<http://jivesoftware.com>> writes:

>
>
> Has anyone on the list worked with Palo Alto Network firewalls and Rancid? I
was wondering if anyone has created a *login for them.
> Thanks-------------------
> Nathan BeckSr. IT Engineer
> Jive Software
> 503.972.9024

Hi Nate,

Did you find a *login script for PAN?

Thanks,

Guillaume Dupuis

_______________________________________________
Rancid-discuss mailing list
Rancid-***@shrubbery.net<javascript:>
http://www.shrubbery.net/mailman/listinfo.cgi/rancid-discuss
Hughes, Doug
2013-09-25 00:40:42 UTC
Permalink
I just sent you the latest versions. I'm the original creator. I can't say if the other version is older, but if they are different, use the ones I sent. (and make sure they are first in the path)

So you are saying when you run panrancid it doesn't create the config file for you?

From: Kishore Rajani [mailto:***@gmail.com]
Sent: Tuesday, September 24, 2013 5:44 PM
To: Hughes, Doug
Cc: Ryan Milton; rancid-***@googlegroups.com; ***@novidys.com; rancid-***@shrubbery.net
Subject: Re: [rancid] Palo Alto Networks

Hi All,

Thanks for your inputs.. much appreciated.

I think i had downloaded these files from some other website, not sure if you have modified it, Doug..

In my setup, I am able to login into the device using panlogin.. however the device config are not backed up. Everything works smooth for Cisco devices.
I have updated the routers.db and other files for PAN devices, but no luck yet.

Unfortunately, I am unable to reach my remote site server at the moment, else would have pasted the log file.

Regards,
Kishore


On 24 September 2013 22:01, Hughes, Doug <***@deshawresearch.com<mailto:***@deshawresearch.com>> wrote:
Sure they can. I do it for 3 of them right now.

Attached. Set your 'switch type' to paloalto. Works with names or IP addresses.

From: Ryan Milton [mailto:***@mvsusa.com<mailto:***@mvsusa.com>]
Sent: Tuesday, September 24, 2013 4:58 PM
To: Hughes, Doug; Kishore Rajani; rancid-***@googlegroups.com<mailto:rancid-***@googlegroups.com>
Cc: ***@novidys.com<mailto:***@novidys.com>; rancid-***@shrubbery.net<mailto:rancid-***@shrubbery.net>
Subject: RE: [rancid] Palo Alto Networks

I would certainly be interested in adding PAN devices to Rancid. I thought that they couldn't be read. That is what I've found with my HP switches-but that is another matter. Any ideas on getting PAN devices read by Rancid would be useful.

Regards,
Ryan Milton

From: rancid-discuss-***@shrubbery.net<mailto:rancid-discuss-***@shrubbery.net> [mailto:rancid-discuss-***@shrubbery.net] On Behalf Of Hughes, Doug
Sent: Tuesday, September 24, 2013 12:26 PM
To: Kishore Rajani; rancid-***@googlegroups.com<mailto:rancid-***@googlegroups.com>
Cc: ***@novidys.com<mailto:***@novidys.com>; rancid-***@shrubbery.net<mailto:rancid-***@shrubbery.net>
Subject: Re: [rancid] Palo Alto Networks

Yes, I have working panlogin and panrancid and have contributed them upstream. Have you not been able to get them to work?


From: rancid-discuss-***@shrubbery.net<mailto:rancid-discuss-***@shrubbery.net> [mailto:rancid-discuss-***@shrubbery.net] On Behalf Of Kishore Rajani
Sent: Monday, September 23, 2013 9:52 AM
To: rancid-***@googlegroups.com<mailto:rancid-***@googlegroups.com>
Cc: ***@novidys.com<mailto:***@novidys.com>; rancid-***@shrubbery.net<mailto:rancid-***@shrubbery.net>
Subject: Re: [rancid] Palo Alto Networks

HI,

did you manage to get the RANCID running with PAN?

Regards,
Kishore

On Thursday, 29 March 2012 13:53:33 UTC+1, Guillaume Dupuis wrote:
Nate Beck <Nate.Beck <at> jivesoftware.com<http://jivesoftware.com>> writes:

>
>
> Has anyone on the list worked with Palo Alto Network firewalls and Rancid? I
was wondering if anyone has created a *login for them.
> Thanks-------------------
> Nathan BeckSr. IT Engineer
> Jive Software
> 503.972.9024

Hi Nate,

Did you find a *login script for PAN?

Thanks,

Guillaume Dupuis
Kishore Rajani
2013-09-25 05:48:31 UTC
Permalink
I will use them as soon as the remote site becomes available.. and will
also let you know how did it go.

Appreciate your help.

Regards,
Kishore


On 25 September 2013 01:40, Hughes, Doug
<***@deshawresearch.com>wrote:

> I just sent you the latest versions. I’m the original creator. I can’t
> say if the other version is older, but if they are different, use the ones
> I sent. (and make sure they are first in the path)****
>
> ** **
>
> So you are saying when you run panrancid it doesn’t create the config file
> for you?****
>
> ** **
>
> *From:* Kishore Rajani [mailto:***@gmail.com]
> *Sent:* Tuesday, September 24, 2013 5:44 PM
> *To:* Hughes, Doug
> *Cc:* Ryan Milton; rancid-***@googlegroups.com;
> ***@novidys.com; rancid-***@shrubbery.net
>
> *Subject:* Re: [rancid] Palo Alto Networks****
>
> ** **
>
> Hi All,****
>
> ** **
>
> Thanks for your inputs.. much appreciated.****
>
> ** **
>
> I think i had downloaded these files from some other website, not sure if
> you have modified it, Doug..****
>
> ** **
>
> In my setup, I am able to login into the device using panlogin.. however
> the device config are not backed up. Everything works smooth for Cisco
> devices.****
>
> I have updated the routers.db and other files for PAN devices, but no luck
> yet.****
>
> ** **
>
> Unfortunately, I am unable to reach my remote site server at the moment,
> else would have pasted the log file.****
>
> ** **
>
> Regards,****
>
> Kishore****
>
> ** **
>
> ** **
>
> On 24 September 2013 22:01, Hughes, Doug <
> ***@deshawresearch.com> wrote:****
>
> Sure they can. I do it for 3 of them right now.****
>
> ****
>
> Attached. Set your ‘switch type’ to paloalto. Works with names or IP
> addresses.****
>
> ****
>
> *From:* Ryan Milton [mailto:***@mvsusa.com]
> *Sent:* Tuesday, September 24, 2013 4:58 PM
> *To:* Hughes, Doug; Kishore Rajani; rancid-***@googlegroups.com
> *Cc:* ***@novidys.com; rancid-***@shrubbery.net
> *Subject:* RE: [rancid] Palo Alto Networks****
>
> ****
>
> I would certainly be interested in adding PAN devices to Rancid. I thought
> that they couldn’t be read. That is what I’ve found with my HP switches—but
> that is another matter. Any ideas on getting PAN devices read by Rancid
> would be useful.****
>
> ****
>
> Regards,****
>
> Ryan Milton****
>
> ****
>
> *From:* rancid-discuss-***@shrubbery.net [
> mailto:rancid-discuss-***@shrubbery.net<rancid-discuss-***@shrubbery.net>]
> *On Behalf Of *Hughes, Doug
> *Sent:* Tuesday, September 24, 2013 12:26 PM
> *To:* Kishore Rajani; rancid-***@googlegroups.com
> *Cc:* ***@novidys.com; rancid-***@shrubbery.net
> *Subject:* Re: [rancid] Palo Alto Networks****
>
> ****
>
> Yes, I have working panlogin and panrancid and have contributed them
> upstream. Have you not been able to get them to work?****
>
> ****
>
> ****
>
> *From:* rancid-discuss-***@shrubbery.net [
> mailto:rancid-discuss-***@shrubbery.net<rancid-discuss-***@shrubbery.net>]
> *On Behalf Of *Kishore Rajani
> *Sent:* Monday, September 23, 2013 9:52 AM
> *To:* rancid-***@googlegroups.com
> *Cc:* ***@novidys.com; rancid-***@shrubbery.net
> *Subject:* Re: [rancid] Palo Alto Networks****
>
> ****
>
> HI,
>
> did you manage to get the RANCID running with PAN?
>
> Regards,
> Kishore
>
> On Thursday, 29 March 2012 13:53:33 UTC+1, Guillaume Dupuis wrote:****
>
> Nate Beck <Nate.Beck <at> jivesoftware.com> writes:****
>
> >
> >
> > Has anyone on the list worked with Palo Alto Network firewalls and
> Rancid? I
> was wondering if anyone has created a *login for them.
> > Thanks-------------------
> > Nathan BeckSr. IT Engineer
> > Jive Software
> > 503.972.9024****
>
> Hi Nate,****
>
> Did you find a *login script for PAN?****
>
> Thanks,****
>
> Guillaume Dupuis****
>
> _______________________________________________
> Rancid-discuss mailing list
> Rancid-***@shrubbery.net
> http://www.shrubbery.net/mailman/listinfo.cgi/rancid-discuss****
>
> ** **
>
Hughes, Doug
2013-10-02 14:21:12 UTC
Permalink
I suspect you haven't added the mapping to your vendor table.
In rancid-fe, find the %vendortable hash (about 2/3 of the way down)

Add a line:
'paloalto' => 'panrancid',


I put mine in alphabetical order, just below netscreen.

From: Kishore Rajani [mailto:***@gmail.com]
Sent: Wednesday, October 02, 2013 10:14 AM
To: Hughes, Doug
Cc: Ryan Milton; rancid-***@googlegroups.com; ***@novidys.com; rancid-***@shrubbery.net
Subject: Re: [rancid] Palo Alto Networks

HI Doug,
Now that I have my remote site up, here are the logs that are generated by rancid-run:
exec failed router manufacturer paloalto: No such file or directory
exec failed router manufacturer paloalto: No such file or directory
exec failed router manufacturer paloalto: No such file or directory
exec failed router manufacturer paloalto: No such file or directory
exec failed router manufacturer paloalto: No such file or directory
exec failed router manufacturer paloalto: No such file or directory
exec failed router manufacturer paloalto: No such file or directory
exec failed router manufacturer paloalto: No such file or directory
Any idea where I could have been wrong. I have the panlogin and panrancid in the "/usr/local/rancid/bin/" directory. Also I have checked the router.db file and it has the config like:
FWL1:paloalto:up
FWL2:paloalto:up
FWL3:paloalto:up
FWL4:paloalto:up
FWL5:paloalto:up
Thanks and Regards,
Kishore

On 25 September 2013 06:48, Kishore Rajani <***@gmail.com<mailto:***@gmail.com>> wrote:
I will use them as soon as the remote site becomes available.. and will also let you know how did it go.

Appreciate your help.

Regards,
Kishore

On 25 September 2013 01:40, Hughes, Doug <***@deshawresearch.com<mailto:***@deshawresearch.com>> wrote:
I just sent you the latest versions. I'm the original creator. I can't say if the other version is older, but if they are different, use the ones I sent. (and make sure they are first in the path)

So you are saying when you run panrancid it doesn't create the config file for you?

From: Kishore Rajani [mailto:***@gmail.com<mailto:***@gmail.com>]
Sent: Tuesday, September 24, 2013 5:44 PM
To: Hughes, Doug
Cc: Ryan Milton; rancid-***@googlegroups.com<mailto:rancid-***@googlegroups.com>; ***@novidys.com<mailto:***@novidys.com>; rancid-***@shrubbery.net<mailto:rancid-***@shrubbery.net>

Subject: Re: [rancid] Palo Alto Networks

Hi All,

Thanks for your inputs.. much appreciated.

I think i had downloaded these files from some other website, not sure if you have modified it, Doug..

In my setup, I am able to login into the device using panlogin.. however the device config are not backed up. Everything works smooth for Cisco devices.
I have updated the routers.db and other files for PAN devices, but no luck yet.

Unfortunately, I am unable to reach my remote site server at the moment, else would have pasted the log file.

Regards,
Kishore


On 24 September 2013 22:01, Hughes, Doug <***@deshawresearch.com<mailto:***@deshawresearch.com>> wrote:
Sure they can. I do it for 3 of them right now.

Attached. Set your 'switch type' to paloalto. Works with names or IP addresses.

From: Ryan Milton [mailto:***@mvsusa.com<mailto:***@mvsusa.com>]
Sent: Tuesday, September 24, 2013 4:58 PM
To: Hughes, Doug; Kishore Rajani; rancid-***@googlegroups.com<mailto:rancid-***@googlegroups.com>
Cc: ***@novidys.com<mailto:***@novidys.com>; rancid-***@shrubbery.net<mailto:rancid-***@shrubbery.net>
Subject: RE: [rancid] Palo Alto Networks

I would certainly be interested in adding PAN devices to Rancid. I thought that they couldn't be read. That is what I've found with my HP switches-but that is another matter. Any ideas on getting PAN devices read by Rancid would be useful.

Regards,
Ryan Milton

From: rancid-discuss-***@shrubbery.net<mailto:rancid-discuss-***@shrubbery.net> [mailto:rancid-discuss-***@shrubbery.net] On Behalf Of Hughes, Doug
Sent: Tuesday, September 24, 2013 12:26 PM
To: Kishore Rajani; rancid-***@googlegroups.com<mailto:rancid-***@googlegroups.com>
Cc: ***@novidys.com<mailto:***@novidys.com>; rancid-***@shrubbery.net<mailto:rancid-***@shrubbery.net>
Subject: Re: [rancid] Palo Alto Networks

Yes, I have working panlogin and panrancid and have contributed them upstream. Have you not been able to get them to work?


From: rancid-discuss-***@shrubbery.net<mailto:rancid-discuss-***@shrubbery.net> [mailto:rancid-discuss-***@shrubbery.net] On Behalf Of Kishore Rajani
Sent: Monday, September 23, 2013 9:52 AM
To: rancid-***@googlegroups.com<mailto:rancid-***@googlegroups.com>
Cc: ***@novidys.com<mailto:***@novidys.com>; rancid-***@shrubbery.net<mailto:rancid-***@shrubbery.net>
Subject: Re: [rancid] Palo Alto Networks

HI,

did you manage to get the RANCID running with PAN?

Regards,
Kishore

On Thursday, 29 March 2012 13:53:33 UTC+1, Guillaume Dupuis wrote:
Nate Beck <Nate.Beck <at> jivesoftware.com<http://jivesoftware.com>> writes:

>
>
> Has anyone on the list worked with Palo Alto Network firewalls and Rancid? I
was wondering if anyone has created a *login for them.
> Thanks-------------------
> Nathan BeckSr. IT Engineer
> Jive Software
> 503.972.9024

Hi Nate,

Did you find a *login script for PAN?

Thanks,

Guillaume Dupuis
Hughes, Doug
2013-10-02 14:34:01 UTC
Permalink
That message is definitely coming from rancid-fe. It's just below the vendor table. Are you sure that you don't have 'another' version of rancid-fe somewhere else in the path? That's the only explanation that I could think of other than a misspelling. You could use strace -f -e trace=execve to find out exactly what it's running.


From: Kishore Rajani [mailto:***@gmail.com]
Sent: Wednesday, October 02, 2013 10:24 AM
To: Hughes, Doug
Cc: Ryan Milton; rancid-***@googlegroups.com; ***@novidys.com; rancid-***@shrubbery.net
Subject: Re: [rancid] Palo Alto Networks

Just checked, I do have that entry as well:

'netscaler' => 'nsrancid',
'netscreen' => 'nrancid',
'paloalto' => 'panrancid',
'procket' => 'prancid',
Do you think I have missed it anywhere else.. is there any modification needed in the rancid-run script? the cisco devices are being backed up without any problem..
Regards,
Kishore

On 2 October 2013 15:21, Hughes, Doug <***@deshawresearch.com<mailto:***@deshawresearch.com>> wrote:
I suspect you haven't added the mapping to your vendor table.
In rancid-fe, find the %vendortable hash (about 2/3 of the way down)

Add a line:
'paloalto' => 'panrancid',


I put mine in alphabetical order, just below netscreen.

From: Kishore Rajani [mailto:***@gmail.com<mailto:***@gmail.com>]
Sent: Wednesday, October 02, 2013 10:14 AM

To: Hughes, Doug
Cc: Ryan Milton; rancid-***@googlegroups.com<mailto:rancid-***@googlegroups.com>; ***@novidys.com<mailto:***@novidys.com>; rancid-***@shrubbery.net<mailto:rancid-***@shrubbery.net>
Subject: Re: [rancid] Palo Alto Networks

HI Doug,
Now that I have my remote site up, here are the logs that are generated by rancid-run:
exec failed router manufacturer paloalto: No such file or directory
exec failed router manufacturer paloalto: No such file or directory
exec failed router manufacturer paloalto: No such file or directory
exec failed router manufacturer paloalto: No such file or directory
exec failed router manufacturer paloalto: No such file or directory
exec failed router manufacturer paloalto: No such file or directory
exec failed router manufacturer paloalto: No such file or directory
exec failed router manufacturer paloalto: No such file or directory
Any idea where I could have been wrong. I have the panlogin and panrancid in the "/usr/local/rancid/bin/" directory. Also I have checked the router.db file and it has the config like:
FWL1:paloalto:up
FWL2:paloalto:up
FWL3:paloalto:up
FWL4:paloalto:up
FWL5:paloalto:up
Thanks and Regards,
Kishore

On 25 September 2013 06:48, Kishore Rajani <***@gmail.com<mailto:***@gmail.com>> wrote:
I will use them as soon as the remote site becomes available.. and will also let you know how did it go.

Appreciate your help.

Regards,
Kishore

On 25 September 2013 01:40, Hughes, Doug <***@deshawresearch.com<mailto:***@deshawresearch.com>> wrote:
I just sent you the latest versions. I'm the original creator. I can't say if the other version is older, but if they are different, use the ones I sent. (and make sure they are first in the path)

So you are saying when you run panrancid it doesn't create the config file for you?

From: Kishore Rajani [mailto:***@gmail.com<mailto:***@gmail.com>]
Sent: Tuesday, September 24, 2013 5:44 PM
To: Hughes, Doug
Cc: Ryan Milton; rancid-***@googlegroups.com<mailto:rancid-***@googlegroups.com>; ***@novidys.com<mailto:***@novidys.com>; rancid-***@shrubbery.net<mailto:rancid-***@shrubbery.net>

Subject: Re: [rancid] Palo Alto Networks

Hi All,

Thanks for your inputs.. much appreciated.

I think i had downloaded these files from some other website, not sure if you have modified it, Doug..

In my setup, I am able to login into the device using panlogin.. however the device config are not backed up. Everything works smooth for Cisco devices.
I have updated the routers.db and other files for PAN devices, but no luck yet.

Unfortunately, I am unable to reach my remote site server at the moment, else would have pasted the log file.

Regards,
Kishore


On 24 September 2013 22:01, Hughes, Doug <***@deshawresearch.com<mailto:***@deshawresearch.com>> wrote:
Sure they can. I do it for 3 of them right now.

Attached. Set your 'switch type' to paloalto. Works with names or IP addresses.

From: Ryan Milton [mailto:***@mvsusa.com<mailto:***@mvsusa.com>]
Sent: Tuesday, September 24, 2013 4:58 PM
To: Hughes, Doug; Kishore Rajani; rancid-***@googlegroups.com<mailto:rancid-***@googlegroups.com>
Cc: ***@novidys.com<mailto:***@novidys.com>; rancid-***@shrubbery.net<mailto:rancid-***@shrubbery.net>
Subject: RE: [rancid] Palo Alto Networks

I would certainly be interested in adding PAN devices to Rancid. I thought that they couldn't be read. That is what I've found with my HP switches-but that is another matter. Any ideas on getting PAN devices read by Rancid would be useful.

Regards,
Ryan Milton

From: rancid-discuss-***@shrubbery.net<mailto:rancid-discuss-***@shrubbery.net> [mailto:rancid-discuss-***@shrubbery.net] On Behalf Of Hughes, Doug
Sent: Tuesday, September 24, 2013 12:26 PM
To: Kishore Rajani; rancid-***@googlegroups.com<mailto:rancid-***@googlegroups.com>
Cc: ***@novidys.com<mailto:***@novidys.com>; rancid-***@shrubbery.net<mailto:rancid-***@shrubbery.net>
Subject: Re: [rancid] Palo Alto Networks

Yes, I have working panlogin and panrancid and have contributed them upstream. Have you not been able to get them to work?


From: rancid-discuss-***@shrubbery.net<mailto:rancid-discuss-***@shrubbery.net> [mailto:rancid-discuss-***@shrubbery.net] On Behalf Of Kishore Rajani
Sent: Monday, September 23, 2013 9:52 AM
To: rancid-***@googlegroups.com<mailto:rancid-***@googlegroups.com>
Cc: ***@novidys.com<mailto:***@novidys.com>; rancid-***@shrubbery.net<mailto:rancid-***@shrubbery.net>
Subject: Re: [rancid] Palo Alto Networks

HI,

did you manage to get the RANCID running with PAN?

Regards,
Kishore

On Thursday, 29 March 2012 13:53:33 UTC+1, Guillaume Dupuis wrote:
Nate Beck <Nate.Beck <at> jivesoftware.com<http://jivesoftware.com>> writes:

>
>
> Has anyone on the list worked with Palo Alto Network firewalls and Rancid? I
was wondering if anyone has created a *login for them.
> Thanks-------------------
> Nathan BeckSr. IT Engineer
> Jive Software
> 503.972.9024

Hi Nate,

Did you find a *login script for PAN?

Thanks,

Guillaume Dupuis
Kishore Rajani
2013-10-02 14:54:15 UTC
Permalink
Hi Doug,

Finally got it working !!!! great thanks :)
I removed all the files and config related to PAN and applied everything
again and volla it started working :)

Regards,
Kishore


On 2 October 2013 15:34, Hughes, Doug <***@deshawresearch.com>wrote:

> That message is definitely coming from rancid-fe. It’s just below the
> vendor table. Are you sure that you don’t have ‘another’ version of
> rancid-fe somewhere else in the path? That’s the only explanation that I
> could think of other than a misspelling. You could use strace –f –e
> trace=execve to find out exactly what it’s running.****
>
> ** **
>
> ** **
>
> *From:* Kishore Rajani [mailto:***@gmail.com]
> *Sent:* Wednesday, October 02, 2013 10:24 AM
>
> *To:* Hughes, Doug
> *Cc:* Ryan Milton; rancid-***@googlegroups.com;
> ***@novidys.com; rancid-***@shrubbery.net
> *Subject:* Re: [rancid] Palo Alto Networks****
>
> ** **
>
> Just checked, I do have that entry as well:
>
> 'netscaler' => 'nsrancid',
> 'netscreen' => 'nrancid',
> * 'paloalto' => 'panrancid',*
> 'procket' => 'prancid',****
>
> Do you think I have missed it anywhere else.. is there any modification
> needed in the rancid-run script? the cisco devices are being backed up
> without any problem..****
>
> Regards,
> Kishore****
>
> ** **
>
> On 2 October 2013 15:21, Hughes, Doug <***@deshawresearch.com>
> wrote:****
>
> I suspect you haven’t added the mapping to your vendor table.****
>
> In rancid-fe, find the %vendortable hash (about 2/3 of the way down)****
>
> ****
>
> Add a line:****
>
> 'paloalto' => 'panrancid',****
>
> ****
>
> ****
>
> I put mine in alphabetical order, just below netscreen.****
>
> ****
>
> *From:* Kishore Rajani [mailto:***@gmail.com]
> *Sent:* Wednesday, October 02, 2013 10:14 AM****
>
>
> *To:* Hughes, Doug
> *Cc:* Ryan Milton; rancid-***@googlegroups.com;
> ***@novidys.com; rancid-***@shrubbery.net
> *Subject:* Re: [rancid] Palo Alto Networks****
>
> ****
>
> HI Doug,****
>
> Now that I have my remote site up, here are the logs that are generated by
> rancid-run:
> exec failed router manufacturer paloalto: No such file or directory
> exec failed router manufacturer paloalto: No such file or directory
> exec failed router manufacturer paloalto: No such file or directory
> exec failed router manufacturer paloalto: No such file or directory
> exec failed router manufacturer paloalto: No such file or directory
> exec failed router manufacturer paloalto: No such file or directory
> exec failed router manufacturer paloalto: No such file or directory
> exec failed router manufacturer paloalto: No such file or directory****
>
> Any idea where I could have been wrong. I have the panlogin and panrancid
> in the "/usr/local/rancid/bin/" directory. Also I have checked the
> router.db file and it has the config like:
> FWL1:paloalto:up****
>
> FWL2:paloalto:up
> FWL3:paloalto:up
> FWL4:paloalto:up
> FWL5:paloalto:up****
>
> Thanks and Regards,
> Kishore****
>
> ****
>
> On 25 September 2013 06:48, Kishore Rajani <***@gmail.com> wrote:****
>
> I will use them as soon as the remote site becomes available.. and will
> also let you know how did it go.****
>
> ****
>
> Appreciate your help.****
>
> ****
>
> Regards,****
>
> Kishore****
>
> ****
>
> On 25 September 2013 01:40, Hughes, Doug <
> ***@deshawresearch.com> wrote:****
>
> I just sent you the latest versions. I’m the original creator. I can’t say
> if the other version is older, but if they are different, use the ones I
> sent. (and make sure they are first in the path)****
>
> ****
>
> So you are saying when you run panrancid it doesn’t create the config file
> for you?****
>
> ****
>
> *From:* Kishore Rajani [mailto:***@gmail.com]
> *Sent:* Tuesday, September 24, 2013 5:44 PM
> *To:* Hughes, Doug
> *Cc:* Ryan Milton; rancid-***@googlegroups.com;
> ***@novidys.com; rancid-***@shrubbery.net****
>
>
> *Subject:* Re: [rancid] Palo Alto Networks****
>
> ****
>
> Hi All,****
>
> ****
>
> Thanks for your inputs.. much appreciated.****
>
> ****
>
> I think i had downloaded these files from some other website, not sure if
> you have modified it, Doug..****
>
> ****
>
> In my setup, I am able to login into the device using panlogin.. however
> the device config are not backed up. Everything works smooth for Cisco
> devices.****
>
> I have updated the routers.db and other files for PAN devices, but no luck
> yet.****
>
> ****
>
> Unfortunately, I am unable to reach my remote site server at the moment,
> else would have pasted the log file.****
>
> ****
>
> Regards,****
>
> Kishore****
>
> ****
>
> ****
>
> On 24 September 2013 22:01, Hughes, Doug <
> ***@deshawresearch.com> wrote:****
>
> Sure they can. I do it for 3 of them right now.****
>
> ****
>
> Attached. Set your ‘switch type’ to paloalto. Works with names or IP
> addresses.****
>
> ****
>
> *From:* Ryan Milton [mailto:***@mvsusa.com]
> *Sent:* Tuesday, September 24, 2013 4:58 PM
> *To:* Hughes, Doug; Kishore Rajani; rancid-***@googlegroups.com
> *Cc:* ***@novidys.com; rancid-***@shrubbery.net
> *Subject:* RE: [rancid] Palo Alto Networks****
>
> ****
>
> I would certainly be interested in adding PAN devices to Rancid. I thought
> that they couldn’t be read. That is what I’ve found with my HP switches—but
> that is another matter. Any ideas on getting PAN devices read by Rancid
> would be useful.****
>
> ****
>
> Regards,****
>
> Ryan Milton****
>
> ****
>
> *From:* rancid-discuss-***@shrubbery.net [
> mailto:rancid-discuss-***@shrubbery.net<rancid-discuss-***@shrubbery.net>]
> *On Behalf Of *Hughes, Doug
> *Sent:* Tuesday, September 24, 2013 12:26 PM
> *To:* Kishore Rajani; rancid-***@googlegroups.com
> *Cc:* ***@novidys.com; rancid-***@shrubbery.net
> *Subject:* Re: [rancid] Palo Alto Networks****
>
> ****
>
> Yes, I have working panlogin and panrancid and have contributed them
> upstream. Have you not been able to get them to work?****
>
> ****
>
> ****
>
> *From:* rancid-discuss-***@shrubbery.net [
> mailto:rancid-discuss-***@shrubbery.net<rancid-discuss-***@shrubbery.net>]
> *On Behalf Of *Kishore Rajani
> *Sent:* Monday, September 23, 2013 9:52 AM
> *To:* rancid-***@googlegroups.com
> *Cc:* ***@novidys.com; rancid-***@shrubbery.net
> *Subject:* Re: [rancid] Palo Alto Networks****
>
> ****
>
> HI,
>
> did you manage to get the RANCID running with PAN?
>
> Regards,
> Kishore
>
> On Thursday, 29 March 2012 13:53:33 UTC+1, Guillaume Dupuis wrote:****
>
> Nate Beck <Nate.Beck <at> jivesoftware.com> writes:****
>
> >
> >
> > Has anyone on the list worked with Palo Alto Network firewalls and
> Rancid? I
> was wondering if anyone has created a *login for them.
> > Thanks-------------------
> > Nathan BeckSr. IT Engineer
> > Jive Software
> > 503.972.9024****
>
> Hi Nate,****
>
> Did you find a *login script for PAN?****
>
> Thanks,****
>
> Guillaume Dupuis****
>
> _______________________________________________
> Rancid-discuss mailing list
> Rancid-***@shrubbery.net
> http://www.shrubbery.net/mailman/listinfo.cgi/rancid-discuss****
>
> ****
>
> ****
>
> ****
>
> ** **
>
Alan McKinnon
2013-10-02 16:19:59 UTC
Permalink
Most likely cause is that you edited rancid-fe in one terminal, then ran
rancid-run in another without saving rancid-fe first.

It's a *very* easy mistake to make and very hard to find later you did
it. Numerous varieties exist too - my favourite is Ctrl-Z to go to the
terminal, do something, fg to go back to the editor, then realize i
didn't save before Ctrl-Z





On 02/10/2013 16:54, Kishore Rajani wrote:
> Hi Doug,
>
> Finally got it working !!!! great thanks :)
> I removed all the files and config related to PAN and applied everything
> again and volla it started working :)
>
> Regards,
> Kishore
>
>
> On 2 October 2013 15:34, Hughes, Doug <***@deshawresearch.com
> <mailto:***@deshawresearch.com>> wrote:
>
> That message is definitely coming from rancid-fe. It’s just below
> the vendor table. Are you sure that you don’t have ‘another’ version
> of rancid-fe somewhere else in the path? That’s the only explanation
> that I could think of other than a misspelling. You could use strace
> –f –e trace=execve to find out exactly what it’s running.____
>
> __ __
>
> __ __
>
> *From:*Kishore Rajani [mailto:***@gmail.com
> <mailto:***@gmail.com>]
> *Sent:* Wednesday, October 02, 2013 10:24 AM
>
>
> *To:* Hughes, Doug
> *Cc:* Ryan Milton; rancid-***@googlegroups.com
> <mailto:rancid-***@googlegroups.com>;
> ***@novidys.com <mailto:***@novidys.com>;
> rancid-***@shrubbery.net <mailto:rancid-***@shrubbery.net>
> *Subject:* Re: [rancid] Palo Alto Networks____
>
> __ __
>
> Just checked, I do have that entry as well:
>
> 'netscaler' => 'nsrancid',
> 'netscreen' => 'nrancid',
> * 'paloalto' => 'panrancid',*
> 'procket' => 'prancid',____
>
> Do you think I have missed it anywhere else.. is there any
> modification needed in the rancid-run script? the cisco devices are
> being backed up without any problem..____
>
> Regards,
> Kishore____
>
> __ __
>
> On 2 October 2013 15:21, Hughes, Doug
> <***@deshawresearch.com
> <mailto:***@deshawresearch.com>> wrote:____
>
> I suspect you haven’t added the mapping to your vendor table.____
>
> In rancid-fe, find the %vendortable hash (about 2/3 of the way down)____
>
> ____
>
> Add a line:____
>
> 'paloalto' => 'panrancid',____
>
> ____
>
> ____
>
> I put mine in alphabetical order, just below netscreen.____
>
> ____
>
> *From:*Kishore Rajani [mailto:***@gmail.com
> <mailto:***@gmail.com>]
> *Sent:* Wednesday, October 02, 2013 10:14 AM____
>
>
> *To:* Hughes, Doug
> *Cc:* Ryan Milton; rancid-***@googlegroups.com
> <mailto:rancid-***@googlegroups.com>;
> ***@novidys.com <mailto:***@novidys.com>;
> rancid-***@shrubbery.net <mailto:rancid-***@shrubbery.net>
> *Subject:* Re: [rancid] Palo Alto Networks____
>
> ____
>
> HI Doug,____
>
> Now that I have my remote site up, here are the logs that are
> generated by rancid-run:
> exec failed router manufacturer paloalto: No such file or directory
> exec failed router manufacturer paloalto: No such file or directory
> exec failed router manufacturer paloalto: No such file or directory
> exec failed router manufacturer paloalto: No such file or directory
> exec failed router manufacturer paloalto: No such file or directory
> exec failed router manufacturer paloalto: No such file or directory
> exec failed router manufacturer paloalto: No such file or directory
> exec failed router manufacturer paloalto: No such file or directory____
>
> Any idea where I could have been wrong. I have the panlogin and
> panrancid in the "/usr/local/rancid/bin/" directory. Also I have
> checked the router.db file and it has the config like:
> FWL1:paloalto:up____
>
> FWL2:paloalto:up
> FWL3:paloalto:up
> FWL4:paloalto:up
> FWL5:paloalto:up____
>
> Thanks and Regards,
> Kishore____
>
> ____
>
> On 25 September 2013 06:48, Kishore Rajani <***@gmail.com
> <mailto:***@gmail.com>> wrote:____
>
> I will use them as soon as the remote site becomes available.. and
> will also let you know how did it go.____
>
> ____
>
> Appreciate your help.____
>
> ____
>
> Regards,____
>
> Kishore____
>
> ____
>
> On 25 September 2013 01:40, Hughes, Doug
> <***@deshawresearch.com
> <mailto:***@deshawresearch.com>> wrote:____
>
> I just sent you the latest versions. I’m the original creator. I
> can’t say if the other version is older, but if they are different,
> use the ones I sent. (and make sure they are first in the path)____
>
> ____
>
> So you are saying when you run panrancid it doesn’t create the
> config file for you?____
>
> ____
>
> *From:*Kishore Rajani [mailto:***@gmail.com
> <mailto:***@gmail.com>]
> *Sent:* Tuesday, September 24, 2013 5:44 PM
> *To:* Hughes, Doug
> *Cc:* Ryan Milton; rancid-***@googlegroups.com
> <mailto:rancid-***@googlegroups.com>;
> ***@novidys.com <mailto:***@novidys.com>;
> rancid-***@shrubbery.net <mailto:rancid-***@shrubbery.net>____
>
>
> *Subject:* Re: [rancid] Palo Alto Networks____
>
> ____
>
> Hi All,____
>
> ____
>
> Thanks for your inputs.. much appreciated.____
>
> ____
>
> I think i had downloaded these files from some other website, not
> sure if you have modified it, Doug..____
>
> ____
>
> In my setup, I am able to login into the device using panlogin..
> however the device config are not backed up. Everything works smooth
> for Cisco devices.____
>
> I have updated the routers.db and other files for PAN devices, but
> no luck yet.____
>
> ____
>
> Unfortunately, I am unable to reach my remote site server at the
> moment, else would have pasted the log file.____
>
> ____
>
> Regards,____
>
> Kishore____
>
> ____
>
> ____
>
> On 24 September 2013 22:01, Hughes, Doug
> <***@deshawresearch.com
> <mailto:***@deshawresearch.com>> wrote:____
>
> Sure they can. I do it for 3 of them right now.____
>
> ____
>
> Attached. Set your ‘switch type’ to paloalto. Works with names or IP
> addresses.____
>
> ____
>
> *From:*Ryan Milton [mailto:***@mvsusa.com
> <mailto:***@mvsusa.com>]
> *Sent:* Tuesday, September 24, 2013 4:58 PM
> *To:* Hughes, Doug; Kishore Rajani; rancid-***@googlegroups.com
> <mailto:rancid-***@googlegroups.com>
> *Cc:* ***@novidys.com
> <mailto:***@novidys.com>; rancid-***@shrubbery.net
> <mailto:rancid-***@shrubbery.net>
> *Subject:* RE: [rancid] Palo Alto Networks____
>
> ____
>
> I would certainly be interested in adding PAN devices to Rancid. I
> thought that they couldn’t be read. That is what I’ve found with my
> HP switches—but that is another matter. Any ideas on getting PAN
> devices read by Rancid would be useful.____
>
> ____
>
> Regards,____
>
> Ryan Milton____
>
> ____
>
> *From:*rancid-discuss-***@shrubbery.net
> <mailto:rancid-discuss-***@shrubbery.net>
> [mailto:rancid-discuss-***@shrubbery.net] *On Behalf Of *Hughes,
> Doug
> *Sent:* Tuesday, September 24, 2013 12:26 PM
> *To:* Kishore Rajani; rancid-***@googlegroups.com
> <mailto:rancid-***@googlegroups.com>
> *Cc:* ***@novidys.com
> <mailto:***@novidys.com>; rancid-***@shrubbery.net
> <mailto:rancid-***@shrubbery.net>
> *Subject:* Re: [rancid] Palo Alto Networks____
>
> ____
>
> Yes, I have working panlogin and panrancid and have contributed them
> upstream. Have you not been able to get them to work?____
>
> ____
>
> ____
>
> *From:*rancid-discuss-***@shrubbery.net
> <mailto:rancid-discuss-***@shrubbery.net>
> [mailto:rancid-discuss-***@shrubbery.net] *On Behalf Of *Kishore
> Rajani
> *Sent:* Monday, September 23, 2013 9:52 AM
> *To:* rancid-***@googlegroups.com
> <mailto:rancid-***@googlegroups.com>
> *Cc:* ***@novidys.com
> <mailto:***@novidys.com>; rancid-***@shrubbery.net
> <mailto:rancid-***@shrubbery.net>
> *Subject:* Re: [rancid] Palo Alto Networks____
>
> ____
>
> HI,
>
> did you manage to get the RANCID running with PAN?
>
> Regards,
> Kishore
>
> On Thursday, 29 March 2012 13:53:33 UTC+1, Guillaume Dupuis wrote:____
>
> Nate Beck <Nate.Beck <at> jivesoftware.com
> <http://jivesoftware.com>> writes:____
>
> >
> >
> > Has anyone on the list worked with Palo Alto Network firewalls and Rancid? I
> was wondering if anyone has created a *login for them.
> > Thanks-------------------
> > Nathan BeckSr. IT Engineer
> > Jive Software
> > 503.972.9024____
>
> Hi Nate,____
>
> Did you find a *login script for PAN?____
>
> Thanks,____
>
> Guillaume Dupuis____
>
> _______________________________________________
> Rancid-discuss mailing list
> Rancid-***@shrubbery.net <mailto:Rancid-***@shrubbery.net>
> http://www.shrubbery.net/mailman/listinfo.cgi/rancid-discuss____
>
> ____
>
> ____
>
> ____
>
> __ __
>
>
>
>
> _______________________________________________
> Rancid-discuss mailing list
> Rancid-***@shrubbery.net
> http://www.shrubbery.net/mailman/listinfo/rancid-discuss
>


--
Alan McKinnon
***@gmail.com
Kishore Rajani
2013-10-02 14:23:40 UTC
Permalink
Just checked, I do have that entry as well:

'netscaler' => 'nsrancid',
'netscreen' => 'nrancid',
* 'paloalto' => 'panrancid',*
'procket' => 'prancid',

Do you think I have missed it anywhere else.. is there any modification
needed in the rancid-run script? the cisco devices are being backed up
without any problem..

Regards,
Kishore


On 2 October 2013 15:21, Hughes, Doug <***@deshawresearch.com>wrote:

> I suspect you haven’t added the mapping to your vendor table.****
>
> In rancid-fe, find the %vendortable hash (about 2/3 of the way down)****
>
> ** **
>
> Add a line:****
>
> 'paloalto' => 'panrancid',****
>
> ** **
>
> ** **
>
> I put mine in alphabetical order, just below netscreen.****
>
> ** **
>
> *From:* Kishore Rajani [mailto:***@gmail.com]
> *Sent:* Wednesday, October 02, 2013 10:14 AM
>
> *To:* Hughes, Doug
> *Cc:* Ryan Milton; rancid-***@googlegroups.com;
> ***@novidys.com; rancid-***@shrubbery.net
> *Subject:* Re: [rancid] Palo Alto Networks****
>
> ** **
>
> HI Doug,****
>
> Now that I have my remote site up, here are the logs that are generated by
> rancid-run:
> exec failed router manufacturer paloalto: No such file or directory
> exec failed router manufacturer paloalto: No such file or directory
> exec failed router manufacturer paloalto: No such file or directory
> exec failed router manufacturer paloalto: No such file or directory
> exec failed router manufacturer paloalto: No such file or directory
> exec failed router manufacturer paloalto: No such file or directory
> exec failed router manufacturer paloalto: No such file or directory
> exec failed router manufacturer paloalto: No such file or directory****
>
> Any idea where I could have been wrong. I have the panlogin and panrancid
> in the "/usr/local/rancid/bin/" directory. Also I have checked the
> router.db file and it has the config like:
> FWL1:paloalto:up****
>
> FWL2:paloalto:up
> FWL3:paloalto:up
> FWL4:paloalto:up
> FWL5:paloalto:up****
>
> Thanks and Regards,
> Kishore****
>
> ** **
>
> On 25 September 2013 06:48, Kishore Rajani <***@gmail.com> wrote:****
>
> I will use them as soon as the remote site becomes available.. and will
> also let you know how did it go.****
>
> ** **
>
> Appreciate your help.****
>
> ** **
>
> Regards,****
>
> Kishore****
>
> ** **
>
> On 25 September 2013 01:40, Hughes, Doug <
> ***@deshawresearch.com> wrote:****
>
> I just sent you the latest versions. I’m the original creator. I can’t say
> if the other version is older, but if they are different, use the ones I
> sent. (and make sure they are first in the path)****
>
> ****
>
> So you are saying when you run panrancid it doesn’t create the config file
> for you?****
>
> ****
>
> *From:* Kishore Rajani [mailto:***@gmail.com]
> *Sent:* Tuesday, September 24, 2013 5:44 PM
> *To:* Hughes, Doug
> *Cc:* Ryan Milton; rancid-***@googlegroups.com;
> ***@novidys.com; rancid-***@shrubbery.net****
>
>
> *Subject:* Re: [rancid] Palo Alto Networks****
>
> ****
>
> Hi All,****
>
> ****
>
> Thanks for your inputs.. much appreciated.****
>
> ****
>
> I think i had downloaded these files from some other website, not sure if
> you have modified it, Doug..****
>
> ****
>
> In my setup, I am able to login into the device using panlogin.. however
> the device config are not backed up. Everything works smooth for Cisco
> devices.****
>
> I have updated the routers.db and other files for PAN devices, but no luck
> yet.****
>
> ****
>
> Unfortunately, I am unable to reach my remote site server at the moment,
> else would have pasted the log file.****
>
> ****
>
> Regards,****
>
> Kishore****
>
> ****
>
> ****
>
> On 24 September 2013 22:01, Hughes, Doug <
> ***@deshawresearch.com> wrote:****
>
> Sure they can. I do it for 3 of them right now.****
>
> ****
>
> Attached. Set your ‘switch type’ to paloalto. Works with names or IP
> addresses.****
>
> ****
>
> *From:* Ryan Milton [mailto:***@mvsusa.com]
> *Sent:* Tuesday, September 24, 2013 4:58 PM
> *To:* Hughes, Doug; Kishore Rajani; rancid-***@googlegroups.com
> *Cc:* ***@novidys.com; rancid-***@shrubbery.net
> *Subject:* RE: [rancid] Palo Alto Networks****
>
> ****
>
> I would certainly be interested in adding PAN devices to Rancid. I thought
> that they couldn’t be read. That is what I’ve found with my HP switches—but
> that is another matter. Any ideas on getting PAN devices read by Rancid
> would be useful.****
>
> ****
>
> Regards,****
>
> Ryan Milton****
>
> ****
>
> *From:* rancid-discuss-***@shrubbery.net [
> mailto:rancid-discuss-***@shrubbery.net<rancid-discuss-***@shrubbery.net>]
> *On Behalf Of *Hughes, Doug
> *Sent:* Tuesday, September 24, 2013 12:26 PM
> *To:* Kishore Rajani; rancid-***@googlegroups.com
> *Cc:* ***@novidys.com; rancid-***@shrubbery.net
> *Subject:* Re: [rancid] Palo Alto Networks****
>
> ****
>
> Yes, I have working panlogin and panrancid and have contributed them
> upstream. Have you not been able to get them to work?****
>
> ****
>
> ****
>
> *From:* rancid-discuss-***@shrubbery.net [
> mailto:rancid-discuss-***@shrubbery.net<rancid-discuss-***@shrubbery.net>]
> *On Behalf Of *Kishore Rajani
> *Sent:* Monday, September 23, 2013 9:52 AM
> *To:* rancid-***@googlegroups.com
> *Cc:* ***@novidys.com; rancid-***@shrubbery.net
> *Subject:* Re: [rancid] Palo Alto Networks****
>
> ****
>
> HI,
>
> did you manage to get the RANCID running with PAN?
>
> Regards,
> Kishore
>
> On Thursday, 29 March 2012 13:53:33 UTC+1, Guillaume Dupuis wrote:****
>
> Nate Beck <Nate.Beck <at> jivesoftware.com> writes:****
>
> >
> >
> > Has anyone on the list worked with Palo Alto Network firewalls and
> Rancid? I
> was wondering if anyone has created a *login for them.
> > Thanks-------------------
> > Nathan BeckSr. IT Engineer
> > Jive Software
> > 503.972.9024****
>
> Hi Nate,****
>
> Did you find a *login script for PAN?****
>
> Thanks,****
>
> Guillaume Dupuis****
>
> _______________________________________________
> Rancid-discuss mailing list
> Rancid-***@shrubbery.net
> http://www.shrubbery.net/mailman/listinfo.cgi/rancid-discuss****
>
> ****
>
> ** **
>
> ** **
>
Kishore Rajani
2013-10-02 14:13:51 UTC
Permalink
HI Doug,

Now that I have my remote site up, here are the logs that are generated by
rancid-run:
exec failed router manufacturer paloalto: No such file or directory
exec failed router manufacturer paloalto: No such file or directory
exec failed router manufacturer paloalto: No such file or directory
exec failed router manufacturer paloalto: No such file or directory
exec failed router manufacturer paloalto: No such file or directory
exec failed router manufacturer paloalto: No such file or directory
exec failed router manufacturer paloalto: No such file or directory
exec failed router manufacturer paloalto: No such file or directory

Any idea where I could have been wrong. I have the panlogin and panrancid
in the "/usr/local/rancid/bin/" directory. Also I have checked the
router.db file and it has the config like:
FWL1:paloalto:up
FWL2:paloalto:up
FWL3:paloalto:up
FWL4:paloalto:up
FWL5:paloalto:up

Thanks and Regards,
Kishore


On 25 September 2013 06:48, Kishore Rajani <***@gmail.com> wrote:

> I will use them as soon as the remote site becomes available.. and will
> also let you know how did it go.
>
> Appreciate your help.
>
> Regards,
> Kishore
>
>
> On 25 September 2013 01:40, Hughes, Doug <
> ***@deshawresearch.com> wrote:
>
>> I just sent you the latest versions. I’m the original creator. I can’t
>> say if the other version is older, but if they are different, use the ones
>> I sent. (and make sure they are first in the path)****
>>
>> ** **
>>
>> So you are saying when you run panrancid it doesn’t create the config
>> file for you?****
>>
>> ** **
>>
>> *From:* Kishore Rajani [mailto:***@gmail.com]
>> *Sent:* Tuesday, September 24, 2013 5:44 PM
>> *To:* Hughes, Doug
>> *Cc:* Ryan Milton; rancid-***@googlegroups.com;
>> ***@novidys.com; rancid-***@shrubbery.net
>>
>> *Subject:* Re: [rancid] Palo Alto Networks****
>>
>> ** **
>>
>> Hi All,****
>>
>> ** **
>>
>> Thanks for your inputs.. much appreciated.****
>>
>> ** **
>>
>> I think i had downloaded these files from some other website, not sure if
>> you have modified it, Doug..****
>>
>> ** **
>>
>> In my setup, I am able to login into the device using panlogin.. however
>> the device config are not backed up. Everything works smooth for Cisco
>> devices.****
>>
>> I have updated the routers.db and other files for PAN devices, but no
>> luck yet.****
>>
>> ** **
>>
>> Unfortunately, I am unable to reach my remote site server at the moment,
>> else would have pasted the log file.****
>>
>> ** **
>>
>> Regards,****
>>
>> Kishore****
>>
>> ** **
>>
>> ** **
>>
>> On 24 September 2013 22:01, Hughes, Doug <
>> ***@deshawresearch.com> wrote:****
>>
>> Sure they can. I do it for 3 of them right now.****
>>
>> ****
>>
>> Attached. Set your ‘switch type’ to paloalto. Works with names or IP
>> addresses.****
>>
>> ****
>>
>> *From:* Ryan Milton [mailto:***@mvsusa.com]
>> *Sent:* Tuesday, September 24, 2013 4:58 PM
>> *To:* Hughes, Doug; Kishore Rajani; rancid-***@googlegroups.com
>> *Cc:* ***@novidys.com; rancid-***@shrubbery.net
>> *Subject:* RE: [rancid] Palo Alto Networks****
>>
>> ****
>>
>> I would certainly be interested in adding PAN devices to Rancid. I
>> thought that they couldn’t be read. That is what I’ve found with my HP
>> switches—but that is another matter. Any ideas on getting PAN devices read
>> by Rancid would be useful.****
>>
>> ****
>>
>> Regards,****
>>
>> Ryan Milton****
>>
>> ****
>>
>> *From:* rancid-discuss-***@shrubbery.net [
>> mailto:rancid-discuss-***@shrubbery.net<rancid-discuss-***@shrubbery.net>]
>> *On Behalf Of *Hughes, Doug
>> *Sent:* Tuesday, September 24, 2013 12:26 PM
>> *To:* Kishore Rajani; rancid-***@googlegroups.com
>> *Cc:* ***@novidys.com; rancid-***@shrubbery.net
>> *Subject:* Re: [rancid] Palo Alto Networks****
>>
>> ****
>>
>> Yes, I have working panlogin and panrancid and have contributed them
>> upstream. Have you not been able to get them to work?****
>>
>> ****
>>
>> ****
>>
>> *From:* rancid-discuss-***@shrubbery.net [
>> mailto:rancid-discuss-***@shrubbery.net<rancid-discuss-***@shrubbery.net>]
>> *On Behalf Of *Kishore Rajani
>> *Sent:* Monday, September 23, 2013 9:52 AM
>> *To:* rancid-***@googlegroups.com
>> *Cc:* ***@novidys.com; rancid-***@shrubbery.net
>> *Subject:* Re: [rancid] Palo Alto Networks****
>>
>> ****
>>
>> HI,
>>
>> did you manage to get the RANCID running with PAN?
>>
>> Regards,
>> Kishore
>>
>> On Thursday, 29 March 2012 13:53:33 UTC+1, Guillaume Dupuis wrote:****
>>
>> Nate Beck <Nate.Beck <at> jivesoftware.com> writes:****
>>
>> >
>> >
>> > Has anyone on the list worked with Palo Alto Network firewalls and
>> Rancid? I
>> was wondering if anyone has created a *login for them.
>> > Thanks-------------------
>> > Nathan BeckSr. IT Engineer
>> > Jive Software
>> > 503.972.9024****
>>
>> Hi Nate,****
>>
>> Did you find a *login script for PAN?****
>>
>> Thanks,****
>>
>> Guillaume Dupuis****
>>
>> _______________________________________________
>> Rancid-discuss mailing list
>> Rancid-***@shrubbery.net
>> http://www.shrubbery.net/mailman/listinfo.cgi/rancid-discuss****
>>
>> ** **
>>
>
>
Hughes, Doug
2013-09-25 12:58:47 UTC
Permalink
First off, in the .cloginrc define the login type as ssh You can use wildcards that match the hostname, so if you name your devices something like paloalto1, paloalto2, etc. it would be something like this to define ssh as the mechanism, admin as the user and FooBar as the password

add method paloalto* ssh
add user paloalto* admin
add password paloalto* FooBar

then in the router.db file that defines all of the switches/routers for that subdomain (assuming you have subdomains, otherwise your main router.db)

paloalto1:paloalto:up
paloalto2:paloalto:up



From: Ryan Milton [mailto:***@mvsusa.com]
Sent: Wednesday, September 25, 2013 8:53 AM
To: Hughes, Doug; Kishore Rajani; rancid-***@googlegroups.com
Cc: ***@novidys.com; rancid-***@shrubbery.net
Subject: RE: [rancid] Palo Alto Networks

Wow! This is great. I am still quite a noob at Rancid. When you say “switch type,” what do you mean by that? That is not in these files, is it?

Regards,
Ryan Milton
MVS Network Manager
o: 201-447-1505 x124
c: 862-249-5230
www.mvsusa.com<http://www.mvsusa.com/>
[MVS final logo GOOD very small]

From: Hughes, Doug [mailto:***@DEShawResearch.com]
Sent: Tuesday, September 24, 2013 5:02 PM
To: Ryan Milton; Kishore Rajani; rancid-***@googlegroups.com<mailto:rancid-***@googlegroups.com>
Cc: ***@novidys.com<mailto:***@novidys.com>; rancid-***@shrubbery.net<mailto:rancid-***@shrubbery.net>
Subject: RE: [rancid] Palo Alto Networks

Sure they can. I do it for 3 of them right now.

Attached. Set your ‘switch type’ to paloalto. Works with names or IP addresses.

From: Ryan Milton [mailto:***@mvsusa.com]
Sent: Tuesday, September 24, 2013 4:58 PM
To: Hughes, Doug; Kishore Rajani; rancid-***@googlegroups.com<mailto:rancid-***@googlegroups.com>
Cc: ***@novidys.com<mailto:***@novidys.com>; rancid-***@shrubbery.net<mailto:rancid-***@shrubbery.net>
Subject: RE: [rancid] Palo Alto Networks

I would certainly be interested in adding PAN devices to Rancid. I thought that they couldn’t be read. That is what I’ve found with my HP switches—but that is another matter. Any ideas on getting PAN devices read by Rancid would be useful.

Regards,
Ryan Milton

From: rancid-discuss-***@shrubbery.net<mailto:rancid-discuss-***@shrubbery.net> [mailto:rancid-discuss-***@shrubbery.net] On Behalf Of Hughes, Doug
Sent: Tuesday, September 24, 2013 12:26 PM
To: Kishore Rajani; rancid-***@googlegroups.com<mailto:rancid-***@googlegroups.com>
Cc: ***@novidys.com<mailto:***@novidys.com>; rancid-***@shrubbery.net<mailto:rancid-***@shrubbery.net>
Subject: Re: [rancid] Palo Alto Networks

Yes, I have working panlogin and panrancid and have contributed them upstream. Have you not been able to get them to work?


From: rancid-discuss-***@shrubbery.net<mailto:rancid-discuss-***@shrubbery.net> [mailto:rancid-discuss-***@shrubbery.net] On Behalf Of Kishore Rajani
Sent: Monday, September 23, 2013 9:52 AM
To: rancid-***@googlegroups.com<mailto:rancid-***@googlegroups.com>
Cc: ***@novidys.com<mailto:***@novidys.com>; rancid-***@shrubbery.net<mailto:rancid-***@shrubbery.net>
Subject: Re: [rancid] Palo Alto Networks

HI,

did you manage to get the RANCID running with PAN?

Regards,
Kishore

On Thursday, 29 March 2012 13:53:33 UTC+1, Guillaume Dupuis wrote:
Nate Beck <Nate.Beck <at> jivesoftware.com<http://jivesoftware.com>> writes:

>
>
> Has anyone on the list worked with Palo Alto Network firewalls and Rancid? I
was wondering if anyone has created a *login for them.
> Thanks-------------------
> Nathan BeckSr. IT Engineer
> Jive Software
> 503.972.9024

Hi Nate,

Did you find a *login script for PAN?

Thanks,

Guillaume Dupuis

_______________________________________________
Rancid-discuss mailing list
Rancid-***@shrubbery.net<javascript:>
http://www.shrubbery.net/mailman/listinfo.cgi/rancid-discuss
Ryan Milton
2013-09-25 13:17:39 UTC
Permalink
Got it! Thanks. I will report back with the results.

Regards,
Ryan Milton
MVS Network Manager
o: 201-447-1505 x124
c: 862-249-5230
www.mvsusa.com<http://www.mvsusa.com/>
[MVS final logo GOOD very small]

From: Hughes, Doug [mailto:***@DEShawResearch.com]
Sent: Wednesday, September 25, 2013 8:59 AM
To: Ryan Milton; Kishore Rajani; rancid-***@googlegroups.com
Cc: ***@novidys.com; rancid-***@shrubbery.net
Subject: RE: [rancid] Palo Alto Networks

First off, in the .cloginrc define the login type as ssh You can use wildcards that match the hostname, so if you name your devices something like paloalto1, paloalto2, etc. it would be something like this to define ssh as the mechanism, admin as the user and FooBar as the password

add method paloalto* ssh
add user paloalto* admin
add password paloalto* FooBar

then in the router.db file that defines all of the switches/routers for that subdomain (assuming you have subdomains, otherwise your main router.db)

paloalto1:paloalto:up
paloalto2:paloalto:up



From: Ryan Milton [mailto:***@mvsusa.com]
Sent: Wednesday, September 25, 2013 8:53 AM
To: Hughes, Doug; Kishore Rajani; rancid-***@googlegroups.com<mailto:rancid-***@googlegroups.com>
Cc: ***@novidys.com<mailto:***@novidys.com>; rancid-***@shrubbery.net<mailto:rancid-***@shrubbery.net>
Subject: RE: [rancid] Palo Alto Networks

Wow! This is great. I am still quite a noob at Rancid. When you say “switch type,” what do you mean by that? That is not in these files, is it?

Regards,
Ryan Milton
MVS Network Manager
o: 201-447-1505 x124
c: 862-249-5230
www.mvsusa.com<http://www.mvsusa.com/>
[MVS final logo GOOD very small]

From: Hughes, Doug [mailto:***@DEShawResearch.com]
Sent: Tuesday, September 24, 2013 5:02 PM
To: Ryan Milton; Kishore Rajani; rancid-***@googlegroups.com<mailto:rancid-***@googlegroups.com>
Cc: ***@novidys.com<mailto:***@novidys.com>; rancid-***@shrubbery.net<mailto:rancid-***@shrubbery.net>
Subject: RE: [rancid] Palo Alto Networks

Sure they can. I do it for 3 of them right now.

Attached. Set your ‘switch type’ to paloalto. Works with names or IP addresses.

From: Ryan Milton [mailto:***@mvsusa.com]
Sent: Tuesday, September 24, 2013 4:58 PM
To: Hughes, Doug; Kishore Rajani; rancid-***@googlegroups.com<mailto:rancid-***@googlegroups.com>
Cc: ***@novidys.com<mailto:***@novidys.com>; rancid-***@shrubbery.net<mailto:rancid-***@shrubbery.net>
Subject: RE: [rancid] Palo Alto Networks

I would certainly be interested in adding PAN devices to Rancid. I thought that they couldn’t be read. That is what I’ve found with my HP switches—but that is another matter. Any ideas on getting PAN devices read by Rancid would be useful.

Regards,
Ryan Milton

From: rancid-discuss-***@shrubbery.net<mailto:rancid-discuss-***@shrubbery.net> [mailto:rancid-discuss-***@shrubbery.net] On Behalf Of Hughes, Doug
Sent: Tuesday, September 24, 2013 12:26 PM
To: Kishore Rajani; rancid-***@googlegroups.com<mailto:rancid-***@googlegroups.com>
Cc: ***@novidys.com<mailto:***@novidys.com>; rancid-***@shrubbery.net<mailto:rancid-***@shrubbery.net>
Subject: Re: [rancid] Palo Alto Networks

Yes, I have working panlogin and panrancid and have contributed them upstream. Have you not been able to get them to work?


From: rancid-discuss-***@shrubbery.net<mailto:rancid-discuss-***@shrubbery.net> [mailto:rancid-discuss-***@shrubbery.net] On Behalf Of Kishore Rajani
Sent: Monday, September 23, 2013 9:52 AM
To: rancid-***@googlegroups.com<mailto:rancid-***@googlegroups.com>
Cc: ***@novidys.com<mailto:***@novidys.com>; rancid-***@shrubbery.net<mailto:rancid-***@shrubbery.net>
Subject: Re: [rancid] Palo Alto Networks

HI,

did you manage to get the RANCID running with PAN?

Regards,
Kishore

On Thursday, 29 March 2012 13:53:33 UTC+1, Guillaume Dupuis wrote:
Nate Beck <Nate.Beck <at> jivesoftware.com<http://jivesoftware.com>> writes:

>
>
> Has anyone on the list worked with Palo Alto Network firewalls and Rancid? I
was wondering if anyone has created a *login for them.
> Thanks-------------------
> Nathan BeckSr. IT Engineer
> Jive Software
> 503.972.9024

Hi Nate,

Did you find a *login script for PAN?

Thanks,

Guillaume Dupuis

_______________________________________________
Rancid-discuss mailing list
Rancid-***@shrubbery.net<javascript:>
http://www.shrubbery.net/mailman/listinfo.cgi/rancid-discuss
Ryan Milton
2013-09-25 12:52:35 UTC
Permalink
Wow! This is great. I am still quite a noob at Rancid. When you say “switch type,” what do you mean by that? That is not in these files, is it?

Regards,
Ryan Milton
MVS Network Manager
o: 201-447-1505 x124
c: 862-249-5230
www.mvsusa.com<http://www.mvsusa.com/>
[MVS final logo GOOD very small]

From: Hughes, Doug [mailto:***@DEShawResearch.com]
Sent: Tuesday, September 24, 2013 5:02 PM
To: Ryan Milton; Kishore Rajani; rancid-***@googlegroups.com
Cc: ***@novidys.com; rancid-***@shrubbery.net
Subject: RE: [rancid] Palo Alto Networks

Sure they can. I do it for 3 of them right now.

Attached. Set your ‘switch type’ to paloalto. Works with names or IP addresses.

From: Ryan Milton [mailto:***@mvsusa.com]
Sent: Tuesday, September 24, 2013 4:58 PM
To: Hughes, Doug; Kishore Rajani; rancid-***@googlegroups.com<mailto:rancid-***@googlegroups.com>
Cc: ***@novidys.com<mailto:***@novidys.com>; rancid-***@shrubbery.net<mailto:rancid-***@shrubbery.net>
Subject: RE: [rancid] Palo Alto Networks

I would certainly be interested in adding PAN devices to Rancid. I thought that they couldn’t be read. That is what I’ve found with my HP switches—but that is another matter. Any ideas on getting PAN devices read by Rancid would be useful.

Regards,
Ryan Milton

From: rancid-discuss-***@shrubbery.net<mailto:rancid-discuss-***@shrubbery.net> [mailto:rancid-discuss-***@shrubbery.net] On Behalf Of Hughes, Doug
Sent: Tuesday, September 24, 2013 12:26 PM
To: Kishore Rajani; rancid-***@googlegroups.com<mailto:rancid-***@googlegroups.com>
Cc: ***@novidys.com<mailto:***@novidys.com>; rancid-***@shrubbery.net<mailto:rancid-***@shrubbery.net>
Subject: Re: [rancid] Palo Alto Networks

Yes, I have working panlogin and panrancid and have contributed them upstream. Have you not been able to get them to work?


From: rancid-discuss-***@shrubbery.net<mailto:rancid-discuss-***@shrubbery.net> [mailto:rancid-discuss-***@shrubbery.net] On Behalf Of Kishore Rajani
Sent: Monday, September 23, 2013 9:52 AM
To: rancid-***@googlegroups.com<mailto:rancid-***@googlegroups.com>
Cc: ***@novidys.com<mailto:***@novidys.com>; rancid-***@shrubbery.net<mailto:rancid-***@shrubbery.net>
Subject: Re: [rancid] Palo Alto Networks

HI,

did you manage to get the RANCID running with PAN?

Regards,
Kishore

On Thursday, 29 March 2012 13:53:33 UTC+1, Guillaume Dupuis wrote:
Nate Beck <Nate.Beck <at> jivesoftware.com<http://jivesoftware.com>> writes:

>
>
> Has anyone on the list worked with Palo Alto Network firewalls and Rancid? I
was wondering if anyone has created a *login for them.
> Thanks-------------------
> Nathan BeckSr. IT Engineer
> Jive Software
> 503.972.9024

Hi Nate,

Did you find a *login script for PAN?

Thanks,

Guillaume Dupuis

_______________________________________________
Rancid-discuss mailing list
Rancid-***@shrubbery.net<javascript:>
http://www.shrubbery.net/mailman/listinfo.cgi/rancid-discuss
Ryan West
2013-09-25 13:09:14 UTC
Permalink
Check bin/rancid-fe

Sent from handheld.

On Sep 25, 2013, at 9:08 AM, "Ryan Milton" <***@mvsusa.com<mailto:***@mvsusa.com>> wrote:

Wow! This is great. I am still quite a noob at Rancid. When you say “switch type,” what do you mean by that? That is not in these files, is it?

Regards,
Ryan Milton
MVS Network Manager
o: 201-447-1505 x124
c: 862-249-5230
www.mvsusa.com<http://www.mvsusa.com/>
<image001.jpg>

From: Hughes, Doug [mailto:***@DEShawResearch.com]
Sent: Tuesday, September 24, 2013 5:02 PM
To: Ryan Milton; Kishore Rajani; rancid-***@googlegroups.com<mailto:rancid-***@googlegroups.com>
Cc: ***@novidys.com<mailto:***@novidys.com>; rancid-***@shrubbery.net<mailto:rancid-***@shrubbery.net>
Subject: RE: [rancid] Palo Alto Networks

Sure they can. I do it for 3 of them right now.

Attached. Set your ‘switch type’ to paloalto. Works with names or IP addresses.

From: Ryan Milton [mailto:***@mvsusa.com]
Sent: Tuesday, September 24, 2013 4:58 PM
To: Hughes, Doug; Kishore Rajani; rancid-***@googlegroups.com<mailto:rancid-***@googlegroups.com>
Cc: ***@novidys.com<mailto:***@novidys.com>; rancid-***@shrubbery.net<mailto:rancid-***@shrubbery.net>
Subject: RE: [rancid] Palo Alto Networks

I would certainly be interested in adding PAN devices to Rancid. I thought that they couldn’t be read. That is what I’ve found with my HP switches—but that is another matter. Any ideas on getting PAN devices read by Rancid would be useful.

Regards,
Ryan Milton

From: rancid-discuss-***@shrubbery.net<mailto:rancid-discuss-***@shrubbery.net> [mailto:rancid-discuss-***@shrubbery.net] On Behalf Of Hughes, Doug
Sent: Tuesday, September 24, 2013 12:26 PM
To: Kishore Rajani; rancid-***@googlegroups.com<mailto:rancid-***@googlegroups.com>
Cc: ***@novidys.com<mailto:***@novidys.com>; rancid-***@shrubbery.net<mailto:rancid-***@shrubbery.net>
Subject: Re: [rancid] Palo Alto Networks

Yes, I have working panlogin and panrancid and have contributed them upstream. Have you not been able to get them to work?


From: rancid-discuss-***@shrubbery.net<mailto:rancid-discuss-***@shrubbery.net> [mailto:rancid-discuss-***@shrubbery.net] On Behalf Of Kishore Rajani
Sent: Monday, September 23, 2013 9:52 AM
To: rancid-***@googlegroups.com<mailto:rancid-***@googlegroups.com>
Cc: ***@novidys.com<mailto:***@novidys.com>; rancid-***@shrubbery.net<mailto:rancid-***@shrubbery.net>
Subject: Re: [rancid] Palo Alto Networks

HI,

did you manage to get the RANCID running with PAN?

Regards,
Kishore

On Thursday, 29 March 2012 13:53:33 UTC+1, Guillaume Dupuis wrote:
Nate Beck <Nate.Beck <at> jivesoftware.com<http://jivesoftware.com>> writes:

>
>
> Has anyone on the list worked with Palo Alto Network firewalls and Rancid? I
was wondering if anyone has created a *login for them.
> Thanks-------------------
> Nathan BeckSr. IT Engineer
> Jive Software
> 503.972.9024

Hi Nate,

Did you find a *login script for PAN?

Thanks,

Guillaume Dupuis
Kishore Rajani
2013-09-24 21:44:27 UTC
Permalink
Hi All,

Thanks for your inputs.. much appreciated.

I think i had downloaded these files from some other website, not sure if
you have modified it, Doug..

In my setup, I am able to login into the device using panlogin.. however
the device config are not backed up. Everything works smooth for Cisco
devices.
I have updated the routers.db and other files for PAN devices, but no luck
yet.

Unfortunately, I am unable to reach my remote site server at the moment,
else would have pasted the log file.

Regards,
Kishore



On 24 September 2013 22:01, Hughes, Doug
<***@deshawresearch.com>wrote:

> Sure they can. I do it for 3 of them right now.****
>
> ** **
>
> Attached. Set your ‘switch type’ to paloalto. Works with names or IP
> addresses.****
>
> ** **
>
> *From:* Ryan Milton [mailto:***@mvsusa.com]
> *Sent:* Tuesday, September 24, 2013 4:58 PM
> *To:* Hughes, Doug; Kishore Rajani; rancid-***@googlegroups.com
> *Cc:* ***@novidys.com; rancid-***@shrubbery.net
> *Subject:* RE: [rancid] Palo Alto Networks****
>
> ** **
>
> I would certainly be interested in adding PAN devices to Rancid. I thought
> that they couldn’t be read. That is what I’ve found with my HP switches—but
> that is another matter. Any ideas on getting PAN devices read by Rancid
> would be useful.****
>
> ** **
>
> Regards,****
>
> Ryan Milton****
>
> ** **
>
> *From:* rancid-discuss-***@shrubbery.net [
> mailto:rancid-discuss-***@shrubbery.net<rancid-discuss-***@shrubbery.net>]
> *On Behalf Of *Hughes, Doug
> *Sent:* Tuesday, September 24, 2013 12:26 PM
> *To:* Kishore Rajani; rancid-***@googlegroups.com
> *Cc:* ***@novidys.com; rancid-***@shrubbery.net
> *Subject:* Re: [rancid] Palo Alto Networks****
>
> ** **
>
> Yes, I have working panlogin and panrancid and have contributed them
> upstream. Have you not been able to get them to work?****
>
> ** **
>
> ** **
>
> *From:* rancid-discuss-***@shrubbery.net [
> mailto:rancid-discuss-***@shrubbery.net<rancid-discuss-***@shrubbery.net>]
> *On Behalf Of *Kishore Rajani
> *Sent:* Monday, September 23, 2013 9:52 AM
> *To:* rancid-***@googlegroups.com
> *Cc:* ***@novidys.com; rancid-***@shrubbery.net
> *Subject:* Re: [rancid] Palo Alto Networks****
>
> ** **
>
> HI,
>
> did you manage to get the RANCID running with PAN?
>
> Regards,
> Kishore
>
> On Thursday, 29 March 2012 13:53:33 UTC+1, Guillaume Dupuis wrote:****
>
> Nate Beck <Nate.Beck <at> jivesoftware.com> writes:****
>
> >
> >
> > Has anyone on the list worked with Palo Alto Network firewalls and
> Rancid? I
> was wondering if anyone has created a *login for them.
> > Thanks-------------------
> > Nathan BeckSr. IT Engineer
> > Jive Software
> > 503.972.9024****
>
> Hi Nate,****
>
> Did you find a *login script for PAN?****
>
> Thanks,****
>
> Guillaume Dupuis****
>
> _______________________________________________
> Rancid-discuss mailing list
> Rancid-***@shrubbery.net
> http://www.shrubbery.net/mailman/listinfo.cgi/rancid-discuss****
>
Ryan Milton
2013-09-27 15:08:24 UTC
Permalink
Hi Doug,

So I am testing your scripts. I got one error:
Trying to get all of the configs.
defined(%hash) is deprecated at /usr/lib/rancid/bin/panrancid line 53.
(Maybe you should just omit the defined()?)
Paloaltofw1: missed cmd(s): show config running, set
..

Is there a fix for this? I figure the code is just out of date?

Regards,
Ryan Milton
MVS Network Manager
o: 201-447-1505 x124
c: 862-249-5230
www.mvsusa.com<http://www.mvsusa.com/>
[MVS final logo GOOD very small]

From: Hughes, Doug [mailto:***@DEShawResearch.com]
Sent: Tuesday, September 24, 2013 5:02 PM
To: Ryan Milton; Kishore Rajani; rancid-***@googlegroups.com
Cc: ***@novidys.com; rancid-***@shrubbery.net
Subject: RE: [rancid] Palo Alto Networks

Sure they can. I do it for 3 of them right now.

Attached. Set your ‘switch type’ to paloalto. Works with names or IP addresses.

From: Ryan Milton [mailto:***@mvsusa.com]
Sent: Tuesday, September 24, 2013 4:58 PM
To: Hughes, Doug; Kishore Rajani; rancid-***@googlegroups.com<mailto:rancid-***@googlegroups.com>
Cc: ***@novidys.com<mailto:***@novidys.com>; rancid-***@shrubbery.net<mailto:rancid-***@shrubbery.net>
Subject: RE: [rancid] Palo Alto Networks

I would certainly be interested in adding PAN devices to Rancid. I thought that they couldn’t be read. That is what I’ve found with my HP switches—but that is another matter. Any ideas on getting PAN devices read by Rancid would be useful.

Regards,
Ryan Milton

From: rancid-discuss-***@shrubbery.net<mailto:rancid-discuss-***@shrubbery.net> [mailto:rancid-discuss-***@shrubbery.net] On Behalf Of Hughes, Doug
Sent: Tuesday, September 24, 2013 12:26 PM
To: Kishore Rajani; rancid-***@googlegroups.com<mailto:rancid-***@googlegroups.com>
Cc: ***@novidys.com<mailto:***@novidys.com>; rancid-***@shrubbery.net<mailto:rancid-***@shrubbery.net>
Subject: Re: [rancid] Palo Alto Networks

Yes, I have working panlogin and panrancid and have contributed them upstream. Have you not been able to get them to work?


From: rancid-discuss-***@shrubbery.net<mailto:rancid-discuss-***@shrubbery.net> [mailto:rancid-discuss-***@shrubbery.net] On Behalf Of Kishore Rajani
Sent: Monday, September 23, 2013 9:52 AM
To: rancid-***@googlegroups.com<mailto:rancid-***@googlegroups.com>
Cc: ***@novidys.com<mailto:***@novidys.com>; rancid-***@shrubbery.net<mailto:rancid-***@shrubbery.net>
Subject: Re: [rancid] Palo Alto Networks

HI,

did you manage to get the RANCID running with PAN?

Regards,
Kishore

On Thursday, 29 March 2012 13:53:33 UTC+1, Guillaume Dupuis wrote:
Nate Beck <Nate.Beck <at> jivesoftware.com<http://jivesoftware.com>> writes:

>
>
> Has anyone on the list worked with Palo Alto Network firewalls and Rancid? I
was wondering if anyone has created a *login for them.
> Thanks-------------------
> Nathan BeckSr. IT Engineer
> Jive Software
> 503.972.9024

Hi Nate,

Did you find a *login script for PAN?

Thanks,

Guillaume Dupuis

_______________________________________________
Rancid-discuss mailing list
Rancid-***@shrubbery.net<javascript:>
http://www.shrubbery.net/mailman/listinfo.cgi/rancid-discuss
Hughes, Doug
2013-09-27 15:14:55 UTC
Permalink
What version of Perl are you using? That looks like a Perl error. Also, I don’t have a define(%hash) at line 53 in the one I sent you.

What does ‘sum /usr/lib/rancid/bin/panrancid’ say?
It should say
14180 9


From: Ryan Milton [mailto:***@mvsusa.com]
Sent: Friday, September 27, 2013 11:08 AM
To: Hughes, Doug; Kishore Rajani
Cc: ***@novidys.com; rancid-***@shrubbery.net
Subject: RE: [rancid] Palo Alto Networks

Hi Doug,

So I am testing your scripts. I got one error:
Trying to get all of the configs.
defined(%hash) is deprecated at /usr/lib/rancid/bin/panrancid line 53.
(Maybe you should just omit the defined()?)
Paloaltofw1: missed cmd(s): show config running, set
..

Is there a fix for this? I figure the code is just out of date?

Regards,
Ryan Milton
MVS Network Manager
o: 201-447-1505 x124
c: 862-249-5230
www.mvsusa.com<http://www.mvsusa.com/>
[MVS final logo GOOD very small]

From: Hughes, Doug [mailto:***@DEShawResearch.com]
Sent: Tuesday, September 24, 2013 5:02 PM
To: Ryan Milton; Kishore Rajani; rancid-***@googlegroups.com<mailto:rancid-***@googlegroups.com>
Cc: ***@novidys.com<mailto:***@novidys.com>; rancid-***@shrubbery.net<mailto:rancid-***@shrubbery.net>
Subject: RE: [rancid] Palo Alto Networks

Sure they can. I do it for 3 of them right now.

Attached. Set your ‘switch type’ to paloalto. Works with names or IP addresses.

From: Ryan Milton [mailto:***@mvsusa.com]
Sent: Tuesday, September 24, 2013 4:58 PM
To: Hughes, Doug; Kishore Rajani; rancid-***@googlegroups.com<mailto:rancid-***@googlegroups.com>
Cc: ***@novidys.com<mailto:***@novidys.com>; rancid-***@shrubbery.net<mailto:rancid-***@shrubbery.net>
Subject: RE: [rancid] Palo Alto Networks

I would certainly be interested in adding PAN devices to Rancid. I thought that they couldn’t be read. That is what I’ve found with my HP switches—but that is another matter. Any ideas on getting PAN devices read by Rancid would be useful.

Regards,
Ryan Milton

From: rancid-discuss-***@shrubbery.net<mailto:rancid-discuss-***@shrubbery.net> [mailto:rancid-discuss-***@shrubbery.net] On Behalf Of Hughes, Doug
Sent: Tuesday, September 24, 2013 12:26 PM
To: Kishore Rajani; rancid-***@googlegroups.com<mailto:rancid-***@googlegroups.com>
Cc: ***@novidys.com<mailto:***@novidys.com>; rancid-***@shrubbery.net<mailto:rancid-***@shrubbery.net>
Subject: Re: [rancid] Palo Alto Networks

Yes, I have working panlogin and panrancid and have contributed them upstream. Have you not been able to get them to work?


From: rancid-discuss-***@shrubbery.net<mailto:rancid-discuss-***@shrubbery.net> [mailto:rancid-discuss-***@shrubbery.net] On Behalf Of Kishore Rajani
Sent: Monday, September 23, 2013 9:52 AM
To: rancid-***@googlegroups.com<mailto:rancid-***@googlegroups.com>
Cc: ***@novidys.com<mailto:***@novidys.com>; rancid-***@shrubbery.net<mailto:rancid-***@shrubbery.net>
Subject: Re: [rancid] Palo Alto Networks

HI,

did you manage to get the RANCID running with PAN?

Regards,
Kishore

On Thursday, 29 March 2012 13:53:33 UTC+1, Guillaume Dupuis wrote:
Nate Beck <Nate.Beck <at> jivesoftware.com<http://jivesoftware.com>> writes:

>
>
> Has anyone on the list worked with Palo Alto Network firewalls and Rancid? I
was wondering if anyone has created a *login for them.
> Thanks-------------------
> Nathan BeckSr. IT Engineer
> Jive Software
> 503.972.9024

Hi Nate,

Did you find a *login script for PAN?

Thanks,

Guillaume Dupuis

_______________________________________________
Rancid-discuss mailing list
Rancid-***@shrubbery.net<javascript:>
http://www.shrubbery.net/mailman/listinfo.cgi/rancid-discuss
Ryan Milton
2013-09-27 17:22:32 UTC
Permalink
So, the Perl version is perl 5, version 14, subversion 2 (v5.14.2) built for x86_64-linux-gnu-thread-multi

And

***@ObserviumNYC:~$ sum /usr/lib/rancid/bin/panrancid
14180 9

Regards,
Ryan Milton
MVS Network Manager
o: 201-447-1505 x124
c: 862-249-5230
www.mvsusa.com<http://www.mvsusa.com/>
[MVS final logo GOOD very small]

From: Hughes, Doug [mailto:***@DEShawResearch.com]
Sent: Friday, September 27, 2013 11:15 AM
To: Ryan Milton; Kishore Rajani
Cc: ***@novidys.com; rancid-***@shrubbery.net
Subject: RE: [rancid] Palo Alto Networks

What version of Perl are you using? That looks like a Perl error. Also, I don’t have a define(%hash) at line 53 in the one I sent you.

What does ‘sum /usr/lib/rancid/bin/panrancid’ say?
It should say
14180 9


From: Ryan Milton [mailto:***@mvsusa.com]
Sent: Friday, September 27, 2013 11:08 AM
To: Hughes, Doug; Kishore Rajani
Cc: ***@novidys.com<mailto:***@novidys.com>; rancid-***@shrubbery.net<mailto:rancid-***@shrubbery.net>
Subject: RE: [rancid] Palo Alto Networks

Hi Doug,

So I am testing your scripts. I got one error:
Trying to get all of the configs.
defined(%hash) is deprecated at /usr/lib/rancid/bin/panrancid line 53.
(Maybe you should just omit the defined()?)
Paloaltofw1: missed cmd(s): show config running, set
..

Is there a fix for this? I figure the code is just out of date?

Regards,
Ryan Milton
MVS Network Manager
o: 201-447-1505 x124
c: 862-249-5230
www.mvsusa.com<http://www.mvsusa.com/>
[MVS final logo GOOD very small]

From: Hughes, Doug [mailto:***@DEShawResearch.com]
Sent: Tuesday, September 24, 2013 5:02 PM
To: Ryan Milton; Kishore Rajani; rancid-***@googlegroups.com<mailto:rancid-***@googlegroups.com>
Cc: ***@novidys.com<mailto:***@novidys.com>; rancid-***@shrubbery.net<mailto:rancid-***@shrubbery.net>
Subject: RE: [rancid] Palo Alto Networks

Sure they can. I do it for 3 of them right now.

Attached. Set your ‘switch type’ to paloalto. Works with names or IP addresses.

From: Ryan Milton [mailto:***@mvsusa.com]
Sent: Tuesday, September 24, 2013 4:58 PM
To: Hughes, Doug; Kishore Rajani; rancid-***@googlegroups.com<mailto:rancid-***@googlegroups.com>
Cc: ***@novidys.com<mailto:***@novidys.com>; rancid-***@shrubbery.net<mailto:rancid-***@shrubbery.net>
Subject: RE: [rancid] Palo Alto Networks

I would certainly be interested in adding PAN devices to Rancid. I thought that they couldn’t be read. That is what I’ve found with my HP switches—but that is another matter. Any ideas on getting PAN devices read by Rancid would be useful.

Regards,
Ryan Milton

From: rancid-discuss-***@shrubbery.net<mailto:rancid-discuss-***@shrubbery.net> [mailto:rancid-discuss-***@shrubbery.net] On Behalf Of Hughes, Doug
Sent: Tuesday, September 24, 2013 12:26 PM
To: Kishore Rajani; rancid-***@googlegroups.com<mailto:rancid-***@googlegroups.com>
Cc: ***@novidys.com<mailto:***@novidys.com>; rancid-***@shrubbery.net<mailto:rancid-***@shrubbery.net>
Subject: Re: [rancid] Palo Alto Networks

Yes, I have working panlogin and panrancid and have contributed them upstream. Have you not been able to get them to work?


From: rancid-discuss-***@shrubbery.net<mailto:rancid-discuss-***@shrubbery.net> [mailto:rancid-discuss-***@shrubbery.net] On Behalf Of Kishore Rajani
Sent: Monday, September 23, 2013 9:52 AM
To: rancid-***@googlegroups.com<mailto:rancid-***@googlegroups.com>
Cc: ***@novidys.com<mailto:***@novidys.com>; rancid-***@shrubbery.net<mailto:rancid-***@shrubbery.net>
Subject: Re: [rancid] Palo Alto Networks

HI,

did you manage to get the RANCID running with PAN?

Regards,
Kishore

On Thursday, 29 March 2012 13:53:33 UTC+1, Guillaume Dupuis wrote:
Nate Beck <Nate.Beck <at> jivesoftware.com<http://jivesoftware.com>> writes:

>
>
> Has anyone on the list worked with Palo Alto Network firewalls and Rancid? I
was wondering if anyone has created a *login for them.
> Thanks-------------------
> Nathan BeckSr. IT Engineer
> Jive Software
> 503.972.9024

Hi Nate,

Did you find a *login script for PAN?

Thanks,

Guillaume Dupuis

_______________________________________________
Rancid-discuss mailing list
Rancid-***@shrubbery.net<javascript:>
http://www.shrubbery.net/mailman/listinfo.cgi/rancid-discuss
Hughes, Doug
2013-09-27 19:57:58 UTC
Permalink
I have perl 5.8.8. I’m not sure why that would make a significant difference, though.

There are many used of defined in the perl code.. So why would it pick that one? (semi-rhetorical)

It appears to be complaining about the first use of defined. Do other rancid files work ok? ProcessHistory is just lifted from another one, originally.. Does the crancid or hprancid work ok?

Do you have access to an older Perl for testing?

Does it work if you run panrancid directly on the command line from the bin directory?


From: Ryan Milton [mailto:***@mvsusa.com]
Sent: Friday, September 27, 2013 1:23 PM
To: Hughes, Doug; Kishore Rajani
Cc: ***@novidys.com; rancid-***@shrubbery.net
Subject: RE: [rancid] Palo Alto Networks

So, the Perl version is perl 5, version 14, subversion 2 (v5.14.2) built for x86_64-linux-gnu-thread-multi

And

***@ObserviumNYC:~$ sum /usr/lib/rancid/bin/panrancid
14180 9

Regards,
Ryan Milton
MVS Network Manager
o: 201-447-1505 x124
c: 862-249-5230
www.mvsusa.com<http://www.mvsusa.com/>
[MVS final logo GOOD very small]

From: Hughes, Doug [mailto:***@DEShawResearch.com]
Sent: Friday, September 27, 2013 11:15 AM
To: Ryan Milton; Kishore Rajani
Cc: ***@novidys.com<mailto:***@novidys.com>; rancid-***@shrubbery.net<mailto:rancid-***@shrubbery.net>
Subject: RE: [rancid] Palo Alto Networks

What version of Perl are you using? That looks like a Perl error. Also, I don’t have a define(%hash) at line 53 in the one I sent you.

What does ‘sum /usr/lib/rancid/bin/panrancid’ say?
It should say
14180 9


From: Ryan Milton [mailto:***@mvsusa.com]
Sent: Friday, September 27, 2013 11:08 AM
To: Hughes, Doug; Kishore Rajani
Cc: ***@novidys.com<mailto:***@novidys.com>; rancid-***@shrubbery.net<mailto:rancid-***@shrubbery.net>
Subject: RE: [rancid] Palo Alto Networks

Hi Doug,

So I am testing your scripts. I got one error:
Trying to get all of the configs.
defined(%hash) is deprecated at /usr/lib/rancid/bin/panrancid line 53.
(Maybe you should just omit the defined()?)
Paloaltofw1: missed cmd(s): show config running, set
..

Is there a fix for this? I figure the code is just out of date?

Regards,
Ryan Milton
MVS Network Manager
o: 201-447-1505 x124
c: 862-249-5230
www.mvsusa.com<http://www.mvsusa.com/>
[MVS final logo GOOD very small]

From: Hughes, Doug [mailto:***@DEShawResearch.com]
Sent: Tuesday, September 24, 2013 5:02 PM
To: Ryan Milton; Kishore Rajani; rancid-***@googlegroups.com<mailto:rancid-***@googlegroups.com>
Cc: ***@novidys.com<mailto:***@novidys.com>; rancid-***@shrubbery.net<mailto:rancid-***@shrubbery.net>
Subject: RE: [rancid] Palo Alto Networks

Sure they can. I do it for 3 of them right now.

Attached. Set your ‘switch type’ to paloalto. Works with names or IP addresses.

From: Ryan Milton [mailto:***@mvsusa.com]
Sent: Tuesday, September 24, 2013 4:58 PM
To: Hughes, Doug; Kishore Rajani; rancid-***@googlegroups.com<mailto:rancid-***@googlegroups.com>
Cc: ***@novidys.com<mailto:***@novidys.com>; rancid-***@shrubbery.net<mailto:rancid-***@shrubbery.net>
Subject: RE: [rancid] Palo Alto Networks

I would certainly be interested in adding PAN devices to Rancid. I thought that they couldn’t be read. That is what I’ve found with my HP switches—but that is another matter. Any ideas on getting PAN devices read by Rancid would be useful.

Regards,
Ryan Milton

From: rancid-discuss-***@shrubbery.net<mailto:rancid-discuss-***@shrubbery.net> [mailto:rancid-discuss-***@shrubbery.net] On Behalf Of Hughes, Doug
Sent: Tuesday, September 24, 2013 12:26 PM
To: Kishore Rajani; rancid-***@googlegroups.com<mailto:rancid-***@googlegroups.com>
Cc: ***@novidys.com<mailto:***@novidys.com>; rancid-***@shrubbery.net<mailto:rancid-***@shrubbery.net>
Subject: Re: [rancid] Palo Alto Networks

Yes, I have working panlogin and panrancid and have contributed them upstream. Have you not been able to get them to work?


From: rancid-discuss-***@shrubbery.net<mailto:rancid-discuss-***@shrubbery.net> [mailto:rancid-discuss-***@shrubbery.net] On Behalf Of Kishore Rajani
Sent: Monday, September 23, 2013 9:52 AM
To: rancid-***@googlegroups.com<mailto:rancid-***@googlegroups.com>
Cc: ***@novidys.com<mailto:***@novidys.com>; rancid-***@shrubbery.net<mailto:rancid-***@shrubbery.net>
Subject: Re: [rancid] Palo Alto Networks

HI,

did you manage to get the RANCID running with PAN?

Regards,
Kishore

On Thursday, 29 March 2012 13:53:33 UTC+1, Guillaume Dupuis wrote:
Nate Beck <Nate.Beck <at> jivesoftware.com<http://jivesoftware.com>> writes:

>
>
> Has anyone on the list worked with Palo Alto Network firewalls and Rancid? I
was wondering if anyone has created a *login for them.
> Thanks-------------------
> Nathan BeckSr. IT Engineer
> Jive Software
> 503.972.9024

Hi Nate,

Did you find a *login script for PAN?

Thanks,

Guillaume Dupuis

_______________________________________________
Rancid-discuss mailing list
Rancid-***@shrubbery.net<javascript:>
http://www.shrubbery.net/mailman/listinfo.cgi/rancid-discuss
Ryan Milton
2013-09-28 17:48:54 UTC
Permalink
You ask a few questions. Most of my scripts seem to work, like jrancid, nrancid. Hrancid (for hp?) doesn't seem to work as I get "failed to login" errors.

Does it work if you run panrancid directly on the command line from the bin directory?

-->not sure I know how to do this.

Ryan Milton
MVS Network Manager
O: 201-447-1505 x124
C: 862-249-5230
________________________________
From: Hughes, Doug <***@DEShawResearch.com>
Sent: Friday, September 27, 2013 3:57:58 PM
To: Ryan Milton; Kishore Rajani
Cc: ***@novidys.com; rancid-***@shrubbery.net
Subject: RE: [rancid] Palo Alto Networks

I have perl 5.8.8. I’m not sure why that would make a significant difference, though.

There are many used of defined in the perl code.. So why would it pick that one? (semi-rhetorical)

It appears to be complaining about the first use of defined. Do other rancid files work ok? ProcessHistory is just lifted from another one, originally.. Does the crancid or hprancid work ok?

Do you have access to an older Perl for testing?

Does it work if you run panrancid directly on the command line from the bin directory?


From: Ryan Milton [mailto:***@mvsusa.com]
Sent: Friday, September 27, 2013 1:23 PM
To: Hughes, Doug; Kishore Rajani
Cc: ***@novidys.com; rancid-***@shrubbery.net
Subject: RE: [rancid] Palo Alto Networks

So, the Perl version is perl 5, version 14, subversion 2 (v5.14.2) built for x86_64-linux-gnu-thread-multi

And

***@ObserviumNYC:~$ sum /usr/lib/rancid/bin/panrancid
14180 9

Regards,
Ryan Milton
MVS Network Manager
o: 201-447-1505 x124
c: 862-249-5230
www.mvsusa.com<http://www.mvsusa.com/>
[MVS final logo GOOD very small]

From: Hughes, Doug [mailto:***@DEShawResearch.com]
Sent: Friday, September 27, 2013 11:15 AM
To: Ryan Milton; Kishore Rajani
Cc: ***@novidys.com<mailto:***@novidys.com>; rancid-***@shrubbery.net<mailto:rancid-***@shrubbery.net>
Subject: RE: [rancid] Palo Alto Networks

What version of Perl are you using? That looks like a Perl error. Also, I don’t have a define(%hash) at line 53 in the one I sent you.

What does ‘sum /usr/lib/rancid/bin/panrancid’ say?
It should say
14180 9


From: Ryan Milton [mailto:***@mvsusa.com]
Sent: Friday, September 27, 2013 11:08 AM
To: Hughes, Doug; Kishore Rajani
Cc: ***@novidys.com<mailto:***@novidys.com>; rancid-***@shrubbery.net<mailto:rancid-***@shrubbery.net>
Subject: RE: [rancid] Palo Alto Networks

Hi Doug,

So I am testing your scripts. I got one error:
Trying to get all of the configs.
defined(%hash) is deprecated at /usr/lib/rancid/bin/panrancid line 53.
(Maybe you should just omit the defined()?)
Paloaltofw1: missed cmd(s): show config running, set…..

Is there a fix for this? I figure the code is just out of date?

Regards,
Ryan Milton
MVS Network Manager
o: 201-447-1505 x124
c: 862-249-5230
www.mvsusa.com<http://www.mvsusa.com/>
[MVS final logo GOOD very small]

From: Hughes, Doug [mailto:***@DEShawResearch.com]
Sent: Tuesday, September 24, 2013 5:02 PM
To: Ryan Milton; Kishore Rajani; rancid-***@googlegroups.com<mailto:rancid-***@googlegroups.com>
Cc: ***@novidys.com<mailto:***@novidys.com>; rancid-***@shrubbery.net<mailto:rancid-***@shrubbery.net>
Subject: RE: [rancid] Palo Alto Networks

Sure they can. I do it for 3 of them right now.

Attached. Set your ‘switch type’ to paloalto. Works with names or IP addresses.

From: Ryan Milton [mailto:***@mvsusa.com]
Sent: Tuesday, September 24, 2013 4:58 PM
To: Hughes, Doug; Kishore Rajani; rancid-***@googlegroups.com<mailto:rancid-***@googlegroups.com>
Cc: ***@novidys.com<mailto:***@novidys.com>; rancid-***@shrubbery.net<mailto:rancid-***@shrubbery.net>
Subject: RE: [rancid] Palo Alto Networks

I would certainly be interested in adding PAN devices to Rancid. I thought that they couldn’t be read. That is what I’ve found with my HP switches—but that is another matter. Any ideas on getting PAN devices read by Rancid would be useful.

Regards,
Ryan Milton

From: rancid-discuss-***@shrubbery.net<mailto:rancid-discuss-***@shrubbery.net> [mailto:rancid-discuss-***@shrubbery.net] On Behalf Of Hughes, Doug
Sent: Tuesday, September 24, 2013 12:26 PM
To: Kishore Rajani; rancid-***@googlegroups.com<mailto:rancid-***@googlegroups.com>
Cc: ***@novidys.com<mailto:***@novidys.com>; rancid-***@shrubbery.net<mailto:rancid-***@shrubbery.net>
Subject: Re: [rancid] Palo Alto Networks

Yes, I have working panlogin and panrancid and have contributed them upstream. Have you not been able to get them to work?


From: rancid-discuss-***@shrubbery.net<mailto:rancid-discuss-***@shrubbery.net> [mailto:rancid-discuss-***@shrubbery.net] On Behalf Of Kishore Rajani
Sent: Monday, September 23, 2013 9:52 AM
To: rancid-***@googlegroups.com<mailto:rancid-***@googlegroups.com>
Cc: ***@novidys.com<mailto:***@novidys.com>; rancid-***@shrubbery.net<mailto:rancid-***@shrubbery.net>
Subject: Re: [rancid] Palo Alto Networks

HI,

did you manage to get the RANCID running with PAN?

Regards,
Kishore

On Thursday, 29 March 2012 13:53:33 UTC+1, Guillaume Dupuis wrote:
Nate Beck <Nate.Beck <at> jivesoftware.com<http://jivesoftware.com>> writes:

>
>
> Has anyone on the list worked with Palo Alto Network firewalls and Rancid? I
was wondering if anyone has created a *login for them.
> Thanks-------------------
> Nathan BeckSr. IT Engineer
> Jive Software
> 503.972.9024

Hi Nate,

Did you find a *login script for PAN?

Thanks,

Guillaume Dupuis
Hughes, Doug
2013-09-28 17:52:55 UTC
Permalink
1) Become the rancid user
2) make sure that panrancid and panlogin are in your path
3) "panrancid <device>"
After you run it, if it works, you should see a file <device>.new in the current directory.

If it fails, paste the results of this: "panrancid -d <device>"

From: Ryan Milton [mailto:***@mvsusa.com]
Sent: Saturday, September 28, 2013 1:49 PM
To: Hughes, Doug; Kishore Rajani
Cc: ***@novidys.com; rancid-***@shrubbery.net
Subject: RE: [rancid] Palo Alto Networks

You ask a few questions. Most of my scripts seem to work, like jrancid, nrancid. Hrancid (for hp?) doesn't seem to work as I get "failed to login" errors.

Does it work if you run panrancid directly on the command line from the bin directory?

-->not sure I know how to do this.

Ryan Milton
MVS Network Manager
O: 201-447-1505 x124
C: 862-249-5230
________________________________
From: Hughes, Doug <***@DEShawResearch.com<mailto:***@DEShawResearch.com>>
Sent: Friday, September 27, 2013 3:57:58 PM
To: Ryan Milton; Kishore Rajani
Cc: ***@novidys.com<mailto:***@novidys.com>; rancid-***@shrubbery.net<mailto:rancid-***@shrubbery.net>
Subject: RE: [rancid] Palo Alto Networks

I have perl 5.8.8. I'm not sure why that would make a significant difference, though.

There are many used of defined in the perl code.. So why would it pick that one? (semi-rhetorical)

It appears to be complaining about the first use of defined. Do other rancid files work ok? ProcessHistory is just lifted from another one, originally.. Does the crancid or hprancid work ok?

Do you have access to an older Perl for testing?

Does it work if you run panrancid directly on the command line from the bin directory?


From: Ryan Milton [mailto:***@mvsusa.com]
Sent: Friday, September 27, 2013 1:23 PM
To: Hughes, Doug; Kishore Rajani
Cc: ***@novidys.com<mailto:***@novidys.com>; rancid-***@shrubbery.net<mailto:rancid-***@shrubbery.net>
Subject: RE: [rancid] Palo Alto Networks

So, the Perl version is perl 5, version 14, subversion 2 (v5.14.2) built for x86_64-linux-gnu-thread-multi

And

***@ObserviumNYC:~$ sum /usr/lib/rancid/bin/panrancid
14180 9

Regards,
Ryan Milton
MVS Network Manager
o: 201-447-1505 x124
c: 862-249-5230
www.mvsusa.com<http://www.mvsusa.com/>
[MVS final logo GOOD very small]

From: Hughes, Doug [mailto:***@DEShawResearch.com]
Sent: Friday, September 27, 2013 11:15 AM
To: Ryan Milton; Kishore Rajani
Cc: ***@novidys.com<mailto:***@novidys.com>; rancid-***@shrubbery.net<mailto:rancid-***@shrubbery.net>
Subject: RE: [rancid] Palo Alto Networks

What version of Perl are you using? That looks like a Perl error. Also, I don't have a define(%hash) at line 53 in the one I sent you.

What does 'sum /usr/lib/rancid/bin/panrancid' say?
It should say
14180 9


From: Ryan Milton [mailto:***@mvsusa.com]
Sent: Friday, September 27, 2013 11:08 AM
To: Hughes, Doug; Kishore Rajani
Cc: ***@novidys.com<mailto:***@novidys.com>; rancid-***@shrubbery.net<mailto:rancid-***@shrubbery.net>
Subject: RE: [rancid] Palo Alto Networks

Hi Doug,

So I am testing your scripts. I got one error:
Trying to get all of the configs.
defined(%hash) is deprecated at /usr/lib/rancid/bin/panrancid line 53.
(Maybe you should just omit the defined()?)
Paloaltofw1: missed cmd(s): show config running, set.....

Is there a fix for this? I figure the code is just out of date?

Regards,
Ryan Milton
MVS Network Manager
o: 201-447-1505 x124
c: 862-249-5230
www.mvsusa.com<http://www.mvsusa.com/>
[MVS final logo GOOD very small]

From: Hughes, Doug [mailto:***@DEShawResearch.com]
Sent: Tuesday, September 24, 2013 5:02 PM
To: Ryan Milton; Kishore Rajani; rancid-***@googlegroups.com<mailto:rancid-***@googlegroups.com>
Cc: ***@novidys.com<mailto:***@novidys.com>; rancid-***@shrubbery.net<mailto:rancid-***@shrubbery.net>
Subject: RE: [rancid] Palo Alto Networks

Sure they can. I do it for 3 of them right now.

Attached. Set your 'switch type' to paloalto. Works with names or IP addresses.

From: Ryan Milton [mailto:***@mvsusa.com]
Sent: Tuesday, September 24, 2013 4:58 PM
To: Hughes, Doug; Kishore Rajani; rancid-***@googlegroups.com<mailto:rancid-***@googlegroups.com>
Cc: ***@novidys.com<mailto:***@novidys.com>; rancid-***@shrubbery.net<mailto:rancid-***@shrubbery.net>
Subject: RE: [rancid] Palo Alto Networks

I would certainly be interested in adding PAN devices to Rancid. I thought that they couldn't be read. That is what I've found with my HP switches-but that is another matter. Any ideas on getting PAN devices read by Rancid would be useful.

Regards,
Ryan Milton

From: rancid-discuss-***@shrubbery.net<mailto:rancid-discuss-***@shrubbery.net> [mailto:rancid-discuss-***@shrubbery.net] On Behalf Of Hughes, Doug
Sent: Tuesday, September 24, 2013 12:26 PM
To: Kishore Rajani; rancid-***@googlegroups.com<mailto:rancid-***@googlegroups.com>
Cc: ***@novidys.com<mailto:***@novidys.com>; rancid-***@shrubbery.net<mailto:rancid-***@shrubbery.net>
Subject: Re: [rancid] Palo Alto Networks

Yes, I have working panlogin and panrancid and have contributed them upstream. Have you not been able to get them to work?


From: rancid-discuss-***@shrubbery.net<mailto:rancid-discuss-***@shrubbery.net> [mailto:rancid-discuss-***@shrubbery.net] On Behalf Of Kishore Rajani
Sent: Monday, September 23, 2013 9:52 AM
To: rancid-***@googlegroups.com<mailto:rancid-***@googlegroups.com>
Cc: ***@novidys.com<mailto:***@novidys.com>; rancid-***@shrubbery.net<mailto:rancid-***@shrubbery.net>
Subject: Re: [rancid] Palo Alto Networks

HI,

did you manage to get the RANCID running with PAN?

Regards,
Kishore

On Thursday, 29 March 2012 13:53:33 UTC+1, Guillaume Dupuis wrote:
Nate Beck <Nate.Beck <at> jivesoftware.com<http://jivesoftware.com>> writes:

>
>
> Has anyone on the list worked with Palo Alto Network firewalls and Rancid? I
was wondering if anyone has created a *login for them.
> Thanks-------------------
> Nathan BeckSr. IT Engineer
> Jive Software
> 503.972.9024

Hi Nate,

Did you find a *login script for PAN?

Thanks,

Guillaume Dupuis
Kishore Rajani
2013-09-28 17:56:56 UTC
Permalink
Think you have to do
bin/panlogin device-name

Regards,
Kishore
On 28 Sep 2013 18:49, "Ryan Milton" <***@mvsusa.com> wrote:

> You ask a few questions. Most of my scripts seem to work, like jrancid,
> nrancid. Hrancid (for hp?) doesn't seem to work as I get "failed to login"
> errors.
>
> Does it work if you run panrancid directly on the command line from the
> bin directory?
>
> -->not sure I know how to do this.
>
> Ryan Milton
> MVS Network Manager
> O: 201-447-1505 x124
> C: 862-249-5230
> ------------------------------
> *From:* Hughes, Doug <***@DEShawResearch.com>
> *Sent:* Friday, September 27, 2013 3:57:58 PM
> *To:* Ryan Milton; Kishore Rajani
> *Cc:* ***@novidys.com; rancid-***@shrubbery.net
> *Subject:* RE: [rancid] Palo Alto Networks
>
>
> I have perl 5.8.8. I’m not sure why that would make a significant
> difference, though.
>
>
>
> There are many used of defined in the perl code.. So why would it pick
> that one? (semi-rhetorical)
>
>
>
> It appears to be complaining about the first use of defined. Do other
> rancid files work ok? ProcessHistory is just lifted from another one,
> originally.. Does the crancid or hprancid work ok?
>
>
>
> Do you have access to an older Perl for testing?
>
>
>
> Does it work if you run panrancid directly on the command line from the
> bin directory?
>
>
>
>
>
> *From:* Ryan Milton [mailto:***@mvsusa.com]
> *Sent:* Friday, September 27, 2013 1:23 PM
> *To:* Hughes, Doug; Kishore Rajani
> *Cc:* ***@novidys.com; rancid-***@shrubbery.net
> *Subject:* RE: [rancid] Palo Alto Networks
>
>
>
> So, the Perl version is perl 5, version 14, subversion 2 (v5.14.2) built
> for x86_64-linux-gnu-thread-multi
>
>
>
> And
>
>
>
> ***@ObserviumNYC:~$ sum /usr/lib/rancid/bin/panrancid
>
> 14180 9
>
>
>
> Regards,
>
> Ryan Milton
>
> MVS Network Manager
>
> o: 201-447-1505 x124
>
> c: 862-249-5230
>
> www.mvsusa.com
>
> [image: MVS final logo GOOD very small]
>
>
>
> *From:* Hughes, Doug [mailto:***@DEShawResearch.com<***@DEShawResearch.com>]
>
> *Sent:* Friday, September 27, 2013 11:15 AM
> *To:* Ryan Milton; Kishore Rajani
> *Cc:* ***@novidys.com; rancid-***@shrubbery.net
> *Subject:* RE: [rancid] Palo Alto Networks
>
>
>
> What version of Perl are you using? That looks like a Perl error. Also, I
> don’t have a define(%hash) at line 53 in the one I sent you.
>
>
>
> What does ‘sum /usr/lib/rancid/bin/panrancid’ say?
>
> It should say
>
> 14180 9
>
>
>
>
>
> *From:* Ryan Milton [mailto:***@mvsusa.com <***@mvsusa.com>]
> *Sent:* Friday, September 27, 2013 11:08 AM
> *To:* Hughes, Doug; Kishore Rajani
> *Cc:* ***@novidys.com; rancid-***@shrubbery.net
> *Subject:* RE: [rancid] Palo Alto Networks
>
>
>
> Hi Doug,
>
>
>
> So I am testing your scripts. I got one error:
>
> Trying to get all of the configs.
>
> defined(%hash) is deprecated at /usr/lib/rancid/bin/panrancid line 53.
>
> (Maybe you should just omit the defined()?)
>
> Paloaltofw1: missed cmd(s): show config running, set…..
>
>
>
> Is there a fix for this? I figure the code is just out of date?
>
>
>
> Regards,
>
> Ryan Milton
>
> MVS Network Manager
>
> o: 201-447-1505 x124
>
> c: 862-249-5230
>
> www.mvsusa.com
>
> [image: MVS final logo GOOD very small]
>
>
>
> *From:* Hughes, Doug [mailto:***@DEShawResearch.com<***@DEShawResearch.com>]
>
> *Sent:* Tuesday, September 24, 2013 5:02 PM
> *To:* Ryan Milton; Kishore Rajani; rancid-***@googlegroups.com
> *Cc:* ***@novidys.com; rancid-***@shrubbery.net
> *Subject:* RE: [rancid] Palo Alto Networks
>
>
>
> Sure they can. I do it for 3 of them right now.
>
>
>
> Attached. Set your ‘switch type’ to paloalto. Works with names or IP
> addresses.
>
>
>
> *From:* Ryan Milton [mailto:***@mvsusa.com <***@mvsusa.com>]
> *Sent:* Tuesday, September 24, 2013 4:58 PM
> *To:* Hughes, Doug; Kishore Rajani; rancid-***@googlegroups.com
> *Cc:* ***@novidys.com; rancid-***@shrubbery.net
> *Subject:* RE: [rancid] Palo Alto Networks
>
>
>
> I would certainly be interested in adding PAN devices to Rancid. I thought
> that they couldn’t be read. That is what I’ve found with my HP switches—but
> that is another matter. Any ideas on getting PAN devices read by Rancid
> would be useful.
>
>
>
> Regards,
>
> Ryan Milton
>
>
>
> *From:* rancid-discuss-***@shrubbery.net [
> mailto:rancid-discuss-***@shrubbery.net<rancid-discuss-***@shrubbery.net>]
> *On Behalf Of *Hughes, Doug
> *Sent:* Tuesday, September 24, 2013 12:26 PM
> *To:* Kishore Rajani; rancid-***@googlegroups.com
> *Cc:* ***@novidys.com; rancid-***@shrubbery.net
> *Subject:* Re: [rancid] Palo Alto Networks
>
>
>
> Yes, I have working panlogin and panrancid and have contributed them
> upstream. Have you not been able to get them to work?
>
>
>
>
>
> *From:* rancid-discuss-***@shrubbery.net [
> mailto:rancid-discuss-***@shrubbery.net<rancid-discuss-***@shrubbery.net>]
> *On Behalf Of *Kishore Rajani
> *Sent:* Monday, September 23, 2013 9:52 AM
> *To:* rancid-***@googlegroups.com
> *Cc:* ***@novidys.com; rancid-***@shrubbery.net
> *Subject:* Re: [rancid] Palo Alto Networks
>
>
>
> HI,
>
> did you manage to get the RANCID running with PAN?
>
> Regards,
> Kishore
>
> On Thursday, 29 March 2012 13:53:33 UTC+1, Guillaume Dupuis wrote:
>
> Nate Beck <Nate.Beck <at> jivesoftware.com> writes:
>
> >
> >
> > Has anyone on the list worked with Palo Alto Network firewalls and
> Rancid? I
> was wondering if anyone has created a *login for them.
> > Thanks-------------------
> > Nathan BeckSr. IT Engineer
> > Jive Software
> > 503.972.9024
>
> Hi Nate,
>
> Did you find a *login script for PAN?
>
> Thanks,
>
> Guillaume Dupuis
>
> _______________________________________________
> Rancid-discuss mailing list
> Rancid-***@shrubbery.net
> http://www.shrubbery.net/mailman/listinfo.cgi/rancid-discuss
>
Tim Eberhard
2013-09-24 17:39:40 UTC
Permalink
I used panlogin and panrancid, although if I recall correctly I had to
modify it slightly to work. I did those and aruba's at the same time so I
can't recall which one was the pita.

-Tim Eberhard


On Tue, Sep 24, 2013 at 9:25 AM, Hughes, Doug <
***@deshawresearch.com> wrote:

> Yes, I have working panlogin and panrancid and have contributed them
> upstream. Have you not been able to get them to work?****
>
> ** **
>
> ** **
>
> *From:* rancid-discuss-***@shrubbery.net [mailto:
> rancid-discuss-***@shrubbery.net] *On Behalf Of *Kishore Rajani
> *Sent:* Monday, September 23, 2013 9:52 AM
> *To:* rancid-***@googlegroups.com
> *Cc:* ***@novidys.com; rancid-***@shrubbery.net
> *Subject:* Re: [rancid] Palo Alto Networks****
>
> ** **
>
> HI,
>
> did you manage to get the RANCID running with PAN?
>
> Regards,
> Kishore
>
> On Thursday, 29 March 2012 13:53:33 UTC+1, Guillaume Dupuis wrote:****
>
> Nate Beck <Nate.Beck <at> jivesoftware.com> writes:****
>
> >
> >
> > Has anyone on the list worked with Palo Alto Network firewalls and
> Rancid? I
> was wondering if anyone has created a *login for them.
> > Thanks-------------------
> > Nathan BeckSr. IT Engineer
> > Jive Software
> > 503.972.9024****
>
> Hi Nate,****
>
> Did you find a *login script for PAN?****
>
> Thanks,****
>
> Guillaume Dupuis****
>
> _______________________________________________
> Rancid-discuss mailing list
> Rancid-***@shrubbery.net
> http://www.shrubbery.net/mailman/listinfo.cgi/rancid-discuss****
>
> _______________________________________________
> Rancid-discuss mailing list
> Rancid-***@shrubbery.net
> http://www.shrubbery.net/mailman/listinfo/rancid-discuss
>
Konstantin Konstantin
2014-11-11 10:38:57 UTC
Permalink
fix it?

суббПта, 18 яМваря 2014 г., 18:45:03 UTC+4 пПльзПватель Maria Jose Erquiaga
МапОсал:
>
> Hi Everyone!
>
> I'm having the same problem, but with Mikrotik.
>
> I follow these instructions : http://falz.net/tech/rancid-mikrotik
>
> and I have this error when I run Rancid :
> exec failed router manufacturer mikrotik: No such file or directory
>
> I'm using these files as well : http://falz.net/static/rancid/ and pearl5
> is installed in my ubuntu server.
> I have created the /var/lib/rancid/ap/router.db file as well with the IP
> of my devices
> I have access to my device but I can't obtain the config file, I can see a
> file in /var/lib/rancid/all/configs but it is empty.-
>
> Thanks in advance
>
>
>
>
> Le jeudi 29 mars 2012 09:53:33 UTC-3, Guillaume Dupuis a écrit :
>>
>> Nate Beck <Nate.Beck <at> jivesoftware.com> writes:
>>
>> >
>> >
>> > Has anyone on the list worked with Palo Alto Network firewalls and
>> Rancid? I
>> was wondering if anyone has created a *login for them.
>> > Thanks-------------------
>> > Nathan BeckSr. IT Engineer
>> > Jive Software
>> > 503.972.9024
>>
>> Hi Nate,
>>
>> Did you find a *login script for PAN?
>>
>> Thanks,
>>
>> Guillaume Dupuis
>>
>> _______________________________________________
>> Rancid-discuss mailing list
>> Rancid-***@shrubbery.net
>> http://www.shrubbery.net/mailman/listinfo.cgi/rancid-discuss
>>
>>
Hughes, Doug
2014-11-13 22:34:28 UTC
Permalink
To answer the original question (which somehow I missed), yes, I wrote a panrancid and panlogin a couple of years ago. It should be out there somewhere, but I can email the text files too. I have not tested it with rancid 3. Though. It works fine with rancid 2.3


From: Rancid-discuss [mailto:rancid-discuss-***@shrubbery.net] On Behalf Of Konstantin Konstantin
Sent: Tuesday, November 11, 2014 5:39 AM
To: rancid-***@googlegroups.com
Cc: ***@novidys.com; rancid-***@shrubbery.net
Subject: Re: [rancid] Palo Alto Networks

fix it?

суббПта, 18 яМваря 2014 г., 18:45:03 UTC+4 пПльзПватель Maria Jose Erquiaga МапОсал:
Hi Everyone!

I'm having the same problem, but with Mikrotik.

I follow these instructions : http://falz.net/tech/rancid-mikrotik

and I have this error when I run Rancid :
exec failed router manufacturer mikrotik: No such file or directory

I'm using these files as well : http://falz.net/static/rancid/ and pearl5 is installed in my ubuntu server.
I have created the /var/lib/rancid/ap/router.db file as well with the IP of my devices
I have access to my device but I can't obtain the config file, I can see a file in /var/lib/rancid/all/configs but it is empty.-

Thanks in advance




Le jeudi 29 mars 2012 09:53:33 UTC-3, Guillaume Dupuis a écrit :
Nate Beck <Nate.Beck <at> jivesoftware.com<http://jivesoftware.com>> writes:

>
>
> Has anyone on the list worked with Palo Alto Network firewalls and Rancid? I
was wondering if anyone has created a *login for them.
> Thanks-------------------
> Nathan BeckSr. IT Engineer
> Jive Software
> 503.972.9024

Hi Nate,

Did you find a *login script for PAN?

Thanks,

Guillaume Dupuis

_______________________________________________
Rancid-discuss mailing list
Rancid-***@shrubbery.net<mailto:Rancid-***@shrubbery.net>
http://www.shrubbery.net/mailman/listinfo.cgi/rancid-discuss
heasley
2014-11-18 20:56:37 UTC
Permalink
Thu, Nov 13, 2014 at 10:34:28PM +0000, Hughes, Doug:
> To answer the original question (which somehow I missed), yes, I wrote a panrancid and panlogin a couple of years ago. It should be out there somewhere, but I can email the text files too. I have not tested it with rancid 3. Though. It works fine with rancid 2.3

ftp://ftp.shrubbery.net/pub/rancid/contrib/paloalto.tgz is the last version
that I'd seen, but I have no manner of testing it, nor do I know what it
would have to do with Mikrotik. But, the 2.x scripts should with with 3.x;
see the definition for alteon in the 3.x's etc/rancid.types.base.

for the mikrotik issue below, look for errors in the log file for the group.

> From: Rancid-discuss [mailto:rancid-discuss-***@shrubbery.net] On Behalf Of Konstantin Konstantin
> Sent: Tuesday, November 11, 2014 5:39 AM
> To: rancid-***@googlegroups.com
> Cc: ***@novidys.com; rancid-***@shrubbery.net
> Subject: Re: [rancid] Palo Alto Networks
>
> fix it?
>
> суббота, 18 января 2014 г., 18:45:03 UTC+4 пользователь Maria Jose Erquiaga написал:
> Hi Everyone!
>
> I'm having the same problem, but with Mikrotik.
>
> I follow these instructions : http://falz.net/tech/rancid-mikrotik
>
> and I have this error when I run Rancid :
> exec failed router manufacturer mikrotik: No such file or directory
>
> I'm using these files as well : http://falz.net/static/rancid/ and pearl5 is installed in my ubuntu server.
> I have created the /var/lib/rancid/ap/router.db file as well with the IP of my devices
> I have access to my device but I can't obtain the config file, I can see a file in /var/lib/rancid/all/configs but it is empty.-
>
> Thanks in advance
>
>
>
>
> Le jeudi 29 mars 2012 09:53:33 UTC-3, Guillaume Dupuis a écrit :
> Nate Beck <Nate.Beck <at> jivesoftware.com<http://jivesoftware.com>> writes:
>
> >
> >
> > Has anyone on the list worked with Palo Alto Network firewalls and Rancid? I
> was wondering if anyone has created a *login for them.
> > Thanks-------------------
> > Nathan BeckSr. IT Engineer
> > Jive Software
> > 503.972.9024
>
> Hi Nate,
>
> Did you find a *login script for PAN?
>
> Thanks,
>
> Guillaume Dupuis
>
> _______________________________________________
> Rancid-discuss mailing list
> Rancid-***@shrubbery.net<mailto:Rancid-***@shrubbery.net>
> http://www.shrubbery.net/mailman/listinfo.cgi/rancid-discuss

> _______________________________________________
> Rancid-discuss mailing list
> Rancid-***@shrubbery.net
> http://www.shrubbery.net/mailman/listinfo/rancid-discuss
Peter Jackson
2014-11-20 01:33:14 UTC
Permalink
We have Doug's scripts running in RANCID 3.1 without issue.



> On Nov 18, 2014, at 3:56 PM, heasley <***@shrubbery.net> wrote:
>
> Thu, Nov 13, 2014 at 10:34:28PM +0000, Hughes, Doug:
>> To answer the original question (which somehow I missed), yes, I wrote a panrancid and panlogin a couple of years ago. It should be out there somewhere, but I can email the text files too. I have not tested it with rancid 3. Though. It works fine with rancid 2.3
>
> ftp://ftp.shrubbery.net/pub/rancid/contrib/paloalto.tgz is the last version
> that I'd seen, but I have no manner of testing it, nor do I know what it
> would have to do with Mikrotik. But, the 2.x scripts should with with 3.x;
> see the definition for alteon in the 3.x's etc/rancid.types.base.
>
> for the mikrotik issue below, look for errors in the log file for the group.
>
>> From: Rancid-discuss [mailto:rancid-discuss-***@shrubbery.net] On Behalf Of Konstantin Konstantin
>> Sent: Tuesday, November 11, 2014 5:39 AM
>> To: rancid-***@googlegroups.com
>> Cc: ***@novidys.com; rancid-***@shrubbery.net
>> Subject: Re: [rancid] Palo Alto Networks
>>
>> fix it?
>>
>> суббота, 18 января 2014 г., 18:45:03 UTC+4 пользователь Maria Jose Erquiaga написал:
>> Hi Everyone!
>>
>> I'm having the same problem, but with Mikrotik.
>>
>> I follow these instructions : http://falz.net/tech/rancid-mikrotik
>>
>> and I have this error when I run Rancid :
>> exec failed router manufacturer mikrotik: No such file or directory
>>
>> I'm using these files as well : http://falz.net/static/rancid/ and pearl5 is installed in my ubuntu server.
>> I have created the /var/lib/rancid/ap/router.db file as well with the IP of my devices
>> I have access to my device but I can't obtain the config file, I can see a file in /var/lib/rancid/all/configs but it is empty.-
>>
>> Thanks in advance
>>
>>
>>
>>
>> Le jeudi 29 mars 2012 09:53:33 UTC-3, Guillaume Dupuis a écrit :
>> Nate Beck <Nate.Beck <at> jivesoftware.com<http://jivesoftware.com>> writes:
>>
>>>
>>>
>>> Has anyone on the list worked with Palo Alto Network firewalls and Rancid? I
>> was wondering if anyone has created a *login for them.
>>> Thanks-------------------
>>> Nathan BeckSr. IT Engineer
>>> Jive Software
>>> 503.972.9024
>>
>> Hi Nate,
>>
>> Did you find a *login script for PAN?
>>
>> Thanks,
>>
>> Guillaume Dupuis
>>
>> _______________________________________________
>> Rancid-discuss mailing list
>> Rancid-***@shrubbery.net<mailto:Rancid-***@shrubbery.net>
>> http://www.shrubbery.net/mailman/listinfo.cgi/rancid-discuss
>
>> _______________________________________________
>> Rancid-discuss mailing list
>> Rancid-***@shrubbery.net
>> http://www.shrubbery.net/mailman/listinfo/rancid-discuss
>
> _______________________________________________
> Rancid-discuss mailing list
> Rancid-***@shrubbery.net
> http://www.shrubbery.net/mailman/listinfo/rancid-discuss
Tom Simpson
2013-09-25 13:09:57 UTC
Permalink
Jethro R Binks
2013-09-27 16:19:22 UTC
Permalink
And for the HP models you sent me privately, you would need to set the
type to "hp" in the same file, so it would have:

devicename:hp:up

or similar.

Jethro.



On Wed, 25 Sep 2013, Tom Simpson wrote:

> After the switch name or IP you should have a :paloalto:up in the config
> file as well.
>
> Just like all of your CatOS devices would have a :cisco:up  after all of
> them
.
>
>
>
> -- 
> Thanks,
>
> Tom Simpson
> LAN/WAN Engineer
> Forcht Group of Kentucky
> 859.259.9700 x538
>
> "We all knew there was just one way to improve our odds for survival:
> train, train, train. Sometimes, if your training is properly intense it
> will kill you. More often -- much, much more often -- it will save your
> life."  - Richard Marcinko, former US Navy SEAL Team Commander
>
> From: Ryan Milton <***@mvsusa.com>
> Date: Wednesday, September 25, 2013 8:52 AM
> To: "Hughes, Doug" <***@DEShawResearch.com>, Kishore Rajani
> <***@gmail.com>, "rancid-***@googlegroups.com"
> <rancid-***@googlegroups.com>
> Cc: "***@novidys.com" <***@novidys.com>,
> "rancid-***@shrubbery.net" <rancid-***@shrubbery.net>
> Subject: Re: [rancid] Palo Alto Networks
>
> Wow! This is great. I am still quite a noob at Rancid. When you say “switch
> type,” what do you mean by that? That is not in these files, is it?
>
>  
>
> Regards,
>
> Ryan Milton
>
> MVS Network Manager
>
> o: 201-447-1505 x124
>
> c: 862-249-5230
>
> www.mvsusa.com
>
> MVS final logo GOOD very small
>
>  
>
> From: Hughes, Doug [mailto:***@DEShawResearch.com]
> Sent: Tuesday, September 24, 2013 5:02 PM
> To: Ryan Milton; Kishore Rajani; rancid-***@googlegroups.com
> Cc: ***@novidys.com; rancid-***@shrubbery.net
> Subject: RE: [rancid] Palo Alto Networks
>
>  
>
> Sure they can. I do it for 3 of them right now.
>
>  
>
> Attached. Set your ‘switch type’ to paloalto. Works with names or IP
> addresses.
>
>  
>
> From: Ryan Milton [mailto:***@mvsusa.com]
> Sent: Tuesday, September 24, 2013 4:58 PM
> To: Hughes, Doug; Kishore Rajani; rancid-***@googlegroups.com
> Cc: ***@novidys.com; rancid-***@shrubbery.net
> Subject: RE: [rancid] Palo Alto Networks
>
>  
>
> I would certainly be interested in adding PAN devices to Rancid. I thought
> that they couldn’t be read. That is what I’ve found with my HP switches—but
> that is another matter. Any ideas on getting PAN devices read by Rancid
> would be useful.
>
>  
>
> Regards,
>
> Ryan Milton
>
>  
>
> From:rancid-discuss-***@shrubbery.net
> [mailto:rancid-discuss-***@shrubbery.net] On Behalf Of Hughes, Doug
> Sent: Tuesday, September 24, 2013 12:26 PM
> To: Kishore Rajani; rancid-***@googlegroups.com
> Cc: ***@novidys.com; rancid-***@shrubbery.net
> Subject: Re: [rancid] Palo Alto Networks
>
>  
>
> Yes, I have working panlogin and panrancid and have contributed them
> upstream. Have you not been able to get them to work?
>
>  
>
>  
>
> From:rancid-discuss-***@shrubbery.net
> [mailto:rancid-discuss-***@shrubbery.net] On Behalf Of Kishore Rajani
> Sent: Monday, September 23, 2013 9:52 AM
> To: rancid-***@googlegroups.com
> Cc: ***@novidys.com; rancid-***@shrubbery.net
> Subject: Re: [rancid] Palo Alto Networks
>
>  
>
> HI,
>
> did you manage to get the RANCID running with PAN?
>
> Regards,
> Kishore
>
> On Thursday, 29 March 2012 13:53:33 UTC+1, Guillaume Dupuis wrote:
>
> Nate Beck <Nate.Beck <at> jivesoftware.com> writes:
>
> >
> >
> > Has anyone on the list worked with Palo Alto Network firewalls and Rancid?
>  I
> was wondering if anyone has created a *login for them.
> > Thanks-------------------
> > Nathan BeckSr. IT Engineer
> > Jive Software
> > 503.972.9024
>
> Hi Nate,
>
> Did you find a *login script for PAN?
>
> Thanks,
>
> Guillaume Dupuis
>
> _______________________________________________
> Rancid-discuss mailing list
> Rancid-***@shrubbery.net
> http://www.shrubbery.net/mailman/listinfo.cgi/rancid-discuss
>
>
> ____________________________________________________________________________
>
> CONFIDENTIALITY NOTICE:
> This message contains confidential information and is intended only for the
> individual named. If you are not the named addressee you should not
> disseminate, distribute or copy this e-mail. Please notify the sender
> immediately by e-mail if you have received this e-mail by mistake and delete
> this e-mail from your system. E-mail transmission cannot be guaranteed to be
> secure or error-free as information could be intercepted, corrupted, lost,
> destroyed, arrive late or incomplete, or contain viruses. The sender
> therefore does not accept liability for any errors or omissions in the
> contents of this message, which arise as a result of e-mail transmission. If
> verification is required please request a hard-copy version.
>
> Forcht Group IT, 2400 South Main Street, Corbin, Ky.
>
>

. . . . . . . . . . . . . . . . . . . . . . . . .
Jethro R Binks, Network Manager,
Information Services Directorate, University Of Strathclyde, Glasgow, UK

The University of Strathclyde is a charitable body, registered in
Scotland, number SC015263.
Ryan Milton
2013-09-27 17:30:17 UTC
Permalink
Yes, what I have for the HP devices, is IPAddress:hp:up
The problem is that even though I have it like that, I keep getting a "clogin error: Error: Couldn't login"

When I test with the script (below) it works:

***@ObserviumNYC:~$ /usr/lib/rancid/bin/hlogin -f /var/lib/rancid/.cloginrc hpswitch5


spawn hpuifilter -- ssh -c 3des -x -l rancid 94.229.14.250

*** truncated***

***@94.229.14.250's password:

Press any key to continuesw-1.ams5#
sw-1.ams5# show conf

Startup configuration:

; J9088A Configuration Edi***trunc***



Regards,
Ryan Milton
MVS Network Manager
o: 201-447-1505 x124
c: 862-249-5230
www.mvsusa.com


> -----Original Message-----
> From: Jethro R Binks [mailto:***@strath.ac.uk]
> Sent: Friday, September 27, 2013 12:19 PM
> To: Ryan Milton
> Cc: rancid-***@shrubbery.net
> Subject: Re: [rancid] Palo Alto Networks
>
> And for the HP models you sent me privately, you would need to set the
> type to "hp" in the same file, so it would have:
>
> devicename:hp:up
>
> or similar.
>
> Jethro.
>
>
>
> On Wed, 25 Sep 2013, Tom Simpson wrote:
>
> > After the switch name or IP you should have a :paloalto:up in the
> > config file as well.
> >
> > Just like all of your CatOS devices would have a :cisco:up  after all
> > of them….
> >
> >
> >
> > --
> > Thanks,
> >
> > Tom Simpson
> > LAN/WAN Engineer
> > Forcht Group of Kentucky
> > 859.259.9700 x538
> >
> > "We all knew there was just one way to improve our odds for survival:
> > train, train, train. Sometimes, if your training is properly intense
> > it will kill you. More often -- much, much more often -- it will save
> > your life."  - Richard Marcinko, former US Navy SEAL Team Commander
> >
> > From: Ryan Milton <***@mvsusa.com>
> > Date: Wednesday, September 25, 2013 8:52 AM
> > To: "Hughes, Doug" <***@DEShawResearch.com>, Kishore
> Rajani
> > <***@gmail.com>, "rancid-***@googlegroups.com"
> > <rancid-***@googlegroups.com>
> > Cc: "***@novidys.com" <***@novidys.com>,
> > "rancid-***@shrubbery.net" <rancid-***@shrubbery.net>
> > Subject: Re: [rancid] Palo Alto Networks
> >
> > Wow! This is great. I am still quite a noob at Rancid. When you say
> > “switch type,” what do you mean by that? That is not in these files, is it?
> >
> >
> >
> > Regards,
> >
> > Ryan Milton
> >
> > MVS Network Manager
> >
> > o: 201-447-1505 x124
> >
> > c: 862-249-5230
> >
> > www.mvsusa.com
> >
> > MVS final logo GOOD very small
> >
> >
> >
> > From: Hughes, Doug [mailto:***@DEShawResearch.com]
> > Sent: Tuesday, September 24, 2013 5:02 PM
> > To: Ryan Milton; Kishore Rajani; rancid-***@googlegroups.com
> > Cc: ***@novidys.com; rancid-***@shrubbery.net
> > Subject: RE: [rancid] Palo Alto Networks
> >
> >
> >
> > Sure they can. I do it for 3 of them right now.
> >
> >
> >
> > Attached. Set your ‘switch type’ to paloalto. Works with names or IP
> > addresses.
> >
> >
> >
> > From: Ryan Milton [mailto:***@mvsusa.com]
> > Sent: Tuesday, September 24, 2013 4:58 PM
> > To: Hughes, Doug; Kishore Rajani; rancid-***@googlegroups.com
> > Cc: ***@novidys.com; rancid-***@shrubbery.net
> > Subject: RE: [rancid] Palo Alto Networks
> >
> >
> >
> > I would certainly be interested in adding PAN devices to Rancid. I
> > thought that they couldn’t be read. That is what I’ve found with my HP
> > switches—but that is another matter. Any ideas on getting PAN devices
> > read by Rancid would be useful.
> >
> >
> >
> > Regards,
> >
> > Ryan Milton
> >
> >
> >
> > From:rancid-discuss-***@shrubbery.net
> > [mailto:rancid-discuss-***@shrubbery.net] On Behalf Of Hughes,
> > Doug
> > Sent: Tuesday, September 24, 2013 12:26 PM
> > To: Kishore Rajani; rancid-***@googlegroups.com
> > Cc: ***@novidys.com; rancid-***@shrubbery.net
> > Subject: Re: [rancid] Palo Alto Networks
> >
> >
> >
> > Yes, I have working panlogin and panrancid and have contributed them
> > upstream. Have you not been able to get them to work?
> >
> >
> >
> >
> >
> > From:rancid-discuss-***@shrubbery.net
> > [mailto:rancid-discuss-***@shrubbery.net] On Behalf Of Kishore
> > Rajani
> > Sent: Monday, September 23, 2013 9:52 AM
> > To: rancid-***@googlegroups.com
> > Cc: ***@novidys.com; rancid-***@shrubbery.net
> > Subject: Re: [rancid] Palo Alto Networks
> >
> >
> >
> > HI,
> >
> > did you manage to get the RANCID running with PAN?
> >
> > Regards,
> > Kishore
> >
> > On Thursday, 29 March 2012 13:53:33 UTC+1, Guillaume Dupuis wrote:
> >
> > Nate Beck <Nate.Beck <at> jivesoftware.com> writes:
> >
> > >
> > >
> > > Has anyone on the list worked with Palo Alto Network firewalls and
> Rancid?
> >  I
> > was wondering if anyone has created a *login for them.
> > > Thanks-------------------
> > > Nathan BeckSr. IT Engineer
> > > Jive Software
> > > 503.972.9024
> >
> > Hi Nate,
> >
> > Did you find a *login script for PAN?
> >
> > Thanks,
> >
> > Guillaume Dupuis
> >
> > _______________________________________________
> > Rancid-discuss mailing list
> > Rancid-***@shrubbery.net
> > http://www.shrubbery.net/mailman/listinfo.cgi/rancid-discuss
> >
> >
> >
> __________________________________________________________
> ____________
> > ______
> >
> > CONFIDENTIALITY NOTICE:
> > This message contains confidential information and is intended only
> > for the individual named. If you are not the named addressee you
> > should not disseminate, distribute or copy this e-mail. Please notify
> > the sender immediately by e-mail if you have received this e-mail by
> > mistake and delete this e-mail from your system. E-mail transmission
> > cannot be guaranteed to be secure or error-free as information could
> > be intercepted, corrupted, lost, destroyed, arrive late or incomplete,
> > or contain viruses. The sender therefore does not accept liability for
> > any errors or omissions in the contents of this message, which arise
> > as a result of e-mail transmission. If verification is required please request a
> hard-copy version.
> >
> > Forcht Group IT, 2400 South Main Street, Corbin, Ky.
> >
> >
>
> . . . . . . . . . . . . . . . . . . . . . . . . .
> Jethro R Binks, Network Manager,
> Information Services Directorate, University Of Strathclyde, Glasgow, UK
>
> The University of Strathclyde is a charitable body, regis
Ryan Milton
2013-09-28 22:17:21 UTC
Permalink
When I go to the executables directory, /usr/lib/rancid/bin/ and panrancid <device>, or jrancid <device>, etc, I get the same thing: "panrancid: command not found", or "jrancid: command not found." so if I run the panlogin, jlogin, etc, I get into the device, but that’s it.

As I wrote that above message, I just did a "rancid-run" and DID get a revision to my Palo Alto test device. So I guess that is good. I don't really know if that will work here forward, but does that mean that it is working?

Sorry to sound like the noob that I am.

Ryan

From: <Hughes>, Doug <***@DEShawResearch.com<mailto:***@DEShawResearch.com>>
Date: Saturday, September 28, 2013 1:52 PM
To: Ryan Milton <***@mvsusa.com<mailto:***@mvsusa.com>>, Kishore Rajani <***@gmail.com<mailto:***@gmail.com>>
Cc: "***@novidys.com<mailto:***@novidys.com>" <***@novidys.com<mailto:***@novidys.com>>, "rancid-***@shrubbery.net<mailto:rancid-***@shrubbery.net>" <rancid-***@shrubbery.net<mailto:rancid-***@shrubbery.net>>
Subject: RE: [rancid] Palo Alto Networks

1) Become the rancid user
2) make sure that panrancid and panlogin are in your path
3) “panrancid <device>”
After you run it, if it works, you should see a file <device>.new in the current directory.

If it fails, paste the results of this: “panrancid –d <device>”

From: Ryan Milton [mailto:***@mvsusa.com]
Sent: Saturday, September 28, 2013 1:49 PM
To: Hughes, Doug; Kishore Rajani
Cc: ***@novidys.com<mailto:***@novidys.com>; rancid-***@shrubbery.net<mailto:rancid-***@shrubbery.net>
Subject: RE: [rancid] Palo Alto Networks

You ask a few questions. Most of my scripts seem to work, like jrancid, nrancid. Hrancid (for hp?) doesn't seem to work as I get "failed to login" errors.

Does it work if you run panrancid directly on the command line from the bin directory?

-->not sure I know how to do this.

Ryan Milton
MVS Network Manager
O: 201-447-1505 x124
C: 862-249-5230
________________________________
From: Hughes, Doug <***@DEShawResearch.com<mailto:***@DEShawResearch.com>>
Sent: Friday, September 27, 2013 3:57:58 PM
To: Ryan Milton; Kishore Rajani
Cc: ***@novidys.com<mailto:***@novidys.com>; rancid-***@shrubbery.net<mailto:rancid-***@shrubbery.net>
Subject: RE: [rancid] Palo Alto Networks

I have perl 5.8.8. I’m not sure why that would make a significant difference, though.

There are many used of defined in the perl code.. So why would it pick that one? (semi-rhetorical)

It appears to be complaining about the first use of defined. Do other rancid files work ok? ProcessHistory is just lifted from another one, originally.. Does the crancid or hprancid work ok?

Do you have access to an older Perl for testing?

Does it work if you run panrancid directly on the command line from the bin directory?


From: Ryan Milton [mailto:***@mvsusa.com]
Sent: Friday, September 27, 2013 1:23 PM
To: Hughes, Doug; Kishore Rajani
Cc: ***@novidys.com<mailto:***@novidys.com>; rancid-***@shrubbery.net<mailto:rancid-***@shrubbery.net>
Subject: RE: [rancid] Palo Alto Networks

So, the Perl version is perl 5, version 14, subversion 2 (v5.14.2) built for x86_64-linux-gnu-thread-multi

And

***@ObserviumNYC:~$ sum /usr/lib/rancid/bin/panrancid
14180 9

Regards,
Ryan Milton
MVS Network Manager
o: 201-447-1505 x124
c: 862-249-5230
www.mvsusa.com<http://www.mvsusa.com/>
[MVS final logo GOOD very small]

From: Hughes, Doug [mailto:***@DEShawResearch.com]
Sent: Friday, September 27, 2013 11:15 AM
To: Ryan Milton; Kishore Rajani
Cc: ***@novidys.com<mailto:***@novidys.com>; rancid-***@shrubbery.net<mailto:rancid-***@shrubbery.net>
Subject: RE: [rancid] Palo Alto Networks

What version of Perl are you using? That looks like a Perl error. Also, I don’t have a define(%hash) at line 53 in the one I sent you.

What does ‘sum /usr/lib/rancid/bin/panrancid’ say?
It should say
14180 9


From: Ryan Milton [mailto:***@mvsusa.com]
Sent: Friday, September 27, 2013 11:08 AM
To: Hughes, Doug; Kishore Rajani
Cc: ***@novidys.com<mailto:***@novidys.com>; rancid-***@shrubbery.net<mailto:rancid-***@shrubbery.net>
Subject: RE: [rancid] Palo Alto Networks

Hi Doug,

So I am testing your scripts. I got one error:
Trying to get all of the configs.
defined(%hash) is deprecated at /usr/lib/rancid/bin/panrancid line 53.
(Maybe you should just omit the defined()?)
Paloaltofw1: missed cmd(s): show config running, set…..

Is there a fix for this? I figure the code is just out of date?

Regards,
Ryan Milton
MVS Network Manager
o: 201-447-1505 x124
c: 862-249-5230
www.mvsusa.com<http://www.mvsusa.com/>
[MVS final logo GOOD very small]

From: Hughes, Doug [mailto:***@DEShawResearch.com]
Sent: Tuesday, September 24, 2013 5:02 PM
To: Ryan Milton; Kishore Rajani; rancid-***@googlegroups.com<mailto:rancid-***@googlegroups.com>
Cc: ***@novidys.com<mailto:***@novidys.com>; rancid-***@shrubbery.net<mailto:rancid-***@shrubbery.net>
Subject: RE: [rancid] Palo Alto Networks

Sure they can. I do it for 3 of them right now.

Attached. Set your ‘switch type’ to paloalto. Works with names or IP addresses.

From: Ryan Milton [mailto:***@mvsusa.com]
Sent: Tuesday, September 24, 2013 4:58 PM
To: Hughes, Doug; Kishore Rajani; rancid-***@googlegroups.com<mailto:rancid-***@googlegroups.com>
Cc: ***@novidys.com<mailto:***@novidys.com>; rancid-***@shrubbery.net<mailto:rancid-***@shrubbery.net>
Subject: RE: [rancid] Palo Alto Networks

I would certainly be interested in adding PAN devices to Rancid. I thought that they couldn’t be read. That is what I’ve found with my HP switches—but that is another matter. Any ideas on getting PAN devices read by Rancid would be useful.

Regards,
Ryan Milton

From:rancid-discuss-***@shrubbery.net<mailto:rancid-discuss-***@shrubbery.net> [mailto:rancid-discuss-***@shrubbery.net] On Behalf Of Hughes, Doug
Sent: Tuesday, September 24, 2013 12:26 PM
To: Kishore Rajani; rancid-***@googlegroups.com<mailto:rancid-***@googlegroups.com>
Cc: ***@novidys.com<mailto:***@novidys.com>; rancid-***@shrubbery.net<mailto:rancid-***@shrubbery.net>
Subject: Re: [rancid] Palo Alto Networks

Yes, I have working panlogin and panrancid and have contributed them upstream. Have you not been able to get them to work?


From:rancid-discuss-***@shrubbery.net<mailto:rancid-discuss-***@shrubbery.net> [mailto:rancid-discuss-***@shrubbery.net] On Behalf Of Kishore Rajani
Sent: Monday, September 23, 2013 9:52 AM
To: rancid-***@googlegroups.com<mailto:rancid-***@googlegroups.com>
Cc: ***@novidys.com<mailto:***@novidys.com>; rancid-***@shrubbery.net<mailto:rancid-***@shrubbery.net>
Subject: Re: [rancid] Palo Alto Networks

HI,

did you manage to get the RANCID running with PAN?

Regards,
Kishore

On Thursday, 29 March 2012 13:53:33 UTC+1, Guillaume Dupuis wrote:
Nate Beck <Nate.Beck <at> jivesoftware.com<http://jivesoftware.com>> writes:

>
>
> Has anyone on the list worked with Palo Alto Network firewalls and Rancid? I
was wondering if anyone has created a *login for them.
> Thanks-------------------
> Nathan BeckSr. IT Engineer
> Jive Software
> 503.972.9024

Hi Nate,

Did you find a *login script for PAN?

Thanks,

Guillaume Dupuis
Roy
2013-09-28 22:26:51 UTC
Permalink
<html>
<head>
<meta content="text/html; charset=ISO-8859-1"
http-equiv="Content-Type">
</head>
<body text="#000000" bgcolor="#FFFFFF">
<div class="moz-cite-prefix"><br>
<br>
If you are going to issue the commands manually, make sure that
the directory (in your case&nbsp; /usr/lib/rancid/bin) is in the path<br>
<br>
On 9/28/2013 3:17 PM, Ryan Milton wrote:<br>
</div>
<blockquote cite="mid:CE6CC9CA.21FD%***@mvsusa.com"
type="cite">
<meta http-equiv="Content-Type" content="text/html;
charset=ISO-8859-1">
<div>When I go to the executables directory, /usr/lib/rancid/bin/
and panrancid &lt;device&gt;, or jrancid &lt;device&gt;, etc, I
get the same thing: "panrancid: command not found", or "jrancid:
command not found." so if I run the panlogin, jlogin, etc, I get
into the device, but that&#8217;s it.</div>
<div><br>
</div>
<div>As I wrote that above message, I just did a "rancid-run" and
DID get a revision to my Palo Alto test device. So I guess that
is good. I don't really know if that will work here forward, but
does that mean that it is working?</div>
<div><br>
</div>
<div>Sorry to sound like the noob that I am.</div>
<div><br>
</div>
<div>Ryan</div>
<div><br>
</div>
<span id="OLK_SRC_BODY_SECTION">
<div style="font-family:Calibri; font-size:11pt;
text-align:left; color:black; BORDER-BOTTOM: medium none;
BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT:
0in; PADDING-RIGHT: 0in; BORDER-TOP: #b5c4df 1pt solid;
BORDER-RIGHT: medium none; PADDING-TOP: 3pt">
<span style="font-weight:bold">From: </span>&lt;Hughes&gt;,
Doug &lt;<a moz-do-not-send="true"
href="mailto:***@DEShawResearch.com">***@DEShawResearch.com</a>&gt;<br>
<span style="font-weight:bold">Date: </span>Saturday,
September 28, 2013 1:52 PM<br>
<span style="font-weight:bold">To: </span>Ryan Milton &lt;<a
moz-do-not-send="true" href="mailto:***@mvsusa.com">***@mvsusa.com</a>&gt;,
Kishore Rajani &lt;<a moz-do-not-send="true"
href="mailto:***@gmail.com">***@gmail.com</a>&gt;<br>
<span style="font-weight:bold">Cc: </span>"<a
moz-do-not-send="true"
href="mailto:***@novidys.com">***@novidys.com</a>"
&lt;<a moz-do-not-send="true"
href="mailto:***@novidys.com">***@novidys.com</a>&gt;,
"<a moz-do-not-send="true"
href="mailto:rancid-***@shrubbery.net">rancid-***@shrubbery.net</a>"
&lt;<a moz-do-not-send="true"
href="mailto:rancid-***@shrubbery.net">rancid-***@shrubbery.net</a>&gt;<br>
<span style="font-weight:bold">Subject: </span>RE: [rancid]
Palo Alto Networks<br>
</div>
<div><br>
</div>
<div xmlns:v="urn:schemas-microsoft-com:vml"
xmlns:o="urn:schemas-microsoft-com:office:office"
xmlns:w="urn:schemas-microsoft-com:office:word"
xmlns:m="http://schemas.microsoft.com/office/2004/12/omml"
xmlns="http://www.w3.org/TR/REC-html40">
<meta name="Generator" content="Microsoft Word 14 (filtered
medium)">
<!--[if !mso]><style>v\:* {behavior:url(#default#VML);}
o\:* {behavior:url(#default#VML);}
w\:* {behavior:url(#default#VML);}
.shape {behavior:url(#default#VML);}
</style><![endif]-->
<style><!--
/* Font Definitions */
@font-face
{font-family:Calibri;
panose-1:2 15 5 2 2 2 4 3 2 4;}
@font-face
{font-family:Tahoma;
panose-1:2 11 6 4 3 5 4 4 2 4;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
{margin:0in;
margin-bottom:.0001pt;
font-size:12.0pt;
font-family:"Times New Roman","serif";}
a:link, span.MsoHyperlink
{mso-style-priority:99;
color:blue;
text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
{mso-style-priority:99;
color:purple;
text-decoration:underline;}
p
{mso-style-priority:99;
mso-margin-top-alt:auto;
margin-right:0in;
mso-margin-bottom-alt:auto;
margin-left:0in;
font-size:12.0pt;
font-family:"Times New Roman","serif";}
p.MsoAcetate, li.MsoAcetate, div.MsoAcetate
{mso-style-priority:99;
mso-style-link:"Balloon Text Char";
margin:0in;
margin-bottom:.0001pt;
font-size:8.0pt;
font-family:"Tahoma","sans-serif";}
span.BalloonTextChar
{mso-style-name:"Balloon Text Char";
mso-style-priority:99;
mso-style-link:"Balloon Text";
font-family:"Tahoma","sans-serif";}
p.msochpdefault, li.msochpdefault, div.msochpdefault
{mso-style-name:msochpdefault;
mso-margin-top-alt:auto;
margin-right:0in;
mso-margin-bottom-alt:auto;
margin-left:0in;
font-size:10.0pt;
font-family:"Times New Roman","serif";}
span.balloontextchar0
{mso-style-name:balloontextchar;
font-family:"Tahoma","sans-serif";}
span.emailstyle20
{mso-style-name:emailstyle20;
font-family:"Calibri","sans-serif";
color:#1F497D;}
span.emailstyle21
{mso-style-name:emailstyle21;
color:black;}
span.emailstyle22
{mso-style-name:emailstyle22;
font-family:"Calibri","sans-serif";
color:#1F497D;}
span.emailstyle23
{mso-style-name:emailstyle23;
color:black;}
span.emailstyle24
{mso-style-name:emailstyle24;
font-family:"Calibri","sans-serif";
color:#1F497D;}
span.emailstyle25
{mso-style-name:emailstyle25;
color:black;}
span.emailstyle26
{mso-style-name:emailstyle26;
font-family:"Calibri","sans-serif";
color:#1F497D;}
span.EmailStyle29
{mso-style-type:personal-reply;
font-family:"Calibri","sans-serif";
color:#1F497D;}
.MsoChpDefault
{mso-style-type:export-only;
font-size:10.0pt;}
@page WordSection1
{size:8.5in 11.0in;
margin:1.0in 1.0in 1.0in 1.0in;}
div.WordSection1
{page:WordSection1;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext="edit" spidmax="1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext="edit">
<o:idmap v:ext="edit" data="1" />
</o:shapelayout></xml><![endif]-->
<div link="blue" vlink="purple" lang="EN-US">
<div class="WordSection1">
<p class="MsoNormal"><font face="Calibri" size="2"
color="#1f497d"><span style="font-size: 11pt;
font-family: Calibri, sans-serif; color: rgb(31, 73,
125); ">1) Become the rancid user<o:p></o:p></span></font></p>
<p class="MsoNormal"><font face="Calibri" size="2"
color="#1f497d"><span style="font-size: 11pt;
font-family: Calibri, sans-serif; color: rgb(31, 73,
125); ">2) make sure that panrancid and panlogin are
in your path<o:p></o:p></span></font></p>
<p class="MsoNormal"><font face="Calibri" size="2"
color="#1f497d"><span style="font-size: 11pt;
font-family: Calibri, sans-serif; color: rgb(31, 73,
125); ">3) &#8220;panrancid &lt;device&gt;&#8221;&nbsp;&nbsp;
<o:p></o:p></span></font></p>
<p class="MsoNormal"><font face="Calibri" size="2"
color="#1f497d"><span style="font-size: 11pt;
font-family: Calibri, sans-serif; color: rgb(31, 73,
125); ">After you run it, if it works, you should
see a file &lt;device&gt;.new in the current
directory.<o:p></o:p></span></font></p>
<p class="MsoNormal"><font face="Calibri" size="2"
color="#1f497d"><span style="font-size: 11pt;
font-family: Calibri, sans-serif; color: rgb(31, 73,
125); "><o:p>&nbsp;</o:p></span></font></p>
<p class="MsoNormal"><font face="Calibri" size="2"
color="#1f497d"><span style="font-size: 11pt;
font-family: Calibri, sans-serif; color: rgb(31, 73,
125); ">If it fails, paste the results of this:
&#8220;panrancid &#8211;d &lt;device&gt;&#8221;<o:p></o:p></span></font></p>
<p class="MsoNormal"><font face="Calibri" size="2"
color="#1f497d"><span style="font-size: 11pt;
font-family: Calibri, sans-serif; color: rgb(31, 73,
125); "><o:p>&nbsp;</o:p></span></font></p>
<div>
<div style="border:none;border-top:solid #B5C4DF
1.0pt;padding:3.0pt 0in 0in 0in">
<p class="MsoNormal" style="margin-left:.5in"><b><font
face="Tahoma" size="2"><span style="font-size:
10pt; font-family: Tahoma, sans-serif;
font-weight: bold; ">From:</span></font></b><font
face="Tahoma" size="2"><span style="font-size:
10pt; font-family: Tahoma, sans-serif; "> Ryan
Milton [<a moz-do-not-send="true"
href="mailto:***@mvsusa.com">mailto:***@mvsusa.com</a>]
<br>
<b><span style="font-weight:bold">Sent:</span></b>
Saturday, September 28, 2013 1:49 PM<br>
<b><span style="font-weight:bold">To:</span></b>
Hughes, Doug; Kishore Rajani<br>
<b><span style="font-weight:bold">Cc:</span></b>
<a moz-do-not-send="true"
href="mailto:***@novidys.com">
***@novidys.com</a>; <a
moz-do-not-send="true"
href="mailto:rancid-***@shrubbery.net">rancid-***@shrubbery.net</a><br>
<b><span style="font-weight:bold">Subject:</span></b>
RE: [rancid] Palo Alto Networks<o:p></o:p></span></font></p>
</div>
</div>
<p class="MsoNormal" style="margin-left:.5in"><font
face="Times New Roman" size="3"><span
style="font-size:12.0pt"><o:p>&nbsp;</o:p></span></font></p>
<p class="MsoNormal" style="margin-left:.5in"><font
face="Times New Roman" size="3"><span
style="font-size:12.0pt">You ask a few questions.&nbsp;
Most of my scripts seem to work, like jrancid,
nrancid. Hrancid (for hp?) doesn't seem to work as I
get "failed to login" errors. <br>
<br>
Does it work if you run panrancid directly on the
command line from the bin directory?<br>
<br>
--&gt;not sure I know how to do this. <br>
<br>
Ryan Milton<br>
MVS Network Manager<br>
O: 201-447-1505 x124<br>
C: 862-249-5230 <o:p></o:p></span></font></p>
<div class="MsoNormal"
style="margin-left:.5in;text-align:center"
align="center">
<font face="Times New Roman" size="3"><span
style="font-size:12.0pt">
<hr size="2" width="98%" align="center">
</span></font></div>
<div id="divRplyFwdMsg">
<p class="MsoNormal" style="margin-left:.5in"><b><font
face="Calibri" size="2" color="black"><span
style="font-size: 11pt; font-family: Calibri,
sans-serif; color: black; font-weight: bold; ">From:</span></font></b><font
face="Calibri" size="2" color="black"><span
style="font-size: 11pt; font-family: Calibri,
sans-serif; color: black; "> Hughes, Doug &lt;<a
moz-do-not-send="true"
href="mailto:***@DEShawResearch.com">***@DEShawResearch.com</a>&gt;<br>
<b><span style="font-weight:bold">Sent:</span></b>
Friday, September 27, 2013 3:57:58 PM<br>
<b><span style="font-weight:bold">To:</span></b>
Ryan Milton; Kishore Rajani<br>
<b><span style="font-weight:bold">Cc:</span></b> <a
moz-do-not-send="true"
href="mailto:***@novidys.com">
***@novidys.com</a>; <a
moz-do-not-send="true"
href="mailto:rancid-***@shrubbery.net">rancid-***@shrubbery.net</a><br>
<b><span style="font-weight:bold">Subject:</span></b>
RE: [rancid] Palo Alto Networks</span></font><o:p></o:p></p>
<div>
<p class="MsoNormal" style="margin-left:.5in"><font
face="Times New Roman" size="3"><span
style="font-size:12.0pt">&nbsp;<o:p></o:p></span></font></p>
</div>
</div>
<div>
<div>
<p class="MsoNormal" style="margin-left:.5in"><font
face="Calibri" size="2" color="#1f497d"><span
style="font-size: 11pt; font-family: Calibri,
sans-serif; color: rgb(31, 73, 125); ">I have
perl 5.8.8. I&#8217;m not sure why that would make a
significant difference, though.</span></font><o:p></o:p></p>
<p class="MsoNormal" style="margin-left:.5in"><font
face="Calibri" size="2" color="#1f497d"><span
style="font-size: 11pt; font-family: Calibri,
sans-serif; color: rgb(31, 73, 125); ">&nbsp;</span></font><o:p></o:p></p>
<p class="MsoNormal" style="margin-left:.5in"><font
face="Calibri" size="2" color="#1f497d"><span
style="font-size: 11pt; font-family: Calibri,
sans-serif; color: rgb(31, 73, 125); ">There are
many used of defined in the perl code.. So why
would it pick that one? (semi-rhetorical)</span></font><o:p></o:p></p>
<p class="MsoNormal" style="margin-left:.5in"><font
face="Calibri" size="2" color="#1f497d"><span
style="font-size: 11pt; font-family: Calibri,
sans-serif; color: rgb(31, 73, 125); ">&nbsp;</span></font><o:p></o:p></p>
<p class="MsoNormal" style="margin-left:.5in"><font
face="Calibri" size="2" color="#1f497d"><span
style="font-size: 11pt; font-family: Calibri,
sans-serif; color: rgb(31, 73, 125); ">It
appears to be complaining about the first use of
defined. Do other rancid files work ok?
ProcessHistory is just lifted from another one,
originally.. Does the crancid or hprancid work
ok?</span></font><o:p></o:p></p>
<p class="MsoNormal" style="margin-left:.5in"><font
face="Calibri" size="2" color="#1f497d"><span
style="font-size: 11pt; font-family: Calibri,
sans-serif; color: rgb(31, 73, 125); ">&nbsp;</span></font><o:p></o:p></p>
<p class="MsoNormal" style="margin-left:.5in"><font
face="Calibri" size="2" color="#1f497d"><span
style="font-size: 11pt; font-family: Calibri,
sans-serif; color: rgb(31, 73, 125); ">Do you
have access to an older Perl for testing?</span></font><o:p></o:p></p>
<p class="MsoNormal" style="margin-left:.5in"><font
face="Calibri" size="2" color="#1f497d"><span
style="font-size: 11pt; font-family: Calibri,
sans-serif; color: rgb(31, 73, 125); ">&nbsp;</span></font><o:p></o:p></p>
<p class="MsoNormal" style="margin-left:.5in"><font
face="Calibri" size="2" color="#1f497d"><span
style="font-size: 11pt; font-family: Calibri,
sans-serif; color: rgb(31, 73, 125); ">Does it
work if you run panrancid directly on the
command line from the bin directory?</span></font><o:p></o:p></p>
<p class="MsoNormal" style="margin-left:.5in"><font
face="Calibri" size="2" color="#1f497d"><span
style="font-size: 11pt; font-family: Calibri,
sans-serif; color: rgb(31, 73, 125); ">&nbsp;</span></font><o:p></o:p></p>
<p class="MsoNormal" style="margin-left:.5in"><font
face="Calibri" size="2" color="#1f497d"><span
style="font-size: 11pt; font-family: Calibri,
sans-serif; color: rgb(31, 73, 125); ">&nbsp;</span></font><o:p></o:p></p>
<div>
<div style="border:none;border-top:solid #B5C4DF
1.0pt;padding:3.0pt 0in 0in 0in">
<p class="MsoNormal" style="margin-left:1.0in"><b><font
face="Tahoma" size="2"><span
style="font-size: 10pt; font-family:
Tahoma, sans-serif; font-weight: bold; ">From:</span></font></b><font
face="Tahoma" size="2"><span style="font-size:
10pt; font-family: Tahoma, sans-serif; ">
Ryan Milton [<a moz-do-not-send="true"
href="mailto:***@mvsusa.com">mailto:***@mvsusa.com</a>]
<br>
<b><span style="font-weight:bold">Sent:</span></b>
Friday, September 27, 2013 1:23 PM<br>
<b><span style="font-weight:bold">To:</span></b>
Hughes, Doug; Kishore Rajani<br>
<b><span style="font-weight:bold">Cc:</span></b>
<a moz-do-not-send="true"
href="mailto:***@novidys.com">
***@novidys.com</a>; <a
moz-do-not-send="true"
href="mailto:rancid-***@shrubbery.net">rancid-***@shrubbery.net</a><br>
<b><span style="font-weight:bold">Subject:</span></b>
RE: [rancid] Palo Alto Networks</span></font><o:p></o:p></p>
</div>
</div>
<p class="MsoNormal" style="margin-left:1.0in"><font
face="Times New Roman" size="3"><span
style="font-size:12.0pt">&nbsp;<o:p></o:p></span></font></p>
<p class="MsoNormal" style="margin-left:1.0in"><font
face="Times New Roman" size="3" color="black"><span
style="font-size:12.0pt;color:black">So, the
Perl version is perl 5, version 14, subversion 2
(v5.14.2) built for
x86_64-linux-gnu-thread-multi</span></font><o:p></o:p></p>
<p class="MsoNormal" style="margin-left:1.0in"><font
face="Times New Roman" size="3" color="black"><span
style="font-size:12.0pt;color:black">&nbsp;</span></font><o:p></o:p></p>
<p class="MsoNormal" style="margin-left:1.0in"><font
face="Times New Roman" size="3" color="black"><span
style="font-size:12.0pt;color:black">And
</span></font><o:p></o:p></p>
<p class="MsoNormal" style="margin-left:1.0in"><font
face="Times New Roman" size="3" color="black"><span
style="font-size:12.0pt;color:black">&nbsp;</span></font><o:p></o:p></p>
<p class="MsoNormal" style="margin-left:1.0in"><font
face="Times New Roman" size="3" color="black"><span
style="font-size:12.0pt;color:black">***@ObserviumNYC:~$
sum /usr/lib/rancid/bin/panrancid</span></font><o:p></o:p></p>
<p class="MsoNormal" style="margin-left:1.0in"><font
face="Times New Roman" size="3" color="black"><span
style="font-size:12.0pt;color:black">14180&nbsp;&nbsp;&nbsp;&nbsp; 9</span></font><o:p></o:p></p>
<p class="MsoNormal" style="margin-left:1.0in"><font
face="Times New Roman" size="3" color="black"><span
style="font-size:12.0pt;color:black">&nbsp;</span></font><o:p></o:p></p>
<div>
<p class="MsoNormal" style="margin-left:1.0in"><font
face="Calibri" size="2" color="black"><span
style="font-size: 11pt; font-family: Calibri,
sans-serif; color: black; ">Regards,</span></font><o:p></o:p></p>
<p class="MsoNormal" style="margin-left:1.0in"><font
face="Calibri" size="2" color="black"><span
style="font-size: 11pt; font-family: Calibri,
sans-serif; color: black; ">Ryan Milton</span></font><o:p></o:p></p>
<p class="MsoNormal" style="margin-left:1.0in"><font
face="Calibri" size="2" color="black"><span
style="font-size: 11pt; font-family: Calibri,
sans-serif; color: black; ">MVS Network
Manager</span></font><o:p></o:p></p>
<p class="MsoNormal" style="margin-left:1.0in"><font
face="Calibri" size="2" color="black"><span
style="font-size: 11pt; font-family: Calibri,
sans-serif; color: black; ">o: 201-447-1505
x124</span></font><o:p></o:p></p>
<p class="MsoNormal" style="margin-left:1.0in"><font
face="Calibri" size="2" color="black"><span
style="font-size: 11pt; font-family: Calibri,
sans-serif; color: black; ">c: 862-249-5230</span></font><o:p></o:p></p>
<p class="MsoNormal" style="margin-left:1.0in"><font
face="Calibri" size="2" color="black"><span
style="font-size:11.0pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;;color:black"><a
moz-do-not-send="true"
href="http://www.mvsusa.com/"><font
color="#0563c1"><span
style="color:#0563C1">www.mvsusa.com</span></font></a></span></font><o:p></o:p></p>
<p class="MsoNormal" style="margin-left:1.0in"><font
face="Calibri" size="2" color="black"><span
style="font-size: 11pt; font-family: Calibri,
sans-serif; color: black; "><img
moz-do-not-send="true" id="_x0000_i1026"
src="cid:***@01CEBC52.08247430"
alt="MVS final logo GOOD very small"
height="76" width="192" border="0"></span></font><o:p></o:p></p>
</div>
<p class="MsoNormal" style="margin-left:1.0in"><font
face="Times New Roman" size="3" color="black"><span
style="font-size:12.0pt;color:black">&nbsp;</span></font><o:p></o:p></p>
<div style="border:none;border-left:solid blue
1.5pt;padding:0in 0in 0in 4.0pt">
<div>
<div style="border:none;border-top:solid #E1E1E1
1.0pt;padding:3.0pt 0in 0in 0in">
<p class="MsoNormal" style="margin-left:1.0in"><b><font
face="Calibri" size="2"><span
style="font-size: 11pt; font-family:
Calibri, sans-serif; font-weight: bold;
">From:</span></font></b><font
face="Calibri" size="2"><span
style="font-size: 11pt; font-family:
Calibri, sans-serif; "> Hughes, Doug [<a
moz-do-not-send="true"
href="mailto:***@DEShawResearch.com">mailto:***@DEShawResearch.com</a>]
<br>
<b><span style="font-weight:bold">Sent:</span></b>
Friday, September 27, 2013 11:15 AM<br>
<b><span style="font-weight:bold">To:</span></b>
Ryan Milton; Kishore Rajani<br>
<b><span style="font-weight:bold">Cc:</span></b>
<a moz-do-not-send="true"
href="mailto:***@novidys.com">
***@novidys.com</a>; <a
moz-do-not-send="true"
href="mailto:rancid-***@shrubbery.net">rancid-***@shrubbery.net</a><br>
<b><span style="font-weight:bold">Subject:</span></b>
RE: [rancid] Palo Alto Networks</span></font><o:p></o:p></p>
</div>
</div>
<p class="MsoNormal" style="margin-left:1.0in"><font
face="Times New Roman" size="3"><span
style="font-size:12.0pt">&nbsp;<o:p></o:p></span></font></p>
<p class="MsoNormal" style="margin-left:1.0in"><font
face="Calibri" size="2" color="#1f497d"><span
style="font-size: 11pt; font-family: Calibri,
sans-serif; color: rgb(31, 73, 125); ">What
version of Perl are you using? That looks like
a Perl error. Also, I don&#8217;t have a
define(%hash) at line 53 in the one I sent
you.</span></font><o:p></o:p></p>
<p class="MsoNormal" style="margin-left:1.0in"><font
face="Calibri" size="2" color="#1f497d"><span
style="font-size: 11pt; font-family: Calibri,
sans-serif; color: rgb(31, 73, 125); ">&nbsp;</span></font><o:p></o:p></p>
<p class="MsoNormal" style="margin-left:1.0in"><font
face="Calibri" size="2" color="#1f497d"><span
style="font-size: 11pt; font-family: Calibri,
sans-serif; color: rgb(31, 73, 125); ">What
does &#8216;sum /usr/lib/rancid/bin/panrancid&#8217; say?</span></font><o:p></o:p></p>
<p class="MsoNormal" style="margin-left:1.0in"><font
face="Calibri" size="2" color="#1f497d"><span
style="font-size: 11pt; font-family: Calibri,
sans-serif; color: rgb(31, 73, 125); ">It
should say</span></font><o:p></o:p></p>
<p class="MsoNormal" style="margin-left:1.0in"><font
face="Calibri" size="2" color="#1f497d"><span
style="font-size: 11pt; font-family: Calibri,
sans-serif; color: rgb(31, 73, 125); ">14180&nbsp;&nbsp;&nbsp;
9</span></font><o:p></o:p></p>
<p class="MsoNormal" style="margin-left:1.0in"><font
face="Calibri" size="2" color="#1f497d"><span
style="font-size: 11pt; font-family: Calibri,
sans-serif; color: rgb(31, 73, 125); ">&nbsp;</span></font><o:p></o:p></p>
<p class="MsoNormal" style="margin-left:1.0in"><font
face="Calibri" size="2" color="#1f497d"><span
style="font-size: 11pt; font-family: Calibri,
sans-serif; color: rgb(31, 73, 125); ">&nbsp;</span></font><o:p></o:p></p>
<div>
<div style="border:none;border-top:solid #B5C4DF
1.0pt;padding:3.0pt 0in 0in 0in">
<p class="MsoNormal" style="margin-left:1.5in"><b><font
face="Tahoma" size="2"><span
style="font-size: 10pt; font-family:
Tahoma, sans-serif; font-weight: bold; ">From:</span></font></b><font
face="Tahoma" size="2"><span
style="font-size: 10pt; font-family:
Tahoma, sans-serif; "> Ryan Milton [<a
moz-do-not-send="true"
href="mailto:***@mvsusa.com">mailto:***@mvsusa.com</a>]
<br>
<b><span style="font-weight:bold">Sent:</span></b>
Friday, September 27, 2013 11:08 AM<br>
<b><span style="font-weight:bold">To:</span></b>
Hughes, Doug; Kishore Rajani<br>
<b><span style="font-weight:bold">Cc:</span></b>
<a moz-do-not-send="true"
href="mailto:***@novidys.com">
***@novidys.com</a>; <a
moz-do-not-send="true"
href="mailto:rancid-***@shrubbery.net">rancid-***@shrubbery.net</a><br>
<b><span style="font-weight:bold">Subject:</span></b>
RE: [rancid] Palo Alto Networks</span></font><o:p></o:p></p>
</div>
</div>
<p class="MsoNormal" style="margin-left:1.5in"><font
face="Times New Roman" size="3"><span
style="font-size:12.0pt">&nbsp;<o:p></o:p></span></font></p>
<p class="MsoNormal" style="margin-left:1.5in"><font
face="Times New Roman" size="3" color="black"><span
style="font-size:12.0pt;color:black">Hi Doug,</span></font><o:p></o:p></p>
<p class="MsoNormal" style="margin-left:1.5in"><font
face="Times New Roman" size="3" color="black"><span
style="font-size:12.0pt;color:black">&nbsp;</span></font><o:p></o:p></p>
<p class="MsoNormal" style="margin-left:1.5in"><font
face="Times New Roman" size="3" color="black"><span
style="font-size:12.0pt;color:black">So I am
testing your scripts. I got one error:
</span></font><o:p></o:p></p>
<p class="MsoNormal" style="margin-left:1.5in"><font
face="Times New Roman" size="3" color="black"><span
style="font-size:12.0pt;color:black">Trying to
get all of the configs.</span></font><o:p></o:p></p>
<p class="MsoNormal" style="margin-left:1.5in"><font
face="Times New Roman" size="3" color="black"><span
style="font-size:12.0pt;color:black">defined(%hash)
is deprecated at /usr/lib/rancid/bin/panrancid
line 53.</span></font><o:p></o:p></p>
<p class="MsoNormal" style="margin-left:1.5in"><font
face="Times New Roman" size="3" color="black"><span
style="font-size:12.0pt;color:black">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
(Maybe you should just omit the defined()?)</span></font><o:p></o:p></p>
<p class="MsoNormal" style="margin-left:1.5in"><font
face="Times New Roman" size="3" color="black"><span
style="font-size:12.0pt;color:black">Paloaltofw1:
missed cmd(s): show config running, set&#8230;..</span></font><o:p></o:p></p>
<p class="MsoNormal" style="margin-left:1.5in"><font
face="Times New Roman" size="3" color="black"><span
style="font-size:12.0pt;color:black">&nbsp;</span></font><o:p></o:p></p>
<p class="MsoNormal" style="margin-left:1.5in"><font
face="Times New Roman" size="3" color="black"><span
style="font-size:12.0pt;color:black">Is there
a fix for this? I figure the code is just out
of date?</span></font><o:p></o:p></p>
<p class="MsoNormal" style="margin-left:1.5in"><font
face="Times New Roman" size="3" color="black"><span
style="font-size:12.0pt;color:black">&nbsp;</span></font><o:p></o:p></p>
<div>
<p class="MsoNormal" style="margin-left:1.5in"><font
face="Calibri" size="2" color="black"><span
style="font-size: 11pt; font-family:
Calibri, sans-serif; color: black; ">Regards,</span></font><o:p></o:p></p>
<p class="MsoNormal" style="margin-left:1.5in"><font
face="Calibri" size="2" color="black"><span
style="font-size: 11pt; font-family:
Calibri, sans-serif; color: black; ">Ryan
Milton</span></font><o:p></o:p></p>
<p class="MsoNormal" style="margin-left:1.5in"><font
face="Calibri" size="2" color="black"><span
style="font-size: 11pt; font-family:
Calibri, sans-serif; color: black; ">MVS
Network Manager</span></font><o:p></o:p></p>
<p class="MsoNormal" style="margin-left:1.5in"><font
face="Calibri" size="2" color="black"><span
style="font-size: 11pt; font-family:
Calibri, sans-serif; color: black; ">o:
201-447-1505 x124</span></font><o:p></o:p></p>
<p class="MsoNormal" style="margin-left:1.5in"><font
face="Calibri" size="2" color="black"><span
style="font-size: 11pt; font-family:
Calibri, sans-serif; color: black; ">c:
862-249-5230</span></font><o:p></o:p></p>
<p class="MsoNormal" style="margin-left:1.5in"><font
face="Calibri" size="2" color="black"><span
style="font-size:11.0pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;;color:black"><a
moz-do-not-send="true"
href="http://www.mvsusa.com/"><font
color="#0563c1"><span
style="color:#0563C1">www.mvsusa.com</span></font></a></span></font><o:p></o:p></p>
<p class="MsoNormal" style="margin-left:1.5in"><font
face="Calibri" size="2" color="black"><span
style="font-size: 11pt; font-family:
Calibri, sans-serif; color: black; "><img
moz-do-not-send="true"
id="Picture_x0020_1"
src="cid:***@01CEBC52.08247430"
alt="MVS final logo GOOD very small"
height="76" width="192" border="0"></span></font><o:p></o:p></p>
</div>
<p class="MsoNormal" style="margin-left:1.5in"><font
face="Times New Roman" size="3" color="black"><span
style="font-size:12.0pt;color:black">&nbsp;</span></font><o:p></o:p></p>
<div style="border:none;border-left:solid blue
1.5pt;padding:0in 0in 0in 4.0pt">
<div>
<div style="border:none;border-top:solid #E1E1E1
1.0pt;padding:3.0pt 0in 0in 0in">
<p class="MsoNormal" style="margin-left:1.5in"><b><font
face="Calibri" size="2"><span
style="font-size: 11pt; font-family:
Calibri, sans-serif; font-weight:
bold; ">From:</span></font></b><font
face="Calibri" size="2"><span
style="font-size: 11pt; font-family:
Calibri, sans-serif; "> Hughes, Doug [<a
moz-do-not-send="true"
href="mailto:***@DEShawResearch.com">mailto:***@DEShawResearch.com</a>]
<br>
<b><span style="font-weight:bold">Sent:</span></b>
Tuesday, September 24, 2013 5:02 PM<br>
<b><span style="font-weight:bold">To:</span></b>
Ryan Milton; Kishore Rajani; <a
moz-do-not-send="true"
href="mailto:rancid-***@googlegroups.com">
rancid-***@googlegroups.com</a><br>
<b><span style="font-weight:bold">Cc:</span></b>
<a moz-do-not-send="true"
href="mailto:***@novidys.com">
***@novidys.com</a>; <a
moz-do-not-send="true"
href="mailto:rancid-***@shrubbery.net">rancid-***@shrubbery.net</a><br>
<b><span style="font-weight:bold">Subject:</span></b>
RE: [rancid] Palo Alto Networks</span></font><o:p></o:p></p>
</div>
</div>
<p class="MsoNormal" style="margin-left:1.5in"><font
face="Times New Roman" size="3"><span
style="font-size:12.0pt">&nbsp;<o:p></o:p></span></font></p>
<p class="MsoNormal" style="margin-left:1.5in"><font
face="Calibri" size="2" color="#1f497d"><span
style="font-size: 11pt; font-family:
Calibri, sans-serif; color: rgb(31, 73,
125); ">Sure they can. I do it for 3 of them
right now.</span></font><o:p></o:p></p>
<p class="MsoNormal" style="margin-left:1.5in"><font
face="Calibri" size="2" color="#1f497d"><span
style="font-size: 11pt; font-family:
Calibri, sans-serif; color: rgb(31, 73,
125); ">&nbsp;</span></font><o:p></o:p></p>
<p class="MsoNormal" style="margin-left:1.5in"><font
face="Calibri" size="2" color="#1f497d"><span
style="font-size: 11pt; font-family:
Calibri, sans-serif; color: rgb(31, 73,
125); ">Attached. Set your &#8216;switch type&#8217; to
paloalto. Works with names or IP addresses.</span></font><o:p></o:p></p>
<p class="MsoNormal" style="margin-left:1.5in"><font
face="Calibri" size="2" color="#1f497d"><span
style="font-size: 11pt; font-family:
Calibri, sans-serif; color: rgb(31, 73,
125); ">&nbsp;</span></font><o:p></o:p></p>
<div>
<div style="border:none;border-top:solid #B5C4DF
1.0pt;padding:3.0pt 0in 0in 0in">
<p class="MsoNormal" style="margin-left:2.0in"><b><font
face="Tahoma" size="2"><span
style="font-size: 10pt; font-family:
Tahoma, sans-serif; font-weight: bold;
">From:</span></font></b><font
face="Tahoma" size="2"><span
style="font-size: 10pt; font-family:
Tahoma, sans-serif; "> Ryan Milton [<a
moz-do-not-send="true"
href="mailto:***@mvsusa.com">mailto:***@mvsusa.com</a>]
<br>
<b><span style="font-weight:bold">Sent:</span></b>
Tuesday, September 24, 2013 4:58 PM<br>
<b><span style="font-weight:bold">To:</span></b>
Hughes, Doug; Kishore Rajani; <a
moz-do-not-send="true"
href="mailto:rancid-***@googlegroups.com">
rancid-***@googlegroups.com</a><br>
<b><span style="font-weight:bold">Cc:</span></b>
<a moz-do-not-send="true"
href="mailto:***@novidys.com">
***@novidys.com</a>; <a
moz-do-not-send="true"
href="mailto:rancid-***@shrubbery.net">rancid-***@shrubbery.net</a><br>
<b><span style="font-weight:bold">Subject:</span></b>
RE: [rancid] Palo Alto Networks</span></font><o:p></o:p></p>
</div>
</div>
<p class="MsoNormal" style="margin-left:2.0in"><font
face="Times New Roman" size="3"><span
style="font-size:12.0pt">&nbsp;<o:p></o:p></span></font></p>
<p class="MsoNormal" style="margin-left:2.0in"><font
face="Times New Roman" size="3" color="black"><span
style="font-size:12.0pt;color:black">I would
certainly be interested in adding PAN
devices to Rancid. I thought that they
couldn&#8217;t be read. That is what I&#8217;ve found
with my HP switches&#8212;but that is another
matter. Any ideas on getting PAN devices
read by Rancid would be useful.</span></font><o:p></o:p></p>
<p class="MsoNormal" style="margin-left:2.0in"><font
face="Times New Roman" size="3" color="black"><span
style="font-size:12.0pt;color:black">&nbsp;</span></font><o:p></o:p></p>
<div>
<p class="MsoNormal" style="margin-left:2.0in"><font
face="Calibri" size="2" color="black"><span
style="font-size: 11pt; font-family:
Calibri, sans-serif; color: black; ">Regards,</span></font><o:p></o:p></p>
<p class="MsoNormal" style="margin-left:2.0in"><font
face="Calibri" size="2" color="black"><span
style="font-size: 11pt; font-family:
Calibri, sans-serif; color: black; ">Ryan
Milton</span></font><o:p></o:p></p>
</div>
<p class="MsoNormal" style="margin-left:2.0in"><font
face="Times New Roman" size="3" color="black"><span
style="font-size:12.0pt;color:black">&nbsp;</span></font><o:p></o:p></p>
<div style="border:none;border-left:solid blue
1.5pt;padding:0in 0in 0in 4.0pt">
<div>
<div style="border:none;border-top:solid
#E1E1E1 1.0pt;padding:3.0pt 0in 0in 0in">
<p class="MsoNormal"
style="margin-left:2.0in"><b><font
face="Calibri" size="2"><span
style="font-size: 11pt; font-family:
Calibri, sans-serif; font-weight:
bold; ">From:</span></font></b><font
face="Calibri" size="2"><span
style="font-size: 11pt; font-family:
Calibri, sans-serif; "><a
moz-do-not-send="true"
href="mailto:rancid-discuss-***@shrubbery.net">rancid-discuss-***@shrubbery.net</a>
[<a moz-do-not-send="true"
href="mailto:rancid-discuss-***@shrubbery.net">mailto:rancid-discuss-***@shrubbery.net</a>]
<b><span style="font-weight:bold">On
Behalf Of </span></b>Hughes, Doug<br>
<b><span style="font-weight:bold">Sent:</span></b>
Tuesday, September 24, 2013 12:26 PM<br>
<b><span style="font-weight:bold">To:</span></b>
Kishore Rajani; <a
moz-do-not-send="true"
href="mailto:rancid-***@googlegroups.com">
rancid-***@googlegroups.com</a><br>
<b><span style="font-weight:bold">Cc:</span></b>
<a moz-do-not-send="true"
href="mailto:***@novidys.com">
***@novidys.com</a>; <a
moz-do-not-send="true"
href="mailto:rancid-***@shrubbery.net">rancid-***@shrubbery.net</a><br>
<b><span style="font-weight:bold">Subject:</span></b>
Re: [rancid] Palo Alto Networks</span></font><o:p></o:p></p>
</div>
</div>
<p class="MsoNormal" style="margin-left:2.0in"><font
face="Times New Roman" size="3"><span
style="font-size:12.0pt">&nbsp;<o:p></o:p></span></font></p>
<p class="MsoNormal" style="margin-left:2.0in"><font
face="Calibri" size="2" color="#1f497d"><span
style="font-size: 11pt; font-family:
Calibri, sans-serif; color: rgb(31, 73,
125); ">Yes, I have working panlogin and
panrancid and have contributed them
upstream. Have you not been able to get
them to work?</span></font><o:p></o:p></p>
<p class="MsoNormal" style="margin-left:2.0in"><font
face="Calibri" size="2" color="#1f497d"><span
style="font-size: 11pt; font-family:
Calibri, sans-serif; color: rgb(31, 73,
125); ">&nbsp;</span></font><o:p></o:p></p>
<p class="MsoNormal" style="margin-left:2.0in"><font
face="Calibri" size="2" color="#1f497d"><span
style="font-size: 11pt; font-family:
Calibri, sans-serif; color: rgb(31, 73,
125); ">&nbsp;</span></font><o:p></o:p></p>
<p class="MsoNormal" style="margin-left:2.5in"><b><font
face="Tahoma" size="2"><span
style="font-size: 10pt; font-family:
Tahoma, sans-serif; font-weight: bold; ">From:</span></font></b><font
face="Tahoma" size="2"><span
style="font-size: 10pt; font-family:
Tahoma, sans-serif; "><a
moz-do-not-send="true"
href="mailto:rancid-discuss-***@shrubbery.net">rancid-discuss-***@shrubbery.net</a>
[<a moz-do-not-send="true"
href="mailto:rancid-discuss-***@shrubbery.net">mailto:rancid-discuss-***@shrubbery.net</a>]
<b><span style="font-weight:bold">On
Behalf Of </span></b>Kishore Rajani<br>
<b><span style="font-weight:bold">Sent:</span></b>
Monday, September 23, 2013 9:52 AM<br>
<b><span style="font-weight:bold">To:</span></b>
<a moz-do-not-send="true"
href="mailto:rancid-***@googlegroups.com">
rancid-***@googlegroups.com</a><br>
<b><span style="font-weight:bold">Cc:</span></b>
<a moz-do-not-send="true"
href="mailto:***@novidys.com">
***@novidys.com</a>; <a
moz-do-not-send="true"
href="mailto:rancid-***@shrubbery.net">rancid-***@shrubbery.net</a><br>
<b><span style="font-weight:bold">Subject:</span></b>
Re: [rancid] Palo Alto Networks</span></font><o:p></o:p></p>
<p class="MsoNormal" style="margin-left:2.5in"><font
face="Times New Roman" size="3"><span
style="font-size:12.0pt">&nbsp;<o:p></o:p></span></font></p>
<div>
<p class="MsoNormal" style="margin-left:2.5in"><font
face="Times New Roman" size="3"><span
style="font-size:12.0pt">HI,<br>
<br>
did you manage to get the RANCID running
with PAN?<br>
<br>
Regards,<br>
Kishore<br>
<br>
On Thursday, 29 March 2012 13:53:33
UTC+1, Guillaume Dupuis wrote:<o:p></o:p></span></font></p>
<p class="MsoNormal" style="margin-left:2.5in"><font
face="Times New Roman" size="3"><span
style="font-size:12.0pt">Nate Beck
&lt;Nate.Beck &lt;at&gt;
<a moz-do-not-send="true"
href="http://jivesoftware.com"
target="_blank">jivesoftware.com</a>&gt;
writes:<o:p></o:p></span></font></p>
<p style="margin-left:2.5in"><font face="Times
New Roman" size="3"><span
style="font-size:12.0pt">&gt;
<br>
&gt; <br>
&gt; Has anyone on the list worked with
Palo Alto Network firewalls and Rancid?
&nbsp;I<br>
was wondering if anyone has created a
*login for them.<br>
&gt; Thanks-------------------<br>
&gt; Nathan BeckSr. IT Engineer<br>
&gt; Jive Software<br>
&gt; 503.972.9024<o:p></o:p></span></font></p>
<p style="margin-left:2.5in"><font face="Times
New Roman" size="3"><span
style="font-size:12.0pt">Hi Nate,<o:p></o:p></span></font></p>
<p style="margin-left:2.5in"><font face="Times
New Roman" size="3"><span
style="font-size:12.0pt">Did you find a
*login script for PAN?<o:p></o:p></span></font></p>
<p style="margin-left:2.5in"><font face="Times
New Roman" size="3"><span
style="font-size:12.0pt">Thanks,<o:p></o:p></span></font></p>
<p style="margin-left:2.5in"><font face="Times
New Roman" size="3"><span
style="font-size:12.0pt">Guillaume
Dupuis<o:p></o:p></span></font></p>
<p style="margin-left:2.5in"><font face="Times
New Roman" size="3"><span
style="font-size:12.0pt">_______________________________________________<br>
Rancid-discuss mailing list<br>
<a moz-do-not-send="true" href=""
target="_blank">Rancid-***@shrubbery.net</a><br>
<a moz-do-not-send="true"
href="http://www.shrubbery.net/mailman/listinfo.cgi/rancid-discuss"
target="_blank">http://www.shrubbery.net/mailman/listinfo.cgi/rancid-discuss</a><o:p></o:p></span></font></p>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</span>
<br>
<fieldset class="mimeAttachmentHeader"></fieldset>
<br>
<pre wrap="">_______________________________________________
Rancid-discuss mailing list
<a class="moz-txt-link-abbreviated" href="mailto:Rancid-***@shrubbery.net">Rancid-***@shrubbery.net</a>
<a class="moz-txt-link-freetext" href="http://www.shrubbery.net/mailman/listinfo/rancid-discuss">http://www.shrubbery.net/mailman/listinfo/rancid-discuss</a></pre>
</blockquote>
<br>
</body>
</html>
Hughes, Doug
2013-09-28 22:29:55 UTC
Permalink
Yeah, that means it is working. It looks like you have a path problem. Make sure that your rancid user account has /usr/lib/rancid/bin first in path.

From: Ryan Milton [mailto:***@mvsusa.com]
Sent: Saturday, September 28, 2013 6:17 PM
To: Hughes, Doug; Kishore Rajani
Cc: ***@novidys.com; rancid-***@shrubbery.net
Subject: Re: [rancid] Palo Alto Networks

When I go to the executables directory, /usr/lib/rancid/bin/ and panrancid <device>, or jrancid <device>, etc, I get the same thing: "panrancid: command not found", or "jrancid: command not found." so if I run the panlogin, jlogin, etc, I get into the device, but that's it.

As I wrote that above message, I just did a "rancid-run" and DID get a revision to my Palo Alto test device. So I guess that is good. I don't really know if that will work here forward, but does that mean that it is working?

Sorry to sound like the noob that I am.

Ryan

From: <Hughes>, Doug <***@DEShawResearch.com<mailto:***@DEShawResearch.com>>
Date: Saturday, September 28, 2013 1:52 PM
To: Ryan Milton <***@mvsusa.com<mailto:***@mvsusa.com>>, Kishore Rajani <***@gmail.com<mailto:***@gmail.com>>
Cc: "***@novidys.com<mailto:***@novidys.com>" <***@novidys.com<mailto:***@novidys.com>>, "rancid-***@shrubbery.net<mailto:rancid-***@shrubbery.net>" <rancid-***@shrubbery.net<mailto:rancid-***@shrubbery.net>>
Subject: RE: [rancid] Palo Alto Networks

1) Become the rancid user
2) make sure that panrancid and panlogin are in your path
3) "panrancid <device>"
After you run it, if it works, you should see a file <device>.new in the current directory.

If it fails, paste the results of this: "panrancid -d <device>"

From: Ryan Milton [mailto:***@mvsusa.com]
Sent: Saturday, September 28, 2013 1:49 PM
To: Hughes, Doug; Kishore Rajani
Cc: ***@novidys.com<mailto:***@novidys.com>; rancid-***@shrubbery.net<mailto:rancid-***@shrubbery.net>
Subject: RE: [rancid] Palo Alto Networks

You ask a few questions. Most of my scripts seem to work, like jrancid, nrancid. Hrancid (for hp?) doesn't seem to work as I get "failed to login" errors.

Does it work if you run panrancid directly on the command line from the bin directory?

-->not sure I know how to do this.

Ryan Milton
MVS Network Manager
O: 201-447-1505 x124
C: 862-249-5230
________________________________
From: Hughes, Doug <***@DEShawResearch.com<mailto:***@DEShawResearch.com>>
Sent: Friday, September 27, 2013 3:57:58 PM
To: Ryan Milton; Kishore Rajani
Cc: ***@novidys.com<mailto:***@novidys.com>; rancid-***@shrubbery.net<mailto:rancid-***@shrubbery.net>
Subject: RE: [rancid] Palo Alto Networks

I have perl 5.8.8. I'm not sure why that would make a significant difference, though.

There are many used of defined in the perl code.. So why would it pick that one? (semi-rhetorical)

It appears to be complaining about the first use of defined. Do other rancid files work ok? ProcessHistory is just lifted from another one, originally.. Does the crancid or hprancid work ok?

Do you have access to an older Perl for testing?

Does it work if you run panrancid directly on the command line from the bin directory?


From: Ryan Milton [mailto:***@mvsusa.com]
Sent: Friday, September 27, 2013 1:23 PM
To: Hughes, Doug; Kishore Rajani
Cc: ***@novidys.com<mailto:***@novidys.com>; rancid-***@shrubbery.net<mailto:rancid-***@shrubbery.net>
Subject: RE: [rancid] Palo Alto Networks

So, the Perl version is perl 5, version 14, subversion 2 (v5.14.2) built for x86_64-linux-gnu-thread-multi

And

***@ObserviumNYC:~$ sum /usr/lib/rancid/bin/panrancid
14180 9

Regards,
Ryan Milton
MVS Network Manager
o: 201-447-1505 x124
c: 862-249-5230
www.mvsusa.com<http://www.mvsusa.com/>
[MVS final logo GOOD very small]

From: Hughes, Doug [mailto:***@DEShawResearch.com]
Sent: Friday, September 27, 2013 11:15 AM
To: Ryan Milton; Kishore Rajani
Cc: ***@novidys.com<mailto:***@novidys.com>; rancid-***@shrubbery.net<mailto:rancid-***@shrubbery.net>
Subject: RE: [rancid] Palo Alto Networks

What version of Perl are you using? That looks like a Perl error. Also, I don't have a define(%hash) at line 53 in the one I sent you.

What does 'sum /usr/lib/rancid/bin/panrancid' say?
It should say
14180 9


From: Ryan Milton [mailto:***@mvsusa.com]
Sent: Friday, September 27, 2013 11:08 AM
To: Hughes, Doug; Kishore Rajani
Cc: ***@novidys.com<mailto:***@novidys.com>; rancid-***@shrubbery.net<mailto:rancid-***@shrubbery.net>
Subject: RE: [rancid] Palo Alto Networks

Hi Doug,

So I am testing your scripts. I got one error:
Trying to get all of the configs.
defined(%hash) is deprecated at /usr/lib/rancid/bin/panrancid line 53.
(Maybe you should just omit the defined()?)
Paloaltofw1: missed cmd(s): show config running, set.....

Is there a fix for this? I figure the code is just out of date?

Regards,
Ryan Milton
MVS Network Manager
o: 201-447-1505 x124
c: 862-249-5230
www.mvsusa.com<http://www.mvsusa.com/>
[MVS final logo GOOD very small]

From: Hughes, Doug [mailto:***@DEShawResearch.com]
Sent: Tuesday, September 24, 2013 5:02 PM
To: Ryan Milton; Kishore Rajani; rancid-***@googlegroups.com<mailto:rancid-***@googlegroups.com>
Cc: ***@novidys.com<mailto:***@novidys.com>; rancid-***@shrubbery.net<mailto:rancid-***@shrubbery.net>
Subject: RE: [rancid] Palo Alto Networks

Sure they can. I do it for 3 of them right now.

Attached. Set your 'switch type' to paloalto. Works with names or IP addresses.

From: Ryan Milton [mailto:***@mvsusa.com]
Sent: Tuesday, September 24, 2013 4:58 PM
To: Hughes, Doug; Kishore Rajani; rancid-***@googlegroups.com<mailto:rancid-***@googlegroups.com>
Cc: ***@novidys.com<mailto:***@novidys.com>; rancid-***@shrubbery.net<mailto:rancid-***@shrubbery.net>
Subject: RE: [rancid] Palo Alto Networks

I would certainly be interested in adding PAN devices to Rancid. I thought that they couldn't be read. That is what I've found with my HP switches-but that is another matter. Any ideas on getting PAN devices read by Rancid would be useful.

Regards,
Ryan Milton

From:rancid-discuss-***@shrubbery.net<mailto:rancid-discuss-***@shrubbery.net> [mailto:rancid-discuss-***@shrubbery.net] On Behalf Of Hughes, Doug
Sent: Tuesday, September 24, 2013 12:26 PM
To: Kishore Rajani; rancid-***@googlegroups.com<mailto:rancid-***@googlegroups.com>
Cc: ***@novidys.com<mailto:***@novidys.com>; rancid-***@shrubbery.net<mailto:rancid-***@shrubbery.net>
Subject: Re: [rancid] Palo Alto Networks

Yes, I have working panlogin and panrancid and have contributed them upstream. Have you not been able to get them to work?


From:rancid-discuss-***@shrubbery.net<mailto:rancid-discuss-***@shrubbery.net> [mailto:rancid-discuss-***@shrubbery.net] On Behalf Of Kishore Rajani
Sent: Monday, September 23, 2013 9:52 AM
To: rancid-***@googlegroups.com<mailto:rancid-***@googlegroups.com>
Cc: ***@novidys.com<mailto:***@novidys.com>; rancid-***@shrubbery.net<mailto:rancid-***@shrubbery.net>
Subject: Re: [rancid] Palo Alto Networks

HI,

did you manage to get the RANCID running with PAN?

Regards,
Kishore

On Thursday, 29 March 2012 13:53:33 UTC+1, Guillaume Dupuis wrote:
Nate Beck <Nate.Beck <at> jivesoftware.com<http://jivesoftware.com>> writes:

>
>
> Has anyone on the list worked with Palo Alto Network firewalls and Rancid? I
was wondering if anyone has created a *login for them.
> Thanks-------------------
> Nathan BeckSr. IT Engineer
> Jive Software
> 503.972.9024

Hi Nate,

Did you find a *login script for PAN?

Thanks,

Guillaume Dupuis
Jethro R Binks
2013-09-28 23:29:01 UTC
Permalink
On Sat, 28 Sep 2013, Ryan Milton wrote:

> When I go to the executables directory, /usr/lib/rancid/bin/ and
> panrancid <device>, or jrancid <device>, etc, I get the same thing:
> "panrancid: command not found", or "jrancid: command not found." so if I
> run the panlogin, jlogin, etc, I get into the device, but that’s it.

What are the first lines of the files "panracid" and "jrancid" ?

It should be the path to your perl interpreter, for example:

#! /usr/bin/perl5


> o: 201-447-1505 x124
> c: 862-249-5230
> www.mvsusa.com<http://www.mvsusa.com/>
> [MVS final logo GOOD very small]
>
> From: Hughes, Doug [mailto:***@DEShawResearch.com]
> Sent: Friday, September 27, 2013 11:15 AM
> To: Ryan Milton; Kishore Rajani
> Cc: ***@novidys.com<mailto:***@novidys.com>; rancid-***@shrubbery.net<mailto:rancid-***@shrubbery.net>
> Subject: RE: [rancid] Palo Alto Networks
>
> What version of Perl are you using? That looks like a Perl error. Also, I don’t have a define(%hash) at line 53 in the one I sent you.
>
> What does ‘sum /usr/lib/rancid/bin/panrancid’ say?
> It should say
> 14180 9
>
>
> From: Ryan Milton [mailto:***@mvsusa.com]
> Sent: Friday, September 27, 2013 11:08 AM
> To: Hughes, Doug; Kishore Rajani
> Cc: ***@novidys.com<mailto:***@novidys.com>; rancid-***@shrubbery.net<mailto:rancid-***@shrubbery.net>
> Subject: RE: [rancid] Palo Alto Networks
>
> Hi Doug,
>
> So I am testing your scripts. I got one error:
> Trying to get all of the configs.
> defined(%hash) is deprecated at /usr/lib/rancid/bin/panrancid line 53.
> (Maybe you should just omit the defined()?)
> Paloaltofw1: missed cmd(s): show config running, set
..
>
> Is there a fix for this? I figure the code is just out of date?
>
> Regards,
> Ryan Milton
> MVS Network Manager
> o: 201-447-1505 x124
> c: 862-249-5230
> www.mvsusa.com<http://www.mvsusa.com/>
> [MVS final logo GOOD very small]
>
> From: Hughes, Doug [mailto:***@DEShawResearch.com]
> Sent: Tuesday, September 24, 2013 5:02 PM
> To: Ryan Milton; Kishore Rajani; rancid-***@googlegroups.com<mailto:rancid-***@googlegroups.com>
> Cc: ***@novidys.com<mailto:***@novidys.com>; rancid-***@shrubbery.net<mailto:rancid-***@shrubbery.net>
> Subject: RE: [rancid] Palo Alto Networks
>
> Sure they can. I do it for 3 of them right now.
>
> Attached. Set your ‘switch type’ to paloalto. Works with names or IP addresses.
>
> From: Ryan Milton [mailto:***@mvsusa.com]
> Sent: Tuesday, September 24, 2013 4:58 PM
> To: Hughes, Doug; Kishore Rajani; rancid-***@googlegroups.com<mailto:rancid-***@googlegroups.com>
> Cc: ***@novidys.com<mailto:***@novidys.com>; rancid-***@shrubbery.net<mailto:rancid-***@shrubbery.net>
> Subject: RE: [rancid] Palo Alto Networks
>
> I would certainly be interested in adding PAN devices to Rancid. I thought that they couldn’t be read. That is what I’ve found with my HP switches—but that is another matter. Any ideas on getting PAN devices read by Rancid would be useful.
>
> Regards,
> Ryan Milton
>
> From:rancid-discuss-***@shrubbery.net<mailto:rancid-discuss-***@shrubbery.net> [mailto:rancid-discuss-***@shrubbery.net] On Behalf Of Hughes, Doug
> Sent: Tuesday, September 24, 2013 12:26 PM
> To: Kishore Rajani; rancid-***@googlegroups.com<mailto:rancid-***@googlegroups.com>
> Cc: ***@novidys.com<mailto:***@novidys.com>; rancid-***@shrubbery.net<mailto:rancid-***@shrubbery.net>
> Subject: Re: [rancid] Palo Alto Networks
>
> Yes, I have working panlogin and panrancid and have contributed them upstream. Have you not been able to get them to work?
>
>
> From:rancid-discuss-***@shrubbery.net<mailto:rancid-discuss-***@shrubbery.net> [mailto:rancid-discuss-***@shrubbery.net] On Behalf Of Kishore Rajani
> Sent: Monday, September 23, 2013 9:52 AM
> To: rancid-***@googlegroups.com<mailto:rancid-***@googlegroups.com>
> Cc: ***@novidys.com<mailto:***@novidys.com>; rancid-***@shrubbery.net<mailto:rancid-***@shrubbery.net>
> Subject: Re: [rancid] Palo Alto Networks
>
> HI,
>
> did you manage to get the RANCID running with PAN?
>
> Regards,
> Kishore
>
> On Thursday, 29 March 2012 13:53:33 UTC+1, Guillaume Dupuis wrote:
> Nate Beck <Nate.Beck <at> jivesoftware.com<http://jivesoftware.com>> writes:
>
> >
> >
> > Has anyone on the list worked with Palo Alto Network firewalls and Rancid? I
> was wondering if anyone has created a *login for them.
> > Thanks-------------------
> > Nathan BeckSr. IT Engineer
> > Jive Software
> > 503.972.9024
>
> Hi Nate,
>
> Did you find a *login script for PAN?
>
> Thanks,
>
> Guillaume Dupuis
>
> _______________________________________________
> Rancid-discuss mailing list
> Rancid-***@shrubbery.net
> http://www.shrubbery.net/mailman/listinfo.cgi/rancid-discuss
>

. . . . . . . . . . . . . . . . . . . . . . . . .
Jethro R Binks, Network Manager,
Information Services Directorate, University Of Strathclyde, Glasgow, UK

The University of Strathclyde is a charitable body, registered in
Scotland, number SC015263.
Ryan Milton
2013-09-28 22:52:08 UTC
Permalink
Ok, I "sort of" get your meaning. So, then I find this:

lrwxrwxrwx 1 root root 28 Mar 5 2012 rancid-run -> ../lib/rancid/bin/rancid-run

But How do I edit to "make sure that …account has /usr/lib/rancid/bin "first" in path." ? I looked at /etc/rancid/rancid.conf, and in there, the only path info that I found possibly suspect is this, but I have no idea here. I'm grasping at straws.

TMPDIR=/tmp; export TMPDIR
# Be careful changing this, it affects CVSROOT below.
BASEDIR=/var/lib/rancid; export BASEDIR
PATH=/usr/lib/rancid/bin:/usr/bin:/usr/sbin:/bin:/usr/local/bin:/usr/bin; export PATH
# Location of the CVS/SVN repository. Be careful changing this.



From: <Hughes>, Doug <***@DEShawResearch.com<mailto:***@DEShawResearch.com>>
Date: Saturday, September 28, 2013 6:29 PM
To: Ryan Milton <***@mvsusa.com<mailto:***@mvsusa.com>>, Kishore Rajani <***@gmail.com<mailto:***@gmail.com>>
Cc: "***@novidys.com<mailto:***@novidys.com>" <***@novidys.com<mailto:***@novidys.com>>, "rancid-***@shrubbery.net<mailto:rancid-***@shrubbery.net>" <rancid-***@shrubbery.net<mailto:rancid-***@shrubbery.net>>
Subject: RE: [rancid] Palo Alto Networks

Yeah, that means it is working. It looks like you have a path problem. Make sure that your rancid user account has /usr/lib/rancid/bin first in path.

From: Ryan Milton [mailto:***@mvsusa.com]
Sent: Saturday, September 28, 2013 6:17 PM
To: Hughes, Doug; Kishore Rajani
Cc: ***@novidys.com<mailto:***@novidys.com>; rancid-***@shrubbery.net<mailto:rancid-***@shrubbery.net>
Subject: Re: [rancid] Palo Alto Networks

When I go to the executables directory, /usr/lib/rancid/bin/ and panrancid <device>, or jrancid <device>, etc, I get the same thing: "panrancid: command not found", or "jrancid: command not found." so if I run the panlogin, jlogin, etc, I get into the device, but that’s it.

As I wrote that above message, I just did a "rancid-run" and DID get a revision to my Palo Alto test device. So I guess that is good. I don't really know if that will work here forward, but does that mean that it is working?

Sorry to sound like the noob that I am.

Ryan

From: <Hughes>, Doug <***@DEShawResearch.com<mailto:***@DEShawResearch.com>>
Date: Saturday, September 28, 2013 1:52 PM
To: Ryan Milton <***@mvsusa.com<mailto:***@mvsusa.com>>, Kishore Rajani <***@gmail.com<mailto:***@gmail.com>>
Cc: "***@novidys.com<mailto:***@novidys.com>" <***@novidys.com<mailto:***@novidys.com>>, "rancid-***@shrubbery.net<mailto:rancid-***@shrubbery.net>" <rancid-***@shrubbery.net<mailto:rancid-***@shrubbery.net>>
Subject: RE: [rancid] Palo Alto Networks

1) Become the rancid user
2) make sure that panrancid and panlogin are in your path
3) “panrancid <device>”
After you run it, if it works, you should see a file <device>.new in the current directory.

If it fails, paste the results of this: “panrancid –d <device>”

From: Ryan Milton [mailto:***@mvsusa.com]
Sent: Saturday, September 28, 2013 1:49 PM
To: Hughes, Doug; Kishore Rajani
Cc: ***@novidys.com<mailto:***@novidys.com>; rancid-***@shrubbery.net<mailto:rancid-***@shrubbery.net>
Subject: RE: [rancid] Palo Alto Networks

You ask a few questions. Most of my scripts seem to work, like jrancid, nrancid. Hrancid (for hp?) doesn't seem to work as I get "failed to login" errors.

Does it work if you run panrancid directly on the command line from the bin directory?

-->not sure I know how to do this.

Ryan Milton
MVS Network Manager
O: 201-447-1505 x124
C: 862-249-5230
________________________________
From: Hughes, Doug <***@DEShawResearch.com<mailto:***@DEShawResearch.com>>
Sent: Friday, September 27, 2013 3:57:58 PM
To: Ryan Milton; Kishore Rajani
Cc: ***@novidys.com<mailto:***@novidys.com>; rancid-***@shrubbery.net<mailto:rancid-***@shrubbery.net>
Subject: RE: [rancid] Palo Alto Networks

I have perl 5.8.8. I’m not sure why that would make a significant difference, though.

There are many used of defined in the perl code.. So why would it pick that one? (semi-rhetorical)

It appears to be complaining about the first use of defined. Do other rancid files work ok? ProcessHistory is just lifted from another one, originally.. Does the crancid or hprancid work ok?

Do you have access to an older Perl for testing?

Does it work if you run panrancid directly on the command line from the bin directory?


From: Ryan Milton [mailto:***@mvsusa.com]
Sent: Friday, September 27, 2013 1:23 PM
To: Hughes, Doug; Kishore Rajani
Cc: ***@novidys.com<mailto:***@novidys.com>; rancid-***@shrubbery.net<mailto:rancid-***@shrubbery.net>
Subject: RE: [rancid] Palo Alto Networks

So, the Perl version is perl 5, version 14, subversion 2 (v5.14.2) built for x86_64-linux-gnu-thread-multi

And

***@ObserviumNYC:~$ sum /usr/lib/rancid/bin/panrancid
14180 9

Regards,
Ryan Milton
MVS Network Manager
o: 201-447-1505 x124
c: 862-249-5230
www.mvsusa.com<http://www.mvsusa.com/>
[MVS final logo GOOD very small]

From: Hughes, Doug [mailto:***@DEShawResearch.com]
Sent: Friday, September 27, 2013 11:15 AM
To: Ryan Milton; Kishore Rajani
Cc: ***@novidys.com<mailto:***@novidys.com>; rancid-***@shrubbery.net<mailto:rancid-***@shrubbery.net>
Subject: RE: [rancid] Palo Alto Networks

What version of Perl are you using? That looks like a Perl error. Also, I don’t have a define(%hash) at line 53 in the one I sent you.

What does ‘sum /usr/lib/rancid/bin/panrancid’ say?
It should say
14180 9


From: Ryan Milton [mailto:***@mvsusa.com]
Sent: Friday, September 27, 2013 11:08 AM
To: Hughes, Doug; Kishore Rajani
Cc: ***@novidys.com<mailto:***@novidys.com>; rancid-***@shrubbery.net<mailto:rancid-***@shrubbery.net>
Subject: RE: [rancid] Palo Alto Networks

Hi Doug,

So I am testing your scripts. I got one error:
Trying to get all of the configs.
defined(%hash) is deprecated at /usr/lib/rancid/bin/panrancid line 53.
(Maybe you should just omit the defined()?)
Paloaltofw1: missed cmd(s): show config running, set…..

Is there a fix for this? I figure the code is just out of date?

Regards,
Ryan Milton
MVS Network Manager
o: 201-447-1505 x124
c: 862-249-5230
www.mvsusa.com<http://www.mvsusa.com/>
[MVS final logo GOOD very small]

From: Hughes, Doug [mailto:***@DEShawResearch.com]
Sent: Tuesday, September 24, 2013 5:02 PM
To: Ryan Milton; Kishore Rajani; rancid-***@googlegroups.com<mailto:rancid-***@googlegroups.com>
Cc: ***@novidys.com<mailto:***@novidys.com>; rancid-***@shrubbery.net<mailto:rancid-***@shrubbery.net>
Subject: RE: [rancid] Palo Alto Networks

Sure they can. I do it for 3 of them right now.

Attached. Set your ‘switch type’ to paloalto. Works with names or IP addresses.

From: Ryan Milton [mailto:***@mvsusa.com]
Sent: Tuesday, September 24, 2013 4:58 PM
To: Hughes, Doug; Kishore Rajani; rancid-***@googlegroups.com<mailto:rancid-***@googlegroups.com>
Cc: ***@novidys.com<mailto:***@novidys.com>; rancid-***@shrubbery.net<mailto:rancid-***@shrubbery.net>
Subject: RE: [rancid] Palo Alto Networks

I would certainly be interested in adding PAN devices to Rancid. I thought that they couldn’t be read. That is what I’ve found with my HP switches—but that is another matter. Any ideas on getting PAN devices read by Rancid would be useful.

Regards,
Ryan Milton

From:rancid-discuss-***@shrubbery.net<mailto:rancid-discuss-***@shrubbery.net> [mailto:rancid-discuss-***@shrubbery.net] On Behalf Of Hughes, Doug
Sent: Tuesday, September 24, 2013 12:26 PM
To: Kishore Rajani; rancid-***@googlegroups.com<mailto:rancid-***@googlegroups.com>
Cc: ***@novidys.com<mailto:***@novidys.com>; rancid-***@shrubbery.net<mailto:rancid-***@shrubbery.net>
Subject: Re: [rancid] Palo Alto Networks

Yes, I have working panlogin and panrancid and have contributed them upstream. Have you not been able to get them to work?


From:rancid-discuss-***@shrubbery.net<mailto:rancid-discuss-***@shrubbery.net> [mailto:rancid-discuss-***@shrubbery.net] On Behalf Of Kishore Rajani
Sent: Monday, September 23, 2013 9:52 AM
To: rancid-***@googlegroups.com<mailto:rancid-***@googlegroups.com>
Cc: ***@novidys.com<mailto:***@novidys.com>; rancid-***@shrubbery.net<mailto:rancid-***@shrubbery.net>
Subject: Re: [rancid] Palo Alto Networks

HI,

did you manage to get the RANCID running with PAN?

Regards,
Kishore

On Thursday, 29 March 2012 13:53:33 UTC+1, Guillaume Dupuis wrote:
Nate Beck <Nate.Beck <at> jivesoftware.com<http://jivesoftware.com>> writes:

>
>
> Has anyone on the list worked with Palo Alto Network firewalls and Rancid? I
was wondering if anyone has created a *login for them.
> Thanks-------------------
> Nathan BeckSr. IT Engineer
> Jive Software
> 503.972.9024

Hi Nate,

Did you find a *login script for PAN?

Thanks,

Guillaume Dupuis
Roy
2013-09-28 23:16:29 UTC
Permalink
<html>
<head>
<meta content="text/html; charset=ISO-8859-1"
http-equiv="Content-Type">
</head>
<body text="#000000" bgcolor="#FFFFFF">
<div class="moz-cite-prefix"><br>
<br>
We are talking the path that the command interpreter is using<br>
<br>
Try something like<br>
<br>
&nbsp;&nbsp;&nbsp; export PATH=$PATH:/usr/lib/rancid/bin<br>
<br>
and then the commands you want to use<br>
<br>
The rancid.conf file is only used by rancid-run and not by the
individual commands<br>
<br>
On 9/28/2013 3:52 PM, Ryan Milton wrote:<br>
</div>
<blockquote cite="mid:CE6CD120.2236%***@mvsusa.com"
type="cite">
<meta http-equiv="Content-Type" content="text/html;
charset=ISO-8859-1">
<div>Ok, I "sort of" get your meaning. So, then I find this:&nbsp;</div>
<div><br>
</div>
<div>lrwxrwxrwx 1 root &nbsp; root &nbsp; &nbsp; &nbsp; &nbsp; 28 Mar &nbsp;5 &nbsp;2012 rancid-run
-&gt; ../lib/rancid/bin/rancid-run</div>
<div><br>
</div>
<div>But How do I edit to "make sure that &#8230;account has
/usr/lib/rancid/bin "first" in path." ? I looked at
/etc/rancid/rancid.conf, and in there, the only path info that I
found possibly suspect is this, but I have no idea here. I'm
grasping at straws.</div>
<div><br>
</div>
<div>
<div>TMPDIR=/tmp; export TMPDIR</div>
<div># Be careful changing this, it affects CVSROOT below.</div>
<div>BASEDIR=/var/lib/rancid; export BASEDIR</div>
<div>PATH=/usr/lib/rancid/bin:/usr/bin:/usr/sbin:/bin:/usr/<span
style="background-color: rgb(255, 255, 0);">local/</span>bin:/usr/bin;
export PATH</div>
<div># Location of the CVS/SVN repository. &nbsp;Be careful changing
this.</div>
</div>
<div><br>
</div>
<div><br>
</div>
<div><br>
</div>
<span id="OLK_SRC_BODY_SECTION"></span><br>
</blockquote>
<br>
</body>
</html>
Hughes, Doug
2013-09-28 23:23:20 UTC
Permalink
If the rancid user is using the /bin/bash, /bin/sh, or /bin/ksh shell add this to ~rancid/.bash_profile

PATH=/usr/lib/rancid/bin:$PATH
export PATH

If the rancid user is using /bin/tcsh or /bin/csh or something like that add this to .cshrc
set path=(/usr/lib/rancid/bin $path)

then start a fresh login shell as rancid user (ssh, login, whatever) and try the commands again. They should work.

grep rancid /etc/passwd to get the shell. It should be at the end of the line.

From: Ryan Milton [mailto:***@mvsusa.com]
Sent: Saturday, September 28, 2013 6:52 PM
To: Hughes, Doug; Kishore Rajani
Cc: ***@novidys.com; rancid-***@shrubbery.net
Subject: Re: [rancid] Palo Alto Networks

Ok, I "sort of" get your meaning. So, then I find this:

lrwxrwxrwx 1 root root 28 Mar 5 2012 rancid-run -> ../lib/rancid/bin/rancid-run

But How do I edit to "make sure that ...account has /usr/lib/rancid/bin "first" in path." ? I looked at /etc/rancid/rancid.conf, and in there, the only path info that I found possibly suspect is this, but I have no idea here. I'm grasping at straws.

TMPDIR=/tmp; export TMPDIR
# Be careful changing this, it affects CVSROOT below.
BASEDIR=/var/lib/rancid; export BASEDIR
PATH=/usr/lib/rancid/bin:/usr/bin:/usr/sbin:/bin:/usr/local/bin:/usr/bin; export PATH
# Location of the CVS/SVN repository. Be careful changing this.



From: <Hughes>, Doug <***@DEShawResearch.com<mailto:***@DEShawResearch.com>>
Date: Saturday, September 28, 2013 6:29 PM
To: Ryan Milton <***@mvsusa.com<mailto:***@mvsusa.com>>, Kishore Rajani <***@gmail.com<mailto:***@gmail.com>>
Cc: "***@novidys.com<mailto:***@novidys.com>" <***@novidys.com<mailto:***@novidys.com>>, "rancid-***@shrubbery.net<mailto:rancid-***@shrubbery.net>" <rancid-***@shrubbery.net<mailto:rancid-***@shrubbery.net>>
Subject: RE: [rancid] Palo Alto Networks

Yeah, that means it is working. It looks like you have a path problem. Make sure that your rancid user account has /usr/lib/rancid/bin first in path.

From: Ryan Milton [mailto:***@mvsusa.com]
Sent: Saturday, September 28, 2013 6:17 PM
To: Hughes, Doug; Kishore Rajani
Cc: ***@novidys.com<mailto:***@novidys.com>; rancid-***@shrubbery.net<mailto:rancid-***@shrubbery.net>
Subject: Re: [rancid] Palo Alto Networks

When I go to the executables directory, /usr/lib/rancid/bin/ and panrancid <device>, or jrancid <device>, etc, I get the same thing: "panrancid: command not found", or "jrancid: command not found." so if I run the panlogin, jlogin, etc, I get into the device, but that's it.

As I wrote that above message, I just did a "rancid-run" and DID get a revision to my Palo Alto test device. So I guess that is good. I don't really know if that will work here forward, but does that mean that it is working?

Sorry to sound like the noob that I am.

Ryan

From: <Hughes>, Doug <***@DEShawResearch.com<mailto:***@DEShawResearch.com>>
Date: Saturday, September 28, 2013 1:52 PM
To: Ryan Milton <***@mvsusa.com<mailto:***@mvsusa.com>>, Kishore Rajani <***@gmail.com<mailto:***@gmail.com>>
Cc: "***@novidys.com<mailto:***@novidys.com>" <***@novidys.com<mailto:***@novidys.com>>, "rancid-***@shrubbery.net<mailto:rancid-***@shrubbery.net>" <rancid-***@shrubbery.net<mailto:rancid-***@shrubbery.net>>
Subject: RE: [rancid] Palo Alto Networks

1) Become the rancid user
2) make sure that panrancid and panlogin are in your path
3) "panrancid <device>"
After you run it, if it works, you should see a file <device>.new in the current directory.

If it fails, paste the results of this: "panrancid -d <device>"

From: Ryan Milton [mailto:***@mvsusa.com]
Sent: Saturday, September 28, 2013 1:49 PM
To: Hughes, Doug; Kishore Rajani
Cc: ***@novidys.com<mailto:***@novidys.com>; rancid-***@shrubbery.net<mailto:rancid-***@shrubbery.net>
Subject: RE: [rancid] Palo Alto Networks

You ask a few questions. Most of my scripts seem to work, like jrancid, nrancid. Hrancid (for hp?) doesn't seem to work as I get "failed to login" errors.

Does it work if you run panrancid directly on the command line from the bin directory?

-->not sure I know how to do this.

Ryan Milton
MVS Network Manager
O: 201-447-1505 x124
C: 862-249-5230
________________________________
From: Hughes, Doug <***@DEShawResearch.com<mailto:***@DEShawResearch.com>>
Sent: Friday, September 27, 2013 3:57:58 PM
To: Ryan Milton; Kishore Rajani
Cc: ***@novidys.com<mailto:***@novidys.com>; rancid-***@shrubbery.net<mailto:rancid-***@shrubbery.net>
Subject: RE: [rancid] Palo Alto Networks

I have perl 5.8.8. I'm not sure why that would make a significant difference, though.

There are many used of defined in the perl code.. So why would it pick that one? (semi-rhetorical)

It appears to be complaining about the first use of defined. Do other rancid files work ok? ProcessHistory is just lifted from another one, originally.. Does the crancid or hprancid work ok?

Do you have access to an older Perl for testing?

Does it work if you run panrancid directly on the command line from the bin directory?


From: Ryan Milton [mailto:***@mvsusa.com]
Sent: Friday, September 27, 2013 1:23 PM
To: Hughes, Doug; Kishore Rajani
Cc: ***@novidys.com<mailto:***@novidys.com>; rancid-***@shrubbery.net<mailto:rancid-***@shrubbery.net>
Subject: RE: [rancid] Palo Alto Networks

So, the Perl version is perl 5, version 14, subversion 2 (v5.14.2) built for x86_64-linux-gnu-thread-multi

And

***@ObserviumNYC:~$ sum /usr/lib/rancid/bin/panrancid
14180 9

Regards,
Ryan Milton
MVS Network Manager
o: 201-447-1505 x124
c: 862-249-5230
www.mvsusa.com<http://www.mvsusa.com/>
[MVS final logo GOOD very small]

From: Hughes, Doug [mailto:***@DEShawResearch.com]
Sent: Friday, September 27, 2013 11:15 AM
To: Ryan Milton; Kishore Rajani
Cc: ***@novidys.com<mailto:***@novidys.com>; rancid-***@shrubbery.net<mailto:rancid-***@shrubbery.net>
Subject: RE: [rancid] Palo Alto Networks

What version of Perl are you using? That looks like a Perl error. Also, I don't have a define(%hash) at line 53 in the one I sent you.

What does 'sum /usr/lib/rancid/bin/panrancid' say?
It should say
14180 9


From: Ryan Milton [mailto:***@mvsusa.com]
Sent: Friday, September 27, 2013 11:08 AM
To: Hughes, Doug; Kishore Rajani
Cc: ***@novidys.com<mailto:***@novidys.com>; rancid-***@shrubbery.net<mailto:rancid-***@shrubbery.net>
Subject: RE: [rancid] Palo Alto Networks

Hi Doug,

So I am testing your scripts. I got one error:
Trying to get all of the configs.
defined(%hash) is deprecated at /usr/lib/rancid/bin/panrancid line 53.
(Maybe you should just omit the defined()?)
Paloaltofw1: missed cmd(s): show config running, set.....

Is there a fix for this? I figure the code is just out of date?

Regards,
Ryan Milton
MVS Network Manager
o: 201-447-1505 x124
c: 862-249-5230
www.mvsusa.com<http://www.mvsusa.com/>
[MVS final logo GOOD very small]

From: Hughes, Doug [mailto:***@DEShawResearch.com]
Sent: Tuesday, September 24, 2013 5:02 PM
To: Ryan Milton; Kishore Rajani; rancid-***@googlegroups.com<mailto:rancid-***@googlegroups.com>
Cc: ***@novidys.com<mailto:***@novidys.com>; rancid-***@shrubbery.net<mailto:rancid-***@shrubbery.net>
Subject: RE: [rancid] Palo Alto Networks

Sure they can. I do it for 3 of them right now.

Attached. Set your 'switch type' to paloalto. Works with names or IP addresses.

From: Ryan Milton [mailto:***@mvsusa.com]
Sent: Tuesday, September 24, 2013 4:58 PM
To: Hughes, Doug; Kishore Rajani; rancid-***@googlegroups.com<mailto:rancid-***@googlegroups.com>
Cc: ***@novidys.com<mailto:***@novidys.com>; rancid-***@shrubbery.net<mailto:rancid-***@shrubbery.net>
Subject: RE: [rancid] Palo Alto Networks

I would certainly be interested in adding PAN devices to Rancid. I thought that they couldn't be read. That is what I've found with my HP switches-but that is another matter. Any ideas on getting PAN devices read by Rancid would be useful.

Regards,
Ryan Milton

From:rancid-discuss-***@shrubbery.net<mailto:rancid-discuss-***@shrubbery.net> [mailto:rancid-discuss-***@shrubbery.net] On Behalf Of Hughes, Doug
Sent: Tuesday, September 24, 2013 12:26 PM
To: Kishore Rajani; rancid-***@googlegroups.com<mailto:rancid-***@googlegroups.com>
Cc: ***@novidys.com<mailto:***@novidys.com>; rancid-***@shrubbery.net<mailto:rancid-***@shrubbery.net>
Subject: Re: [rancid] Palo Alto Networks

Yes, I have working panlogin and panrancid and have contributed them upstream. Have you not been able to get them to work?


From:rancid-discuss-***@shrubbery.net<mailto:rancid-discuss-***@shrubbery.net> [mailto:rancid-discuss-***@shrubbery.net] On Behalf Of Kishore Rajani
Sent: Monday, September 23, 2013 9:52 AM
To: rancid-***@googlegroups.com<mailto:rancid-***@googlegroups.com>
Cc: ***@novidys.com<mailto:***@novidys.com>; rancid-***@shrubbery.net<mailto:rancid-***@shrubbery.net>
Subject: Re: [rancid] Palo Alto Networks

HI,

did you manage to get the RANCID running with PAN?

Regards,
Kishore

On Thursday, 29 March 2012 13:53:33 UTC+1, Guillaume Dupuis wrote:
Nate Beck <Nate.Beck <at> jivesoftware.com<http://jivesoftware.com>> writes:

>
>
> Has anyone on the list worked with Palo Alto Network firewalls and Rancid? I
was wondering if anyone has created a *login for them.
> Thanks-------------------
> Nathan BeckSr. IT Engineer
> Jive Software
> 503.972.9024

Hi Nate,

Did you find a *login script for PAN?

Thanks,

Guillaume Dupuis
Loading...