<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Validation Error: interface 'ethernet1/2' is already in use, but it isn't ... and zones are type unknown, but they aren't in Panorama Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/panorama-discussions/validation-error-interface-ethernet1-2-is-already-in-use-but-it/m-p/557003#M1832</link>
    <description>&lt;P&gt;Hi,&lt;BR /&gt;&lt;BR /&gt;When I try to push a config from Panorama to a PA-440, the commit fails because of these reasons.&amp;nbsp; Which is strange because ethernet1/2 isn't in use (on the PA-440).&lt;/P&gt;
&lt;P&gt;Also the zones are configured and their type is defined.&lt;BR /&gt;&lt;BR /&gt;What am I missing here ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you very much,&lt;/P&gt;</description>
    <pubDate>Thu, 07 Sep 2023 14:00:04 GMT</pubDate>
    <dc:creator>Jeroen_Proost</dc:creator>
    <dc:date>2023-09-07T14:00:04Z</dc:date>
    <item>
      <title>Validation Error: interface 'ethernet1/2' is already in use, but it isn't ... and zones are type unknown, but they aren't</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/validation-error-interface-ethernet1-2-is-already-in-use-but-it/m-p/557003#M1832</link>
      <description>&lt;P&gt;Hi,&lt;BR /&gt;&lt;BR /&gt;When I try to push a config from Panorama to a PA-440, the commit fails because of these reasons.&amp;nbsp; Which is strange because ethernet1/2 isn't in use (on the PA-440).&lt;/P&gt;
&lt;P&gt;Also the zones are configured and their type is defined.&lt;BR /&gt;&lt;BR /&gt;What am I missing here ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you very much,&lt;/P&gt;</description>
      <pubDate>Thu, 07 Sep 2023 14:00:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/validation-error-interface-ethernet1-2-is-already-in-use-but-it/m-p/557003#M1832</guid>
      <dc:creator>Jeroen_Proost</dc:creator>
      <dc:date>2023-09-07T14:00:04Z</dc:date>
    </item>
    <item>
      <title>Re: Validation Error: interface 'ethernet1/2' is already in use, but it isn't ... and zones are type unknown, but they aren't</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/validation-error-interface-ethernet1-2-is-already-in-use-but-it/m-p/557316#M1837</link>
      <description>&lt;P&gt;Hello Jeroen_Proost,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Can you run a "blank" commit on the firewall?&lt;/P&gt;
&lt;P&gt;If it fails, the issue is on your firewall, not on the configuration you are pushing from the Panorama.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Otherwise, you will need to give more info on the change you have done between the last successful commit from Panorama to this PA-400 and the unsuccessful one.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Olivier&lt;/P&gt;</description>
      <pubDate>Mon, 11 Sep 2023 08:33:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/validation-error-interface-ethernet1-2-is-already-in-use-but-it/m-p/557316#M1837</guid>
      <dc:creator>ozheng</dc:creator>
      <dc:date>2023-09-11T08:33:00Z</dc:date>
    </item>
    <item>
      <title>Re: Validation Error: interface 'ethernet1/2' is already in use, but it isn't ... and zones are type unknown, but they aren't</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/validation-error-interface-ethernet1-2-is-already-in-use-but-it/m-p/557325#M1838</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/109098"&gt;@ozheng&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Do you mean a template with no configuration in it ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you,&lt;/P&gt;</description>
      <pubDate>Mon, 11 Sep 2023 09:01:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/validation-error-interface-ethernet1-2-is-already-in-use-but-it/m-p/557325#M1838</guid>
      <dc:creator>Jeroen_Proost</dc:creator>
      <dc:date>2023-09-11T09:01:06Z</dc:date>
    </item>
    <item>
      <title>Re: Validation Error: interface 'ethernet1/2' is already in use, but it isn't ... and zones are type unknown, but they aren't</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/validation-error-interface-ethernet1-2-is-already-in-use-but-it/m-p/557436#M1840</link>
      <description>&lt;P&gt;Hello Jeroen Proost,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You connect to the CLI to the firewall then you run the following commands:&lt;/P&gt;
&lt;PRE&gt;&amp;gt; configure&lt;BR /&gt;# commit force&lt;/PRE&gt;
&lt;P&gt;Then you wait the commit result.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Olivier&lt;/P&gt;</description>
      <pubDate>Tue, 12 Sep 2023 01:14:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/validation-error-interface-ethernet1-2-is-already-in-use-but-it/m-p/557436#M1840</guid>
      <dc:creator>ozheng</dc:creator>
      <dc:date>2023-09-12T01:14:24Z</dc:date>
    </item>
    <item>
      <title>Re: Validation Error: interface 'ethernet1/2' is already in use, but it isn't ... and zones are type unknown, but they aren't</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/validation-error-interface-ethernet1-2-is-already-in-use-but-it/m-p/558480#M1856</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/109098"&gt;@ozheng&lt;/a&gt;&amp;nbsp;,&lt;BR /&gt;&lt;BR /&gt;This is what I get:&lt;BR /&gt;&lt;BR /&gt;Performing panorama connectivity check (attempt 1 of 5)&lt;BR /&gt;Panorama connectivity check was successful for 10.222.222.20&lt;BR /&gt;Configuration committed successfully&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;So that works...&lt;BR /&gt;&lt;BR /&gt;The only difference from the last succesful commit is that in between, for some reason nobody could login anymore so I had to do a factory reset...&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I connected an other PA-440, added it to Panorama but when I try to push the templates and device groups to this device, I get the exact same errors.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For reference, these are the error messages when pushing the device group and template to the PA-440's:&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;" lang="en-US"&gt;&lt;BR /&gt;Details:&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;" lang="en-US"&gt;. In VSYS vsys1 from zone untrust-l3 of type unknown and to zone untrust-l3 of type unknown are incompatible in security rule allow ike-ipsec&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;" lang="en-US"&gt;. In VSYS vsys1 from zone trust-l3 of type unknown and to zone trust-l3 of type unknown are incompatible in security rule drop paxton to non-paxton&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;" lang="en-US"&gt;. In VSYS vsys1 from zone intern-l2 of type unknown and to zone intern-l2 of type unknown are incompatible in security rule allow intern to intern&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;" lang="en-US"&gt;. In VSYS vsys1 from zone trust-l3 of type unknown and to zone trust-l3 of type unknown are incompatible in security rule allow trust to trust&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;" lang="en-US"&gt;. In VSYS vsys1 from zone trust-l3 of type unknown and to zone untrust-l3 of type unknown are incompatible in security rule allow trust to untrust&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;" lang="en-US"&gt;. In VSYS vsys1 from zone trust-l3 of type unknown and to zone untrust-l3 of type unknown are incompatible in nat rule to-internet&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;" lang="en-US"&gt;. Configuration is invalid&lt;BR /&gt;&lt;BR /&gt;=&amp;gt; the zones trust-l3 and untrust-l3 aren't of type unknown, they are type Layer 3&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;" lang="en-US"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;" lang="en-US"&gt;Details:&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;" lang="en-US"&gt;. Validation Error:&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;" lang="en-US"&gt;. network -&amp;gt; vlan -&amp;gt; vlan-intern -&amp;gt; interface 'ethernet1/2' is already in use&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;" lang="en-US"&gt;. network -&amp;gt; vlan -&amp;gt; vlan-intern -&amp;gt; interface is invalid&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;" lang="en-US"&gt;. Commit failed&lt;BR /&gt;&lt;BR /&gt;=&amp;gt; I don't see where interface 'ethernet1/2' is in use. So just for testing I removed&amp;nbsp;'ethernet1/2' from "vlan-intern", but then I get:&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;" lang="nl-BE"&gt;. Validation Error:&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;" lang="nl-BE"&gt;. network -&amp;gt; virtual-wire -&amp;gt; default-vwire -&amp;gt; interface1 'ethernet1/1' is not a valid reference&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;" lang="nl-BE"&gt;. network -&amp;gt; virtual-wire -&amp;gt; default-vwire -&amp;gt; interface1 is invalid&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;" lang="nl-BE"&gt;. Commit failed&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;" lang="nl-BE"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;" lang="nl-BE"&gt;=&amp;gt; But there are no virtual-wire's configured !&lt;/P&gt;</description>
      <pubDate>Tue, 19 Sep 2023 12:35:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/validation-error-interface-ethernet1-2-is-already-in-use-but-it/m-p/558480#M1856</guid>
      <dc:creator>Jeroen_Proost</dc:creator>
      <dc:date>2023-09-19T12:35:52Z</dc:date>
    </item>
    <item>
      <title>Re: Validation Error: interface 'ethernet1/2' is already in use, but it isn't ... and zones are type unknown, but they aren't</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/validation-error-interface-ethernet1-2-is-already-in-use-but-it/m-p/558730#M1863</link>
      <description>&lt;P&gt;Hello Jeroen_Proost.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Maybe there is the vwire on the firewall config?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Anyway, have you run the commit force on the firewall (with no pending change)?&lt;/P&gt;
&lt;P&gt;If it fails --&amp;gt; the issue is on the firewall not on Panorama.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Olivier&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 20 Sep 2023 08:07:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/validation-error-interface-ethernet1-2-is-already-in-use-but-it/m-p/558730#M1863</guid>
      <dc:creator>ozheng</dc:creator>
      <dc:date>2023-09-20T08:07:34Z</dc:date>
    </item>
    <item>
      <title>Re: Validation Error: interface 'ethernet1/2' is already in use, but it isn't ... and zones are type unknown, but they aren't</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/validation-error-interface-ethernet1-2-is-already-in-use-but-it/m-p/558814#M1865</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/109098"&gt;@ozheng&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Yes, I was able to do the commit force on the local firewall. In the meanwhile I contacted PA support, we deleted the standard factory settings (default virt router, default vwire, default interfaces,...) and were able to push the templates and device groups from Panorama...&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'm glad this seems to be the solution. Tomorrow I'm going to connect another fw and see if it works again.&lt;/P&gt;</description>
      <pubDate>Wed, 20 Sep 2023 13:49:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/validation-error-interface-ethernet1-2-is-already-in-use-but-it/m-p/558814#M1865</guid>
      <dc:creator>Jeroen_Proost</dc:creator>
      <dc:date>2023-09-20T13:49:47Z</dc:date>
    </item>
  </channel>
</rss>

