<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cannot push IKE gateway X variable using template (chicken or the egg) in Panorama Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/panorama-discussions/cannot-push-ike-gateway-x-variable-using-template-chicken-or-the/m-p/554039#M1737</link>
    <description>&lt;P&gt;You got it, Tom! And so long as I wasn't trying to use the default to "smash" the templates together before-hand, the PA-440 seemed to do just fine with applying one template in-full before moving onto the next.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Support is going to work on a KB for this.&amp;nbsp; &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 16 Aug 2023 21:16:17 GMT</pubDate>
    <dc:creator>SteveBallantyne</dc:creator>
    <dc:date>2023-08-16T21:16:17Z</dc:date>
    <item>
      <title>Cannot push IKE gateway X variable using template (chicken or the egg)</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/cannot-push-ike-gateway-x-variable-using-template-chicken-or-the/m-p/553844#M1727</link>
      <description>&lt;P&gt;I have run into another 'bug' in 11.0.2 where my Palo Alto (PA-440) is trying to apply a configuration in an impossible order. Or, more likely, this is a Panorama bug of some sort.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Screenshot of gateway configuration:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="SteveBallantyne_0-1692131763931.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/52822iD05B6D3295D51649/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="SteveBallantyne_0-1692131763931.png" alt="SteveBallantyne_0-1692131763931.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Error message from the attempted push from Panorama:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;network -&amp;gt; ike -&amp;gt; gateway -&amp;gt; vpn-xxx-&amp;gt; local-address -&amp;gt; ip '74.xxx.xxx.xxx' is not a valid reference&lt;/LI&gt;
&lt;LI&gt;network -&amp;gt; ike -&amp;gt; gateway -&amp;gt; vpn-xxx -&amp;gt; local-address -&amp;gt; ip is invalid&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;The error is followed by a SLEW of other errors occurring in sort of a domino fashion.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The problem appears to be that this is a first time push to this device and &lt;STRONG&gt;the IP is invalid to be used for an IKE gateway, because it is not yet assigned to the interface of the PA-440.&lt;/STRONG&gt; I opened a support case (&lt;SPAN&gt;02665364) and spent a few hours with support on the issue. But the best advice that they had was to remove the portion of the configuration that is causing the issue. I deleted the IP-Sec tunnel, and the IKE gateway. Then pushed the changes, and got success (verified that the public IP was applied to ethernet1/8 using the X variable . Then I created the IKE gateway with the same settings, and pushed the changes, and also got success. But ... this doesn't help me when I have 10 more devices that I need to configure, and I want to be able to push a VPN tunnel using Panorama and templates.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This appears to be a bug to me, so I am hoping that this gets picked up by engineering, etc?&lt;/P&gt;</description>
      <pubDate>Tue, 15 Aug 2023 20:43:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/cannot-push-ike-gateway-x-variable-using-template-chicken-or-the/m-p/553844#M1727</guid>
      <dc:creator>SteveBallantyne</dc:creator>
      <dc:date>2023-08-15T20:43:29Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot push IKE gateway X variable using template (chicken or the egg)</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/cannot-push-ike-gateway-x-variable-using-template-chicken-or-the/m-p/553892#M1729</link>
      <description>&lt;P&gt;Hello SteveBallantyne,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Have you tried to update the value of the variable?&lt;BR /&gt;I think you should put the netmask with the address.&lt;BR /&gt;For reference, when you use a variable, you can try to set the value normally and you will see it is populated with /xx.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If the netmask is missing, the firewall will take the value as an address object (I guess) and raise the alert you have.&lt;/P&gt;
&lt;P&gt;--&amp;gt; to me seems to be working as expected.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;(also in the case note, it seems the interface is not configured completely as well - no ip set on x/x interface.)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Olivier&lt;/P&gt;</description>
      <pubDate>Wed, 16 Aug 2023 03:30:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/cannot-push-ike-gateway-x-variable-using-template-chicken-or-the/m-p/553892#M1729</guid>
      <dc:creator>ozheng</dc:creator>
      <dc:date>2023-08-16T03:30:09Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot push IKE gateway X variable using template (chicken or the egg)</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/cannot-push-ike-gateway-x-variable-using-template-chicken-or-the/m-p/553968#M1731</link>
      <description>&lt;P&gt;Hello Oliver,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you for the feedback - and these are good thoughts! I actually had tried adding the netmask to the IP. It accepted the value when it was used for the IPv4 address attached to the 1/8 interface - but it rejected that value when used for the IKE gateway.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It seems like the PA-440 is fine with the variable and the way that I used it. But I can't have it defined in an IKE gateway because for some reason it tries to apply that part first. And since it's a first time push, there was a lot that went with that template being applied (such as zones, certificates, etc).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I don't imagine that many people have this problem because it implies that you have at least two or more sites, with nearly the &lt;STRONG&gt;same&lt;/STRONG&gt; VPN tunnel at each site. But we have a traditional hub and spoke site, and all of the satellite need the same access. And man, would this make my life easier if I could get this to work.&amp;nbsp; &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 16 Aug 2023 12:19:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/cannot-push-ike-gateway-x-variable-using-template-chicken-or-the/m-p/553968#M1731</guid>
      <dc:creator>SteveBallantyne</dc:creator>
      <dc:date>2023-08-16T12:19:52Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot push IKE gateway X variable using template (chicken or the egg)</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/cannot-push-ike-gateway-x-variable-using-template-chicken-or-the/m-p/553972#M1732</link>
      <description>&lt;P&gt;Here is a random thought ...&lt;/P&gt;
&lt;P&gt;I am still new to Panorama and templates. I know that I have device groups, templates, and then template *stacks*. Would there be a way that I could trick the PA-440 into applying the changes in the correct order? In other words - one template to apply the external interface IP address - and then another template &lt;EM&gt;lower in the stacking order&lt;/EM&gt; to apply the IKE policy?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;EDIT: I may be onto something as it looks like there is a "move up" and "move down" option on templates, which suggests that these would be applied in a specific order!&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="SteveBallantyne_0-1692190854856.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/52845i049E0458A07BA81D/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="SteveBallantyne_0-1692190854856.png" alt="SteveBallantyne_0-1692190854856.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;I am going to work on configuring this and applying it to a new out-of-the-box PA-440.&lt;/P&gt;</description>
      <pubDate>Wed, 16 Aug 2023 13:01:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/cannot-push-ike-gateway-x-variable-using-template-chicken-or-the/m-p/553972#M1732</guid>
      <dc:creator>SteveBallantyne</dc:creator>
      <dc:date>2023-08-16T13:01:43Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot push IKE gateway X variable using template (chicken or the egg)</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/cannot-push-ike-gateway-x-variable-using-template-chicken-or-the/m-p/553979#M1733</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/118216"&gt;@SteveBallantyne&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;That is a very interesting idea!&amp;nbsp; I would love to know if it works.&amp;nbsp; Sometimes I have commit failures based upon the order of Panorama commits, and I have learned to work around them.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;With regard to your issue, I don't see a problem with 2 pushes from Panorama - one for the interface, and then one for the IPsec.&amp;nbsp; That's a lot better than configuring the 10 NGFWs individually.&amp;nbsp; Thoughts?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;</description>
      <pubDate>Wed, 16 Aug 2023 13:02:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/cannot-push-ike-gateway-x-variable-using-template-chicken-or-the/m-p/553979#M1733</guid>
      <dc:creator>TomYoung</dc:creator>
      <dc:date>2023-08-16T13:02:38Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot push IKE gateway X variable using template (chicken or the egg)</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/cannot-push-ike-gateway-x-variable-using-template-chicken-or-the/m-p/553994#M1734</link>
      <description>&lt;P&gt;Hello all,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I can try tomorrow in testbed to see the IKE gateway with the variable set to IP/netmask.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regarding the order of the template in the stack, I would think the order will only change the actual value pushed to the firewall (template inheritance order), you are not pushing template 1 then template 2 and so on and so on (imagine you're pushing x different templates on a PA-220 ... endless commit).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you need to set up hub and spoke : sdwan plugin? &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Olivier&lt;/P&gt;</description>
      <pubDate>Wed, 16 Aug 2023 13:48:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/cannot-push-ike-gateway-x-variable-using-template-chicken-or-the/m-p/553994#M1734</guid>
      <dc:creator>ozheng</dc:creator>
      <dc:date>2023-08-16T13:48:19Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot push IKE gateway X variable using template (chicken or the egg)</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/cannot-push-ike-gateway-x-variable-using-template-chicken-or-the/m-p/554035#M1735</link>
      <description>&lt;P&gt;&lt;STRONG&gt;Actually, doing two templates in a stack actually worked on a new device!&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have two templates in a template stack. The first template is 99 percent of the firewall configuration, which includes the interface and a variable that is assigning that interfaces IPv4 address. Then the second template in the stack applies only the VPN configuration.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;There is &lt;EM&gt;some&lt;/EM&gt; redundancy, as *both* templates use the same X variables, which are filled with dummy values (on both templates). Then I am overriding those variables with the actual properties on the device level (Managed Devices &amp;gt; Summary &amp;gt; Variables / Edit) which include that external interfaces public IP address.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The only other caveat is when I pushed the configuration to the device for the first time I had to use this combination of settings in Panorama:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Merge with device candidate config - &lt;STRONG&gt;Un-Checked&lt;/STRONG&gt;&lt;/LI&gt;
&lt;LI&gt;Include device and network templates - Checked&lt;/LI&gt;
&lt;LI&gt;Force template values - Checked&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;I will send a note to the case to check this thread, as this seems like a viable solution to this "chicken or the egg" issue.&amp;nbsp; &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 16 Aug 2023 19:58:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/cannot-push-ike-gateway-x-variable-using-template-chicken-or-the/m-p/554035#M1735</guid>
      <dc:creator>SteveBallantyne</dc:creator>
      <dc:date>2023-08-16T19:58:00Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot push IKE gateway X variable using template (chicken or the egg)</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/cannot-push-ike-gateway-x-variable-using-template-chicken-or-the/m-p/554038#M1736</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/118216"&gt;@SteveBallantyne&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;That is good news!&amp;nbsp; The 1st template is the one on top of the stack?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;</description>
      <pubDate>Wed, 16 Aug 2023 20:45:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/cannot-push-ike-gateway-x-variable-using-template-chicken-or-the/m-p/554038#M1736</guid>
      <dc:creator>TomYoung</dc:creator>
      <dc:date>2023-08-16T20:45:07Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot push IKE gateway X variable using template (chicken or the egg)</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/cannot-push-ike-gateway-x-variable-using-template-chicken-or-the/m-p/554039#M1737</link>
      <description>&lt;P&gt;You got it, Tom! And so long as I wasn't trying to use the default to "smash" the templates together before-hand, the PA-440 seemed to do just fine with applying one template in-full before moving onto the next.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Support is going to work on a KB for this.&amp;nbsp; &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 16 Aug 2023 21:16:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/cannot-push-ike-gateway-x-variable-using-template-chicken-or-the/m-p/554039#M1737</guid>
      <dc:creator>SteveBallantyne</dc:creator>
      <dc:date>2023-08-16T21:16:17Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot push IKE gateway X variable using template (chicken or the egg)</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/cannot-push-ike-gateway-x-variable-using-template-chicken-or-the/m-p/554065#M1738</link>
      <description>&lt;P&gt;Hello SteveBallantyne,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Good to hear it works (so there is no bug :D)&lt;/P&gt;
&lt;P&gt;Regarding the KB, I don't have the full picture of the case so I will not comment further.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Just for information, you can check this &lt;A href="https://live.paloaltonetworks.com/t5/pancast/pancast-episode-23-panorama-templates-and-template-stacks/ta-p/549181" target="_self"&gt;PANCast Episode about the Templates and Template Stacks&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Olivier&lt;/P&gt;</description>
      <pubDate>Thu, 17 Aug 2023 01:17:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/cannot-push-ike-gateway-x-variable-using-template-chicken-or-the/m-p/554065#M1738</guid>
      <dc:creator>ozheng</dc:creator>
      <dc:date>2023-08-17T01:17:40Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot push IKE gateway X variable using template (chicken or the egg)</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/cannot-push-ike-gateway-x-variable-using-template-chicken-or-the/m-p/582546#M2264</link>
      <description>&lt;P&gt;I have the same issue with config push. really helpful. I have 6 templets moving up or down dont change anything fyi.&lt;/P&gt;</description>
      <pubDate>Wed, 03 Apr 2024 19:19:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/cannot-push-ike-gateway-x-variable-using-template-chicken-or-the/m-p/582546#M2264</guid>
      <dc:creator>Leightonlee</dc:creator>
      <dc:date>2024-04-03T19:19:46Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot push IKE gateway X variable using template (chicken or the egg)</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/cannot-push-ike-gateway-x-variable-using-template-chicken-or-the/m-p/582547#M2265</link>
      <description>&lt;P&gt;Hello Leightonlee, which setting is the Palo Alto getting hung up on? Best bet for a solution is to create a new template that includes only that setting and then rearrange it so that your new template is on the top of the stack (if possible).&lt;/P&gt;</description>
      <pubDate>Wed, 03 Apr 2024 19:27:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/cannot-push-ike-gateway-x-variable-using-template-chicken-or-the/m-p/582547#M2265</guid>
      <dc:creator>SteveBallantyne</dc:creator>
      <dc:date>2024-04-03T19:27:30Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot push IKE gateway X variable using template (chicken or the egg)</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/cannot-push-ike-gateway-x-variable-using-template-chicken-or-the/m-p/582658#M2266</link>
      <description>&lt;P&gt;Warnings:&lt;BR /&gt;Duplicate certificate subject found:&lt;/P&gt;
&lt;P&gt;Details:Validation Error:&lt;BR /&gt;network -&amp;gt; ike -&amp;gt; gateway&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I opened a case if the new device is in the device group and the templates as well both interface config and all why this keep happening?&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 04 Apr 2024 14:55:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/cannot-push-ike-gateway-x-variable-using-template-chicken-or-the/m-p/582658#M2266</guid>
      <dc:creator>Leightonlee</dc:creator>
      <dc:date>2024-04-04T14:55:45Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot push IKE gateway X variable using template (chicken or the egg)</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/cannot-push-ike-gateway-x-variable-using-template-chicken-or-the/m-p/586096#M2322</link>
      <description>&lt;P&gt;I am also running into this issue right this moment.&amp;nbsp; Much like SteveBallantyne's original post, I have a hub-spoke topology where all satellite offices use the same VPN configuration to phone home.&amp;nbsp; I am getting "network -&amp;gt; ike -&amp;gt; gateway -&amp;gt; Primary-1 -&amp;gt; local-address -&amp;gt; ip 'x.x.x.x' is not a valid reference" no matter what shape or form I build the IP Variable with.&amp;nbsp; I have two templates in my stack, the first configures everything L1, VPN, and Routing, the second configures services (AAA, DNS, NTP, etc) that will phone home across the VPN.&amp;nbsp; Following the guidance in this thread did not change my results in any observable way.&amp;nbsp; If I create the IKE Gateway locally on the Firewall with all the same settings, it accepts just fine.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;To my knowledge, the position of the Templates in the Stack only apply to conflict resolution between the templates.&lt;/P&gt;</description>
      <pubDate>Tue, 07 May 2024 22:08:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/cannot-push-ike-gateway-x-variable-using-template-chicken-or-the/m-p/586096#M2322</guid>
      <dc:creator>kylebrolafski</dc:creator>
      <dc:date>2024-05-07T22:08:39Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot push IKE gateway X variable using template (chicken or the egg)</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/cannot-push-ike-gateway-x-variable-using-template-chicken-or-the/m-p/586097#M2323</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/379689203"&gt;@kylebrolafski&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I think the issue was that the VPN config was committed before the template variable, and therefore did not exist yet.&amp;nbsp; &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/118216"&gt;@SteveBallantyne&lt;/a&gt; moved the VPN config to a template lower in the stack which appears to have forced the interface and template variable to commit 1st.&amp;nbsp; He also recommends other commit options in the solution.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;</description>
      <pubDate>Tue, 07 May 2024 22:55:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/cannot-push-ike-gateway-x-variable-using-template-chicken-or-the/m-p/586097#M2323</guid>
      <dc:creator>TomYoung</dc:creator>
      <dc:date>2024-05-07T22:55:25Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot push IKE gateway X variable using template (chicken or the egg)</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/cannot-push-ike-gateway-x-variable-using-template-chicken-or-the/m-p/586182#M2325</link>
      <description>&lt;P&gt;I resolved this by pushing the devices config first and then the templets.&lt;/P&gt;</description>
      <pubDate>Wed, 08 May 2024 14:13:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/cannot-push-ike-gateway-x-variable-using-template-chicken-or-the/m-p/586182#M2325</guid>
      <dc:creator>Leightonlee</dc:creator>
      <dc:date>2024-05-08T14:13:39Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot push IKE gateway X variable using template (chicken or the egg)</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/cannot-push-ike-gateway-x-variable-using-template-chicken-or-the/m-p/586224#M2326</link>
      <description>&lt;P&gt;The template which configured my VPN was already at the bottom of the stack.&amp;nbsp; Through the suggestion in this thread, I moved it to the top of the stack.&amp;nbsp; The VPN and the Variable are configured within the same template.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I will attempt to create a local configuration with the same naming on the device to let Panorama overwrite it.&amp;nbsp; The larger, yet unspoken issue I am trying to navigate here is having all of my routing completed in the same Template, due to the way the Stack overrides conflicts between Templates within the Stack.&amp;nbsp; Any changes from a single Template would be lost if another Template modified the same Virtual Router's configuration.&lt;/P&gt;</description>
      <pubDate>Wed, 08 May 2024 20:21:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/cannot-push-ike-gateway-x-variable-using-template-chicken-or-the/m-p/586224#M2326</guid>
      <dc:creator>kylebrolafski</dc:creator>
      <dc:date>2024-05-08T20:21:54Z</dc:date>
    </item>
  </channel>
</rss>

