<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Validation Error for High availability in Next-Generation Firewall Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/validation-error-for-high-availability/m-p/592989#M3489</link>
    <description>&lt;P&gt;Hello,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Have you configured interfaces dedicated for HA1 and HA2 and the configuration dedicated to HA1?&lt;/P&gt;</description>
    <pubDate>Thu, 25 Jul 2024 09:55:24 GMT</pubDate>
    <dc:creator>RomainSalmon</dc:creator>
    <dc:date>2024-07-25T09:55:24Z</dc:date>
    <item>
      <title>Validation Error for High availability</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/validation-error-for-high-availability/m-p/590409#M3354</link>
      <description>&lt;P&gt;The error message when commiting is:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Validation Error:&lt;/LI&gt;
&lt;LI&gt;deviceconfig -&amp;gt; high-availability -&amp;gt; group -&amp;gt; state-synchronization unexpected here&lt;/LI&gt;
&lt;LI&gt;deviceconfig -&amp;gt; high-availability -&amp;gt; group -&amp;gt; state-synchronization is invalid&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;I configured high availability using yaml ansible code. After enabling high availability, and setting up a few stuff, I am facing this error. I am not sure what I am missing. I am following the CIS benchmark for the palo alto firewall.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;3.1:&lt;/P&gt;
&lt;P&gt;- name: Set HA2 enabled&lt;/P&gt;
&lt;P&gt;&amp;nbsp; panos_type_cmd:&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; provider: '{{ provider }}'&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; xpath: |&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; /config/devices/entry[@name='localhost.localdomain']&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; /deviceconfig/high-availability&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; element: |&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;lt;enabled&amp;gt;yes&amp;lt;/enabled&amp;gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;group&amp;gt;&amp;lt;group-id&amp;gt;1&amp;lt;/group-id&amp;gt;&amp;lt;/group&amp;gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;- name: Ensure a fully synchronized High Availability peer is configured&lt;/P&gt;
&lt;P&gt;&amp;nbsp; panos_type_cmd:&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; provider: '{{ provider }}'&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; xpath: |&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; /config/devices/entry[@name='localhost.localdomain']&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; /deviceconfig/high-availability/group/state-synchronization&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; element: |&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;lt;enabled&amp;gt;yes&amp;lt;/enabled&amp;gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;lt;transport&amp;gt;udp&amp;lt;/transport&amp;gt; #ethernet/ip/udp&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;- name: Set HA2&lt;/P&gt;
&lt;P&gt;&amp;nbsp; panos_type_cmd:&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; provider: '{{ provider }}'&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; xpath: |&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; /config/devices/entry[@name='localhost.localdomain']&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; /deviceconfig/high-availability/interface/ha2&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; element: |&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;lt;ip-address&amp;gt;1.1.1.2&amp;lt;/ip-address&amp;gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;lt;netmask&amp;gt;255.0.0.0&amp;lt;/netmask&amp;gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;lt;gateway&amp;gt;1.1.1.1&amp;lt;/gateway&amp;gt;&lt;/P&gt;
&lt;P&gt;&lt;LI-WRAPPER&gt;&lt;/LI-WRAPPER&gt;&lt;BR /&gt;3.2:&lt;/P&gt;
&lt;P&gt;- name: Configure Link Monitoring&lt;/P&gt;
&lt;P&gt;&amp;nbsp; panos_type_cmd:&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; provider: '{{ provider }}'&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; xpath: |&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; /config/devices/entry[@name='localhost.localdomain']&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; /deviceconfig/high-availability/group/monitoring/link-monitoring&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; element: |&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;lt;enabled&amp;gt;yes&amp;lt;/enabled&amp;gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;lt;failure-condition&amp;gt;any&amp;lt;/failure-condition&amp;gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;- name: Configure Path Monitoring&lt;/P&gt;
&lt;P&gt;&amp;nbsp; panos_type_cmd:&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; provider: '{{ provider }}'&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; xpath: |&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; /config/devices/entry[@name='localhost.localdomain']&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; /deviceconfig/high-availability/group/monitoring/path-monitoring&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; element: |&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;enabled&amp;gt;yes&amp;lt;/enabled&amp;gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;failure-condition&amp;gt;any&amp;lt;/failure-condition&amp;gt;&lt;/P&gt;
&lt;P&gt;&lt;LI-WRAPPER&gt;&lt;/LI-WRAPPER&gt;&lt;BR /&gt;3.3:&lt;/P&gt;
&lt;P&gt;- name: Set passive-link-state auto&lt;/P&gt;
&lt;P&gt;&amp;nbsp; panos_type_cmd:&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; provider: '{{ provider }}'&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; xpath: |&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; /config/devices/entry[@name='localhost.localdomain']&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; /deviceconfig/high-availability/group/mode/active-passive&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; element: |&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;lt;passive-link-state&amp;gt;auto&amp;lt;/passive-link-state&amp;gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;- name: Disable Preemptive&lt;/P&gt;
&lt;P&gt;&amp;nbsp; panos_type_cmd:&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; provider: '{{ provider }}'&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; xpath: |&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; /config/devices/entry[@name='localhost.localdomain']&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; /deviceconfig/high-availability/group/election-option&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; element: |&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;lt;preemptive&amp;gt;no&amp;lt;/preemptive&amp;gt;&lt;/P&gt;
&lt;P&gt;&lt;LI-WRAPPER&gt;&lt;/LI-WRAPPER&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 26 Jun 2024 06:01:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/validation-error-for-high-availability/m-p/590409#M3354</guid>
      <dc:creator>shanjing</dc:creator>
      <dc:date>2024-06-26T06:01:31Z</dc:date>
    </item>
    <item>
      <title>Re: Validation Error for High availability</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/validation-error-for-high-availability/m-p/592989#M3489</link>
      <description>&lt;P&gt;Hello,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Have you configured interfaces dedicated for HA1 and HA2 and the configuration dedicated to HA1?&lt;/P&gt;</description>
      <pubDate>Thu, 25 Jul 2024 09:55:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/validation-error-for-high-availability/m-p/592989#M3489</guid>
      <dc:creator>RomainSalmon</dc:creator>
      <dc:date>2024-07-25T09:55:24Z</dc:date>
    </item>
  </channel>
</rss>

