<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Panorama fails to commit device group to new firewalls in Panorama Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/panorama-discussions/panorama-fails-to-commit-device-group-to-new-firewalls/m-p/547156#M1607</link>
    <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/185420"&gt;@GrantCampbell4&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;As mentioned at the bottom of this link DN and LN regions were added recently - &lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClFFCA0" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClFFCA0&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;So it looks like your PA-3220 firewall does not use the latest dynamic package updates compared to the Panorama and PA-450.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;First step would be to "check now" and install the latest dynamic content packages on the firewalls and try again to push config from Panorama.&lt;/P&gt;</description>
    <pubDate>Sun, 25 Jun 2023 08:00:06 GMT</pubDate>
    <dc:creator>aleksandar.astardzhiev</dc:creator>
    <dc:date>2023-06-25T08:00:06Z</dc:date>
    <item>
      <title>Panorama fails to commit device group to new firewalls</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/panorama-fails-to-commit-device-group-to-new-firewalls/m-p/546875#M1604</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We are running 10.1.9-h1 Panorama server that manages multiple PA firewalls.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We have imported a new HA pair of PA-450s and a new HA pair of PA-3220 firewalls&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The PA-3220 firewalls are in a template and device group configuration and when committing to the firewalls from Panorama to the PA-3220s for the first time, the template pushes fine but the device group commit fails.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;. Validation Error:&lt;BR /&gt;. rulebase -&amp;gt; security -&amp;gt; rules -&amp;gt; &amp;lt;&amp;lt;omitted ref&amp;gt;&amp;gt;inbound blocks -&amp;gt; source 'DN' is not an allowed keyword&lt;BR /&gt;. rulebase -&amp;gt; security -&amp;gt; rules -&amp;gt; &amp;lt;&amp;lt;omitted ref&amp;gt;&amp;gt;inbound blocks -&amp;gt; source DN is an invalid ipv4/v6 address&lt;BR /&gt;. rulebase -&amp;gt; security -&amp;gt; rules -&amp;gt; &amp;lt;&amp;lt;omitted ref&amp;gt;&amp;gt;inbound blocks -&amp;gt; source DN range separator('-') not found&lt;BR /&gt;. rulebase -&amp;gt; security -&amp;gt; rules -&amp;gt; &amp;lt;&amp;lt;omitted ref&amp;gt;&amp;gt;inbound blocks -&amp;gt; source 'DN' is not a valid reference&lt;BR /&gt;. rulebase -&amp;gt; security -&amp;gt; rules -&amp;gt; &amp;lt;&amp;lt;omitted ref&amp;gt;&amp;gt;inbound blocks -&amp;gt; source 'LN' is not an allowed keyword&lt;BR /&gt;. rulebase -&amp;gt; security -&amp;gt; rules -&amp;gt; &amp;lt;&amp;lt;omitted ref&amp;gt;&amp;gt;inbound blocks -&amp;gt; source LN is an invalid ipv4/v6 address&lt;BR /&gt;. rulebase -&amp;gt; security -&amp;gt; rules -&amp;gt; &amp;lt;&amp;lt;omitted ref&amp;gt;&amp;gt;inbound blocks -&amp;gt; source LN range separator('-') not found&lt;BR /&gt;. rulebase -&amp;gt; security -&amp;gt; rules -&amp;gt; &amp;lt;&amp;lt;omitted ref&amp;gt;&amp;gt;inbound blocks -&amp;gt; source 'LN' is not a valid reference&lt;BR /&gt;. rulebase -&amp;gt; security -&amp;gt; rules -&amp;gt; &amp;lt;&amp;lt;omitted ref&amp;gt;&amp;gt;inbound blocks -&amp;gt; source is invalid&lt;BR /&gt;. rulebase -&amp;gt; security -&amp;gt; rules -&amp;gt; &amp;lt;&amp;lt;omitted ref&amp;gt;&amp;gt;outbound blocks-1 -&amp;gt; destination 'DN' is not an allowed keyword&lt;BR /&gt;. rulebase -&amp;gt; security -&amp;gt; rules -&amp;gt; &amp;lt;&amp;lt;omitted ref&amp;gt;&amp;gt;outbound blocks-1 -&amp;gt; destination DN is an invalid ipv4/v6 address&lt;BR /&gt;. rulebase -&amp;gt; security -&amp;gt; rules -&amp;gt; &amp;lt;&amp;lt;omitted ref&amp;gt;&amp;gt;outbound blocks-1 -&amp;gt; destination DN range separator('-') not found&lt;BR /&gt;. rulebase -&amp;gt; security -&amp;gt; rules -&amp;gt; &amp;lt;&amp;lt;omitted ref&amp;gt;&amp;gt;outbound blocks-1 -&amp;gt; destination 'DN' is not a valid reference&lt;BR /&gt;. rulebase -&amp;gt; security -&amp;gt; rules -&amp;gt; &amp;lt;&amp;lt;omitted ref&amp;gt;&amp;gt;outbound blocks-1 -&amp;gt; destination 'LN' is not an allowed keyword&lt;BR /&gt;. rulebase -&amp;gt; security -&amp;gt; rules -&amp;gt; &amp;lt;&amp;lt;omitted ref&amp;gt;&amp;gt;outbound blocks-1 -&amp;gt; destination LN is an invalid ipv4/v6 address&lt;BR /&gt;. rulebase -&amp;gt; security -&amp;gt; rules -&amp;gt; &amp;lt;&amp;lt;omitted ref&amp;gt;&amp;gt;outbound blocks-1 -&amp;gt; destination LN range separator('-') not found&lt;BR /&gt;. rulebase -&amp;gt; security -&amp;gt; rules -&amp;gt; &amp;lt;&amp;lt;omitted ref&amp;gt;&amp;gt;outbound blocks-1 -&amp;gt; destination 'LN' is not a valid reference&lt;BR /&gt;. rulebase -&amp;gt; security -&amp;gt; rules -&amp;gt; &amp;lt;&amp;lt;omitted ref&amp;gt;&amp;gt;outbound blocks-1 -&amp;gt; destination is invalid&lt;BR /&gt;. rulebase -&amp;gt; security -&amp;gt; rules is invalid&lt;BR /&gt;. rulebase -&amp;gt; security is invalid&lt;BR /&gt;. rulebase is invalid&lt;BR /&gt;. vsys is invalid&lt;BR /&gt;. devices is invalid&lt;BR /&gt;. vsys1&lt;BR /&gt;. Error: Failed to find address 'DN'&lt;BR /&gt;. Error: Unknown address 'DN'&lt;BR /&gt;. Error: Failed to parse security policy&lt;BR /&gt;. (Module: device)&lt;BR /&gt;. client device phase 1 failure&lt;BR /&gt;. Configuration is invalid&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The PA-450s were imported the same way but have not suffered this fate.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Any assistance as to why and how to fix this is appreciated.&lt;/P&gt;</description>
      <pubDate>Thu, 22 Jun 2023 15:34:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/panorama-fails-to-commit-device-group-to-new-firewalls/m-p/546875#M1604</guid>
      <dc:creator>GrantCampbell4</dc:creator>
      <dc:date>2023-06-22T15:34:46Z</dc:date>
    </item>
    <item>
      <title>Re: Panorama fails to commit device group to new firewalls</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/panorama-fails-to-commit-device-group-to-new-firewalls/m-p/547156#M1607</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/185420"&gt;@GrantCampbell4&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;As mentioned at the bottom of this link DN and LN regions were added recently - &lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClFFCA0" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClFFCA0&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;So it looks like your PA-3220 firewall does not use the latest dynamic package updates compared to the Panorama and PA-450.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;First step would be to "check now" and install the latest dynamic content packages on the firewalls and try again to push config from Panorama.&lt;/P&gt;</description>
      <pubDate>Sun, 25 Jun 2023 08:00:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/panorama-fails-to-commit-device-group-to-new-firewalls/m-p/547156#M1607</guid>
      <dc:creator>aleksandar.astardzhiev</dc:creator>
      <dc:date>2023-06-25T08:00:06Z</dc:date>
    </item>
  </channel>
</rss>

