<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ssh invalid commit error in Panorama Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/panorama-discussions/ssh-invalid-commit-error/m-p/545457#M1574</link>
    <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/223621"&gt;@sujithGovindaraj&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;With some major upgrades there are changes in config syntax. During the upgrade firewall will automatically update the configuration to the new syntax - this is one of the main reasons why before it was important to follow the upgrade path and not skip majort version (to ensure proper config upgrade). &lt;BR /&gt;&lt;BR /&gt;Unfortunately there are some rare cases where the automatic config upgrade is failing. What most probably is happening is that the current commited config contain syntax for the previous versions (probably from 10.0 or .1 as SSH ciphers were not available in 9.1).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I would suggest you the following:&lt;BR /&gt;1. Login to the problematic FW&lt;/P&gt;
&lt;P&gt;2. Export running config to xml file&lt;/P&gt;
&lt;P&gt;3. Open the XML with text editor and locate the relevant part of the config - the error gives you some directions &amp;lt;deviceconfig&amp;gt;&amp;lt;system&amp;gt;&amp;lt;ssh&amp;gt;&lt;/P&gt;
&lt;P&gt;4. Delete the whole "section" &amp;lt;ssh&amp;gt;&amp;lt;/ssh&amp;gt;&lt;/P&gt;
&lt;P&gt;5. Import the edited config back to the FW&lt;/P&gt;
&lt;P&gt;6. Load the imported config - this will load the file as candidate config&lt;/P&gt;
&lt;P&gt;7. Commit locally to the firewall&lt;/P&gt;
&lt;P&gt;8. Confirm commit is successfull and try to push from Panorama&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 09 Jun 2023 09:32:02 GMT</pubDate>
    <dc:creator>aleksandar.astardzhiev</dc:creator>
    <dc:date>2023-06-09T09:32:02Z</dc:date>
    <item>
      <title>ssh invalid commit error</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/ssh-invalid-commit-error/m-p/545222#M1571</link>
      <description>&lt;P&gt;We have upgraded our palo alto firewall from 9.2.x to 10.2.4 after degradation from Panroma getting error as " out of sync ". we tried to commit and push from Panorma but we were unable to commit getting the error " SSH invalid"&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="sujithGovindaraj_0-1686194452743.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/50738iBEA6F3417A3A3894/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="sujithGovindaraj_0-1686194452743.png" alt="sujithGovindaraj_0-1686194452743.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;kindly help us to resove this issue&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 08 Jun 2023 03:21:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/ssh-invalid-commit-error/m-p/545222#M1571</guid>
      <dc:creator>sujithGovindaraj</dc:creator>
      <dc:date>2023-06-08T03:21:35Z</dc:date>
    </item>
    <item>
      <title>Re: ssh invalid commit error</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/ssh-invalid-commit-error/m-p/545457#M1574</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/223621"&gt;@sujithGovindaraj&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;With some major upgrades there are changes in config syntax. During the upgrade firewall will automatically update the configuration to the new syntax - this is one of the main reasons why before it was important to follow the upgrade path and not skip majort version (to ensure proper config upgrade). &lt;BR /&gt;&lt;BR /&gt;Unfortunately there are some rare cases where the automatic config upgrade is failing. What most probably is happening is that the current commited config contain syntax for the previous versions (probably from 10.0 or .1 as SSH ciphers were not available in 9.1).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I would suggest you the following:&lt;BR /&gt;1. Login to the problematic FW&lt;/P&gt;
&lt;P&gt;2. Export running config to xml file&lt;/P&gt;
&lt;P&gt;3. Open the XML with text editor and locate the relevant part of the config - the error gives you some directions &amp;lt;deviceconfig&amp;gt;&amp;lt;system&amp;gt;&amp;lt;ssh&amp;gt;&lt;/P&gt;
&lt;P&gt;4. Delete the whole "section" &amp;lt;ssh&amp;gt;&amp;lt;/ssh&amp;gt;&lt;/P&gt;
&lt;P&gt;5. Import the edited config back to the FW&lt;/P&gt;
&lt;P&gt;6. Load the imported config - this will load the file as candidate config&lt;/P&gt;
&lt;P&gt;7. Commit locally to the firewall&lt;/P&gt;
&lt;P&gt;8. Confirm commit is successfull and try to push from Panorama&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 09 Jun 2023 09:32:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/ssh-invalid-commit-error/m-p/545457#M1574</guid>
      <dc:creator>aleksandar.astardzhiev</dc:creator>
      <dc:date>2023-06-09T09:32:02Z</dc:date>
    </item>
  </channel>
</rss>

