<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Active Active HA Out of Sync due to invalid interface address commit failed. in Next-Generation Firewall Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/active-active-ha-out-of-sync-due-to-invalid-interface-address/m-p/1257150#M6984</link>
    <description>&lt;P&gt;Hi Kiwi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you for your response thats good to know, unfortunately in this situation the address object and interface where the address object is assigned are already part of the running configuration, would you suggest we remove the address object and enter the address manually for the interface to see if this succeeds?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Kind Regards&lt;/P&gt;
&lt;P&gt;NG&lt;/P&gt;</description>
    <pubDate>Tue, 23 Jun 2026 14:57:11 GMT</pubDate>
    <dc:creator>N.Gibson577756</dc:creator>
    <dc:date>2026-06-23T14:57:11Z</dc:date>
    <item>
      <title>Active Active HA Out of Sync due to invalid interface address commit failed.</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/active-active-ha-out-of-sync-due-to-invalid-interface-address/m-p/1257012#M6980</link>
      <description>&lt;P&gt;Our customer has 2 PA-3420's running in Active Active HA which are currently out of sync.&lt;/P&gt;
&lt;P&gt;All criteria on the HA widget matches across the two devices.&lt;/P&gt;
&lt;P&gt;When we attempt to sync to peer from the active-primary we get a commit failure on the active secondary stating:&lt;/P&gt;
&lt;P&gt;invalid interface address XXX-XXX-XXX-XXX-30(Module: routed)&lt;/P&gt;
&lt;P&gt;client routed phase 1 failure&lt;/P&gt;
&lt;P&gt;Commit failed.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Can anyone tell me why this is? The address stated in the error message is currently configured to a sub interface on the active secondary.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;All dataplane interface IP's across the two devices do not match.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Kind Regards&lt;/P&gt;
&lt;P&gt;Nathan Gibson&lt;/P&gt;
&lt;P&gt;&lt;LI-PRODUCT title="NGFW" id="NGFW"&gt;&lt;/LI-PRODUCT&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 22 Jun 2026 15:08:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/active-active-ha-out-of-sync-due-to-invalid-interface-address/m-p/1257012#M6980</guid>
      <dc:creator>N.Gibson577756</dc:creator>
      <dc:date>2026-06-22T15:08:06Z</dc:date>
    </item>
    <item>
      <title>Re: Active Active HA Out of Sync due to invalid interface address commit failed.</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/active-active-ha-out-of-sync-due-to-invalid-interface-address/m-p/1257127#M6982</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/1660065991"&gt;@N.Gibson577756&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I've seen this&lt;SPAN&gt;&amp;nbsp;happen because of a timing issue in the commit validation process. &lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;The interface configuration requires an immediate, validated IP address. When it encounters the name of a new, uncommitted address object, the system fails to resolve it because the object has not yet been formally saved to the configuration database. This triggers the "Invalid IP" error and causes the commit to fail. &lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;The solution there was doing a two-stage commit. We must ensure the address object exists in the configuration *before* assigning it to an interface. &lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Stage 1: Create and Commit the Object - First, create the new address object with its corresponding IP address. Perform a commit. &lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;This action validates the new object and adds it to the firewall's configuration database. At this point, the firewall "knows" that your new object name represents a valid IP address.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt; Stage 2: Assign the Object and Commit Again - Now that the address object is a recognized part of the running configuration, you can assign it to the network interface and perform a second commit. &lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;This time, when the validation process checks the interface, it will successfully look up the object name, find the corresponding IP address in its database, and the commit will pass without error. &lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;This two-step process "pre-registers" the address object, making it available for the firewall to use in more sensitive configuration areas like interface IP assignments.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Hope this helps,&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 23 Jun 2026 09:20:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/active-active-ha-out-of-sync-due-to-invalid-interface-address/m-p/1257127#M6982</guid>
      <dc:creator>kiwi</dc:creator>
      <dc:date>2026-06-23T09:20:10Z</dc:date>
    </item>
    <item>
      <title>Re: Active Active HA Out of Sync due to invalid interface address commit failed.</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/active-active-ha-out-of-sync-due-to-invalid-interface-address/m-p/1257150#M6984</link>
      <description>&lt;P&gt;Hi Kiwi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you for your response thats good to know, unfortunately in this situation the address object and interface where the address object is assigned are already part of the running configuration, would you suggest we remove the address object and enter the address manually for the interface to see if this succeeds?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Kind Regards&lt;/P&gt;
&lt;P&gt;NG&lt;/P&gt;</description>
      <pubDate>Tue, 23 Jun 2026 14:57:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/active-active-ha-out-of-sync-due-to-invalid-interface-address/m-p/1257150#M6984</guid>
      <dc:creator>N.Gibson577756</dc:creator>
      <dc:date>2026-06-23T14:57:11Z</dc:date>
    </item>
  </channel>
</rss>

