<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Errors and commit warnings after 11.1.2-h3 upgrade in Next-Generation Firewall Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/errors-and-commit-warnings-after-11-1-2-h3-upgrade/m-p/600130#M3862</link>
    <description>&lt;P&gt;I am also seeing this on multiple PA-850's since moving to 11.1.4-h1:&lt;/P&gt;
&lt;P&gt;Local configuration size: 429 KB&lt;BR /&gt;Predefined configuration size: 18 MB&lt;BR /&gt;Merged configuration size(local, panorama pushed, predefined): 20 MB&lt;BR /&gt;Maximum recommended merged configuration size: 23 MB (86% configured)&lt;/P&gt;</description>
    <pubDate>Thu, 10 Oct 2024 21:43:08 GMT</pubDate>
    <dc:creator>Jpergolizzi</dc:creator>
    <dc:date>2024-10-10T21:43:08Z</dc:date>
    <item>
      <title>Errors and commit warnings after 11.1.2-h3 upgrade</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/errors-and-commit-warnings-after-11-1-2-h3-upgrade/m-p/590150#M3350</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;If anyone could shed some light on the issue below, it would be greatly appreciated. Since upgrading my PA-440 to 11.1.2-h3 (preferred version), I am seeing the following two issues:&lt;/P&gt;
&lt;P&gt;1. Every 5 minutes, there is a system log error:&lt;BR /&gt;&lt;EM&gt;Failed to perform task resulting in connection timeout with WildFire Cloud wildfire.paloaltonetworks.com&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;2. After committing changes to the firewall, the following is observed:&lt;BR /&gt;&lt;EM&gt;Configuration committed successfully&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;Local configuration size: 174 KB&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;Predefined configuration size: 17 MB&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;Merged configuration size(local, panorama pushed, predefined): 18 MB&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;Maximum recommended merged configuration size: 35 MB (51% configured)&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;Anyone else experiencing these issues or have some kind of idea what has happened or how to fix it?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;G&lt;/P&gt;</description>
      <pubDate>Sun, 23 Jun 2024 11:26:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/errors-and-commit-warnings-after-11-1-2-h3-upgrade/m-p/590150#M3350</guid>
      <dc:creator>GregorJus</dc:creator>
      <dc:date>2024-06-23T11:26:39Z</dc:date>
    </item>
    <item>
      <title>Re: Errors and commit warnings after 11.1.2-h3 upgrade</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/errors-and-commit-warnings-after-11-1-2-h3-upgrade/m-p/590730#M3364</link>
      <description>&lt;P&gt;Same issue here. Upgraded from 10.2.8-h3 to 11.1.2-h3 on a VM series KVM firewall.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;If ospf router ID changed,it require restart ospf processor(Module: routed)
client routed phase 1 failure
Commit failed
Local configuration size: 7 KB
Predefined configuration size: 17 MB
Merged configuration size(local, panorama pushed, predefined): 18 MB
Maximum recommended merged configuration size: 17 MB (105% configured)
Failed to commit policy to device&lt;/LI-CODE&gt;</description>
      <pubDate>Fri, 28 Jun 2024 19:15:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/errors-and-commit-warnings-after-11-1-2-h3-upgrade/m-p/590730#M3364</guid>
      <dc:creator>MeCJay12</dc:creator>
      <dc:date>2024-06-28T19:15:48Z</dc:date>
    </item>
    <item>
      <title>Re: Errors and commit warnings after 11.1.2-h3 upgrade</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/errors-and-commit-warnings-after-11-1-2-h3-upgrade/m-p/591146#M3376</link>
      <description>&lt;P&gt;Same issue here with the 17MB limit. Need a fix for this asap.&lt;/P&gt;</description>
      <pubDate>Thu, 04 Jul 2024 04:03:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/errors-and-commit-warnings-after-11-1-2-h3-upgrade/m-p/591146#M3376</guid>
      <dc:creator>P.Piro</dc:creator>
      <dc:date>2024-07-04T04:03:20Z</dc:date>
    </item>
    <item>
      <title>Re: Errors and commit warnings after 11.1.2-h3 upgrade</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/errors-and-commit-warnings-after-11-1-2-h3-upgrade/m-p/591147#M3377</link>
      <description>&lt;P&gt;Apart from the limit "issue", can anyone shed some light on the the matter of:&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;Failed to perform task resulting in connection timeout with WildFire Cloud wildfire.paloaltonetworks.com&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I am loosing my mind &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 04 Jul 2024 06:05:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/errors-and-commit-warnings-after-11-1-2-h3-upgrade/m-p/591147#M3377</guid>
      <dc:creator>GregorJus</dc:creator>
      <dc:date>2024-07-04T06:05:04Z</dc:date>
    </item>
    <item>
      <title>Re: Errors and commit warnings after 11.1.2-h3 upgrade</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/errors-and-commit-warnings-after-11-1-2-h3-upgrade/m-p/600130#M3862</link>
      <description>&lt;P&gt;I am also seeing this on multiple PA-850's since moving to 11.1.4-h1:&lt;/P&gt;
&lt;P&gt;Local configuration size: 429 KB&lt;BR /&gt;Predefined configuration size: 18 MB&lt;BR /&gt;Merged configuration size(local, panorama pushed, predefined): 20 MB&lt;BR /&gt;Maximum recommended merged configuration size: 23 MB (86% configured)&lt;/P&gt;</description>
      <pubDate>Thu, 10 Oct 2024 21:43:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/errors-and-commit-warnings-after-11-1-2-h3-upgrade/m-p/600130#M3862</guid>
      <dc:creator>Jpergolizzi</dc:creator>
      <dc:date>2024-10-10T21:43:08Z</dc:date>
    </item>
    <item>
      <title>Re: Errors and commit warnings after 11.1.2-h3 upgrade</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/errors-and-commit-warnings-after-11-1-2-h3-upgrade/m-p/600206#M3864</link>
      <description>&lt;P&gt;It sounds like you're running into configuration size issues after upgrading to 11.1.4-h1 on the PA-850s. The merged config size being at 86% of the max recommended could definitely be a cause for concern, especially as you continue to push updates or add new policies. Have you tried reaching out to Palo Alto support to see if there's a way to optimize the config? Sometimes there are unused objects or old rules that can be cleaned up to reduce the overall size. Alternatively, it might be worth monitoring it closely and planning for a more efficient setup if you anticipate growth.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 11 Oct 2024 06:39:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/errors-and-commit-warnings-after-11-1-2-h3-upgrade/m-p/600206#M3864</guid>
      <dc:creator>suzannomer258</dc:creator>
      <dc:date>2024-10-11T06:39:47Z</dc:date>
    </item>
    <item>
      <title>Re: Errors and commit warnings after 11.1.2-h3 upgrade</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/errors-and-commit-warnings-after-11-1-2-h3-upgrade/m-p/615883#M4926</link>
      <description>&lt;P&gt;Hi there, thanks for responding! yes, I believe that's exactly whats going on. I've cleaned up my config but in looking at whats taking the space, the majority of it is the pre-defined data sent from Palo Alto. I'm hoping they have a way to trim that down, it will be a hard-sell to my client to purchase new firewalls. &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 31 Oct 2024 17:48:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/errors-and-commit-warnings-after-11-1-2-h3-upgrade/m-p/615883#M4926</guid>
      <dc:creator>Jpergolizzi</dc:creator>
      <dc:date>2024-10-31T17:48:44Z</dc:date>
    </item>
    <item>
      <title>Re: Errors and commit warnings after 11.1.2-h3 upgrade</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/errors-and-commit-warnings-after-11-1-2-h3-upgrade/m-p/996761#M5172</link>
      <description>&lt;P&gt;Have you heard anything back from Palo Alto in regard to trim the predefined config? We just got his with a full 1MB change overnight for their predefined config and it is annoying that Palo Alto is doing this. I guess it's their way of forcing people to upgrade, yet their newer firewalls aren't that high in max config size &amp;amp; they can't be straight forward how much will this increase over the years. I seriously feel like Palo Alto has gone south on their products. We are actively considering moving to another vendor due to this. Our config is very small and we even removed any unused items. Support has gone nowhere for a solution, just stated we should upgrade and yet our firewalls aren't EOL until 2029.&lt;/P&gt;</description>
      <pubDate>Thu, 05 Dec 2024 16:25:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/errors-and-commit-warnings-after-11-1-2-h3-upgrade/m-p/996761#M5172</guid>
      <dc:creator>DZamudio</dc:creator>
      <dc:date>2024-12-05T16:25:29Z</dc:date>
    </item>
    <item>
      <title>Re: Errors and commit warnings after 11.1.2-h3 upgrade</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/errors-and-commit-warnings-after-11-1-2-h3-upgrade/m-p/996770#M5173</link>
      <description>&lt;P&gt;Hi there. Unfortunately, I haven't had a chance to speak with them yet about it but planning to. I've got 2 clients with PA-850's and PA-220s and all devices are reporting the issue. My suspicion is that it's pre-defined config and dynamically downloaded content like threat signatures, etc, etc. Not sure if anything can be done about that. I will open a case and let you know if I get any good answers.&lt;/P&gt;</description>
      <pubDate>Thu, 05 Dec 2024 16:58:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/errors-and-commit-warnings-after-11-1-2-h3-upgrade/m-p/996770#M5173</guid>
      <dc:creator>Jpergolizzi</dc:creator>
      <dc:date>2024-12-05T16:58:59Z</dc:date>
    </item>
    <item>
      <title>Re: Errors and commit warnings after 11.1.2-h3 upgrade</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/errors-and-commit-warnings-after-11-1-2-h3-upgrade/m-p/1221610#M5575</link>
      <description>&lt;P&gt;any feedback about this topic ?&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2025 15:56:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/errors-and-commit-warnings-after-11-1-2-h3-upgrade/m-p/1221610#M5575</guid>
      <dc:creator>Adi-Benbrima</dc:creator>
      <dc:date>2025-02-21T15:56:36Z</dc:date>
    </item>
    <item>
      <title>Re: Errors and commit warnings after 11.1.2-h3 upgrade</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/errors-and-commit-warnings-after-11-1-2-h3-upgrade/m-p/1221772#M5589</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/223657"&gt;@Adi-Benbrima&lt;/a&gt;&amp;nbsp;- I assume in regard to the 'limit' issue? If so, there are a few commands we have been told by Palo Alto TAC to run to expand the max size.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You can find more information in this other post:&amp;nbsp;&lt;A href="https://live.paloaltonetworks.com/t5/general-topics/new-periodic-alert-configuration-size-19mb-is-above-80-of-the/td-p/592593" target="_blank"&gt;Solved: LIVEcommunity - New periodic alert: Configuration size 19MB is above 80% of the maximum recommended configuration size 23MB for the platform. - LIVEcommunity - 592593&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Summary:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Check first if the commands are available, Not sure in which version they were added:&lt;/P&gt;
&lt;P&gt;find command keyword max-config-size&lt;BR /&gt;debug management-server max-config-size set size &amp;lt;1-500&amp;gt;&lt;BR /&gt;debug management-server max-config-size show&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 24 Feb 2025 14:36:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/errors-and-commit-warnings-after-11-1-2-h3-upgrade/m-p/1221772#M5589</guid>
      <dc:creator>DZamudio</dc:creator>
      <dc:date>2025-02-24T14:36:42Z</dc:date>
    </item>
  </channel>
</rss>

