<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Multiple remote site firewall commit errors/failures after Panorama 10.2 upgrade in Next-Generation Firewall Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/multiple-remote-site-firewall-commit-errors-failures-after/m-p/556198#M1794</link>
    <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/153072"&gt;@NeonNetSec&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have not seen this before.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;To answer #2, to push template values to a newly imported NGFW, you need to select Force Template Values.&amp;nbsp; I would definitely have Automated Commit Recovery enabled before this as it will override your network values.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;With regard to #1, it looks like most of your errors are Network related.&amp;nbsp; Open up the GUI, override and check the config, then save.&amp;nbsp; Sometimes this will fix the syntax error in the XML.&amp;nbsp; Do this everywhere you get an error.&amp;nbsp; You could also try looking at the config in the CLI.&amp;nbsp; Sometimes the syntax errors are easy to spot and fix there.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I try not to keep my NGFWs and Panorama versions too far apart.&amp;nbsp; A bigger difference between versions means a bigger chance of a commit error.&amp;nbsp; I upgrade Panorama and then upgrade NGFWs for each version.&amp;nbsp; I know this is not much help for you now.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;</description>
    <pubDate>Fri, 01 Sep 2023 19:41:15 GMT</pubDate>
    <dc:creator>TomYoung</dc:creator>
    <dc:date>2023-09-01T19:41:15Z</dc:date>
    <item>
      <title>Multiple remote site firewall commit errors/failures after Panorama 10.2 upgrade</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/multiple-remote-site-firewall-commit-errors-failures-after/m-p/555998#M1785</link>
      <description>&lt;P&gt;Hey all,&lt;BR /&gt;Recently step-upgraded Panorama from 9.1.14-h4 to 10.2.4-h4. No issues upgrading Panorama. This panorama manages 180+ remote site firewalls. Ever since the upgrade we have *a few* remote site firewalls that are failing to commit properly in 2 ways:&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;1. commit failures related to particular configuration items, mostly specific interfaces and dhcp configurations, that should work, are present on the device, and have worked prior to upgrade (example below)&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="chantilly-error.PNG" style="width: 544px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/53323i6B1CE402C719F21B/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="chantilly-error.PNG" alt="chantilly-error.PNG" /&gt;&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;2. if we do some exhaustive troubleshooting, try to remove and re-import/connect the devices to panorama then commits will succeed again without error but most Template settings, like Network tab, will NOT propagate down to the remote site firewall&lt;BR /&gt;&lt;BR /&gt;We've worked w/ Palo TAC a bit on this. Originally we found that some of the problematic firewalls were on 9.1.x versions so there were configuration transforms happening that could have been problematic, but upgrading these remote site firewall to 10.2.x did not resolve the issue either.&lt;BR /&gt;&lt;BR /&gt;Only other interesting item found is error messages related to Xpath error : invalid expression for a particular interface:&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="MicrosoftTeams-image (2).png" style="width: 906px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/53322iDE8F2EC9FA8E88A8/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="MicrosoftTeams-image (2).png" alt="MicrosoftTeams-image (2).png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;DIV id="tinyMceEditorTimothyHicks_0" class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;P&gt;Has anyone seen this before or have any thoughts? Thanks.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 31 Aug 2023 12:08:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/multiple-remote-site-firewall-commit-errors-failures-after/m-p/555998#M1785</guid>
      <dc:creator>NeonNetSec</dc:creator>
      <dc:date>2023-08-31T12:08:02Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple remote site firewall commit errors/failures after Panorama 10.2 upgrade</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/multiple-remote-site-firewall-commit-errors-failures-after/m-p/556192#M1793</link>
      <description>&lt;P&gt;I have a question, Do you validate if was have same errors before the upgrade? I think same issue but I don't know it's necessary apply commit (after upgrade apply commit) for the all users admin and appears the commit successfully.&lt;/P&gt;</description>
      <pubDate>Fri, 01 Sep 2023 18:52:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/multiple-remote-site-firewall-commit-errors-failures-after/m-p/556192#M1793</guid>
      <dc:creator>felipeorozco</dc:creator>
      <dc:date>2023-09-01T18:52:08Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple remote site firewall commit errors/failures after Panorama 10.2 upgrade</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/multiple-remote-site-firewall-commit-errors-failures-after/m-p/556198#M1794</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/153072"&gt;@NeonNetSec&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have not seen this before.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;To answer #2, to push template values to a newly imported NGFW, you need to select Force Template Values.&amp;nbsp; I would definitely have Automated Commit Recovery enabled before this as it will override your network values.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;With regard to #1, it looks like most of your errors are Network related.&amp;nbsp; Open up the GUI, override and check the config, then save.&amp;nbsp; Sometimes this will fix the syntax error in the XML.&amp;nbsp; Do this everywhere you get an error.&amp;nbsp; You could also try looking at the config in the CLI.&amp;nbsp; Sometimes the syntax errors are easy to spot and fix there.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I try not to keep my NGFWs and Panorama versions too far apart.&amp;nbsp; A bigger difference between versions means a bigger chance of a commit error.&amp;nbsp; I upgrade Panorama and then upgrade NGFWs for each version.&amp;nbsp; I know this is not much help for you now.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;</description>
      <pubDate>Fri, 01 Sep 2023 19:41:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/multiple-remote-site-firewall-commit-errors-failures-after/m-p/556198#M1794</guid>
      <dc:creator>TomYoung</dc:creator>
      <dc:date>2023-09-01T19:41:15Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple remote site firewall commit errors/failures after Panorama 10.2 upgrade</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/multiple-remote-site-firewall-commit-errors-failures-after/m-p/556535#M1798</link>
      <description>&lt;P&gt;Neither solution helped, unfortunately. Issue (commit failures) and errors persist as before.&lt;/P&gt;</description>
      <pubDate>Tue, 05 Sep 2023 13:53:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/multiple-remote-site-firewall-commit-errors-failures-after/m-p/556535#M1798</guid>
      <dc:creator>NeonNetSec</dc:creator>
      <dc:date>2023-09-05T13:53:56Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple remote site firewall commit errors/failures after Panorama 10.2 upgrade</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/multiple-remote-site-firewall-commit-errors-failures-after/m-p/562924#M1994</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/153072"&gt;@NeonNetSec&lt;/a&gt;&amp;nbsp;did you ever find a resolution for this?&amp;nbsp; Have a similar situation with panorama and devices at 11.02.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 24 Oct 2023 11:47:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/multiple-remote-site-firewall-commit-errors-failures-after/m-p/562924#M1994</guid>
      <dc:creator>TripleThreat</dc:creator>
      <dc:date>2023-10-24T11:47:13Z</dc:date>
    </item>
  </channel>
</rss>

