<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: rulebase -&amp;gt; security -&amp;gt; rules -&amp;gt; permit_common 'permit_common' is already in use in Next-Generation Firewall Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/rulebase-gt-security-gt-rules-gt-permit-common-permit-common-is/m-p/1265523#M7162</link>
    <description>&lt;P&gt;Reviving this thread as I ran into this issue when importing a device from one Panorama into another (and wanting to reuse the exact same config from the local NGFW into the new Panorama as a DG and a TS).&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;First, it is incredibly important to ensure the config from the old Panorama is added to the device locally (as desired in my case), as well as to ensure the NGFW has the correct authkey from the new Panorama. This process is outlined here:&amp;nbsp;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u000000HD7pCAG" target="_blank"&gt;How to move a managed firewall from one Panorama to another - Knowledge Base - Palo Alto Networks&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-unlink="true"&gt;Second (where I got caught up again), you need to follow the migration procedure outlined &lt;A href="https://docs.paloaltonetworks.com/panorama/administration/manage-firewalls/transition-a-firewall-to-panorama-management/migrate-a-firewall-to-panorama-management" target="_self"&gt;here&lt;/A&gt; when importing the device config into the new Panorama to create the DG, Template, and TS.&amp;nbsp; My stumbling point was&amp;nbsp;&lt;EM&gt;not pushing the configuration bundle from Panorama to the newly added firewall to removal all policy rules and objects from its local configuration&lt;/EM&gt;. Specifically, I ran into the issue outlined by "&lt;SPAN&gt;This step is necessary to&lt;EM&gt;&lt;U&gt;&lt;STRONG&gt; prevent duplicate rule or object names&lt;/STRONG&gt;&lt;/U&gt;&lt;/EM&gt;, which would cause commit errors when you push the device group configuration from Panorama to the firewall in the next step". The key here is to not first push to the newly created DG and Template/TS, but rather use the "Export or push device config bundle" from Panorama --&amp;gt; Setup --&amp;gt; Operations first, and then push to the newly created DG and Template/TS.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P data-unlink="true"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-unlink="true"&gt;&lt;SPAN&gt;I hope this helps!&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P data-unlink="true"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-unlink="true"&gt;&lt;SPAN&gt;Cheers&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P data-unlink="true"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-unlink="true"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-unlink="true"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-unlink="true"&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 02 Oct 2026 19:24:48 GMT</pubDate>
    <dc:creator>nohash4u</dc:creator>
    <dc:date>2026-10-02T19:24:48Z</dc:date>
    <item>
      <title>rulebase -&gt; security -&gt; rules -&gt; permit_common 'permit_common' is already in use</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/rulebase-gt-security-gt-rules-gt-permit-common-permit-common-is/m-p/559389#M1896</link>
      <description>&lt;P&gt;After importing configuration and after clicking on commit I get this, who know how can I solve it&lt;BR /&gt;rulebase -&amp;gt; security -&amp;gt; rules -&amp;gt; permit_common 'permit_common' is already in use&lt;BR /&gt;&lt;BR /&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Mon, 25 Sep 2023 15:55:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/rulebase-gt-security-gt-rules-gt-permit-common-permit-common-is/m-p/559389#M1896</guid>
      <dc:creator>Hovo_Khach</dc:creator>
      <dc:date>2023-09-25T15:55:33Z</dc:date>
    </item>
    <item>
      <title>Re: rulebase -&gt; security -&gt; rules -&gt; permit_common 'permit_common' is already in use</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/rulebase-gt-security-gt-rules-gt-permit-common-permit-common-is/m-p/559750#M1904</link>
      <description>&lt;P&gt;Hi &lt;SPAN style="background: var(--ck-color-mention-background); color: var(--ck-color-mention-text);"&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/318311"&gt;@Hovo_Khach&lt;/a&gt;&lt;/SPAN&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I woud check your security policy rules and search for that specific rule name to see if there is a duplicate. Another way to check errors on commits is to open up the xml config and control + f and search the keyword the error brings up.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 27 Sep 2023 18:30:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/rulebase-gt-security-gt-rules-gt-permit-common-permit-common-is/m-p/559750#M1904</guid>
      <dc:creator>JayGolf</dc:creator>
      <dc:date>2023-09-27T18:30:34Z</dc:date>
    </item>
    <item>
      <title>Re: rulebase -&gt; security -&gt; rules -&gt; permit_common 'permit_common' is already in use</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/rulebase-gt-security-gt-rules-gt-permit-common-permit-common-is/m-p/559753#M1906</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/318311"&gt;@Hovo_Khach&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/220841"&gt;@JayGolf&lt;/a&gt;&amp;nbsp;already mentioned the best way of doing this, but sometimes looking at the XML is the only way to see duplicates for some configuration aspects. The GUI sometimes just won't display duplicates properly all the time, so this may end up being something that you can&amp;nbsp;&lt;EM&gt;only&amp;nbsp;&lt;/EM&gt;fix in the XML properly.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 27 Sep 2023 18:39:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/rulebase-gt-security-gt-rules-gt-permit-common-permit-common-is/m-p/559753#M1906</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2023-09-27T18:39:57Z</dc:date>
    </item>
    <item>
      <title>Re: rulebase -&gt; security -&gt; rules -&gt; permit_common 'permit_common' is already in use</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/rulebase-gt-security-gt-rules-gt-permit-common-permit-common-is/m-p/1265523#M7162</link>
      <description>&lt;P&gt;Reviving this thread as I ran into this issue when importing a device from one Panorama into another (and wanting to reuse the exact same config from the local NGFW into the new Panorama as a DG and a TS).&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;First, it is incredibly important to ensure the config from the old Panorama is added to the device locally (as desired in my case), as well as to ensure the NGFW has the correct authkey from the new Panorama. This process is outlined here:&amp;nbsp;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u000000HD7pCAG" target="_blank"&gt;How to move a managed firewall from one Panorama to another - Knowledge Base - Palo Alto Networks&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-unlink="true"&gt;Second (where I got caught up again), you need to follow the migration procedure outlined &lt;A href="https://docs.paloaltonetworks.com/panorama/administration/manage-firewalls/transition-a-firewall-to-panorama-management/migrate-a-firewall-to-panorama-management" target="_self"&gt;here&lt;/A&gt; when importing the device config into the new Panorama to create the DG, Template, and TS.&amp;nbsp; My stumbling point was&amp;nbsp;&lt;EM&gt;not pushing the configuration bundle from Panorama to the newly added firewall to removal all policy rules and objects from its local configuration&lt;/EM&gt;. Specifically, I ran into the issue outlined by "&lt;SPAN&gt;This step is necessary to&lt;EM&gt;&lt;U&gt;&lt;STRONG&gt; prevent duplicate rule or object names&lt;/STRONG&gt;&lt;/U&gt;&lt;/EM&gt;, which would cause commit errors when you push the device group configuration from Panorama to the firewall in the next step". The key here is to not first push to the newly created DG and Template/TS, but rather use the "Export or push device config bundle" from Panorama --&amp;gt; Setup --&amp;gt; Operations first, and then push to the newly created DG and Template/TS.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P data-unlink="true"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-unlink="true"&gt;&lt;SPAN&gt;I hope this helps!&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P data-unlink="true"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-unlink="true"&gt;&lt;SPAN&gt;Cheers&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P data-unlink="true"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-unlink="true"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-unlink="true"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-unlink="true"&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 02 Oct 2026 19:24:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/rulebase-gt-security-gt-rules-gt-permit-common-permit-common-is/m-p/1265523#M7162</guid>
      <dc:creator>nohash4u</dc:creator>
      <dc:date>2026-10-02T19:24:48Z</dc:date>
    </item>
  </channel>
</rss>

