<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Can't commit from Panorama due to mis-match Vsys number between Pan and local box in Panorama Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/panorama-discussions/can-t-commit-from-panorama-due-to-mis-match-vsys-number-between/m-p/460243#M671</link>
    <description>&lt;P&gt;wanted to know if anyone has ever experienced this issue. recently configured a new Vsys "Vsys6" which was successfully added to the correct Template_stack and device groups. everything worked fine for 2-3 weeks, however last night after adding 2 Sec.policies to the new Vsys. the commit failed. FYI for security i've edited the zone names and policy name. &lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;. &lt;/STRONG&gt;In VSYS vsys5 from zone "zone name" of type unknown and to zone "zone name" of type unknown are incompatible in security rule "rule name"&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;. &lt;/STRONG&gt;In VSYS vsys5 from zone "zone name" of type unknown and to zone "zone name" of type unknown are incompatible in nat rule "rule name"&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;. &lt;/STRONG&gt;In VSYS vsys5 from zone "zone name" of type unknown and to zone "zone name" of type unknown are incompatible in nat rule "rule name"&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;. &lt;/STRONG&gt;In VSYS vsys5 from zone "zone name" of type unknown and to zone "zone name" of type unknown are incompatible in nat rule "rule name"&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;. &lt;/STRONG&gt;Configuration is invalid&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;It goes on for a couple more rules where the zone or rule name will change.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I've noticed that on the PAN, the Vsys# does not match the name"description" from the Vsys# name"description" on the local boxes. for example on the PAN Vsys5 is named blue and Vsys6 is yellow, but on the local box Vsys5 is Yellow and Vsys6 is blue. I've tried pushing the stack to the boxes but that didnt work, tried reverting but that didn't work either.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 21 Jan 2022 18:01:19 GMT</pubDate>
    <dc:creator>SAugustin</dc:creator>
    <dc:date>2022-01-21T18:01:19Z</dc:date>
    <item>
      <title>Can't commit from Panorama due to mis-match Vsys number between Pan and local box</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/can-t-commit-from-panorama-due-to-mis-match-vsys-number-between/m-p/460243#M671</link>
      <description>&lt;P&gt;wanted to know if anyone has ever experienced this issue. recently configured a new Vsys "Vsys6" which was successfully added to the correct Template_stack and device groups. everything worked fine for 2-3 weeks, however last night after adding 2 Sec.policies to the new Vsys. the commit failed. FYI for security i've edited the zone names and policy name. &lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;. &lt;/STRONG&gt;In VSYS vsys5 from zone "zone name" of type unknown and to zone "zone name" of type unknown are incompatible in security rule "rule name"&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;. &lt;/STRONG&gt;In VSYS vsys5 from zone "zone name" of type unknown and to zone "zone name" of type unknown are incompatible in nat rule "rule name"&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;. &lt;/STRONG&gt;In VSYS vsys5 from zone "zone name" of type unknown and to zone "zone name" of type unknown are incompatible in nat rule "rule name"&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;. &lt;/STRONG&gt;In VSYS vsys5 from zone "zone name" of type unknown and to zone "zone name" of type unknown are incompatible in nat rule "rule name"&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;. &lt;/STRONG&gt;Configuration is invalid&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;It goes on for a couple more rules where the zone or rule name will change.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I've noticed that on the PAN, the Vsys# does not match the name"description" from the Vsys# name"description" on the local boxes. for example on the PAN Vsys5 is named blue and Vsys6 is yellow, but on the local box Vsys5 is Yellow and Vsys6 is blue. I've tried pushing the stack to the boxes but that didnt work, tried reverting but that didn't work either.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Jan 2022 18:01:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/can-t-commit-from-panorama-due-to-mis-match-vsys-number-between/m-p/460243#M671</guid>
      <dc:creator>SAugustin</dc:creator>
      <dc:date>2022-01-21T18:01:19Z</dc:date>
    </item>
    <item>
      <title>Re: Can't commit from Panorama due to mis-match Vsys number between Pan and local box</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/can-t-commit-from-panorama-due-to-mis-match-vsys-number-between/m-p/460514#M675</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Have you followed the article below when adding the new vsys using panorama?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000PLsWCAW" target="_blank"&gt;New Virtual System (vsys) created in Panorama Template does not... - Knowledge Base - Palo Alto Networks&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Also I found the the below info:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV&gt;
&lt;UL&gt;
&lt;LI class="li"&gt;
&lt;DIV&gt;
&lt;DIV class="p"&gt;
&lt;DIV&gt;You can rename a vsys only on the local firewall. On Panorama, renaming a vsys is not supported. If you rename a vsys on Panorama, the result is an entirely new vsys or the new vsys name gets mapped to the wrong vsys on the firewall.&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;/DIV&gt;
&lt;P&gt;&lt;LI-WRAPPER&gt;&lt;/LI-WRAPPER&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-web-interface-help/device/device-virtual-systems.html" target="_blank"&gt;Device &amp;gt; Virtual Systems (paloaltonetworks.com)&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If nothing works you may try to remove and add again the the firewall with its VSYS systems :&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000Cmd6CAC" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000Cmd6CAC&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000CmM0CAK" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000CmM0CAK&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You may also check for bugs for your version, for example :&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/8-1/pan-os-release-notes/pan-os-8-1-release-information/known-issues.html" target="_blank"&gt;Known Issues (paloaltonetworks.com)&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 24 Jan 2022 08:59:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/can-t-commit-from-panorama-due-to-mis-match-vsys-number-between/m-p/460514#M675</guid>
      <dc:creator>nikoolayy1</dc:creator>
      <dc:date>2022-01-24T08:59:38Z</dc:date>
    </item>
    <item>
      <title>Re: Can't commit from Panorama due to mis-match Vsys number between Pan and local box</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/can-t-commit-from-panorama-due-to-mis-match-vsys-number-between/m-p/460896#M680</link>
      <description>&lt;P&gt;Nikolay,&lt;/P&gt;
&lt;P&gt;Everything was done correctly in regards to creating the new Vsys. as i stated the Vsys was created 2-3 weeks before the issue started. Anyway, I tried removing the new Vsys6 and the configs created with it on the PAN and tried to push it to the local FW box. the push still failed but only the device group portion. So we decided to un-pair the FW from PAN but instead of checking the import "device and network template" and the "policy and object" checkbox.we decided to only keep the local default settings "local admin" ,"management port" etc. after UN-pairing we didnt commit the change on the local box. instead we went straight to re-pairing the FW back to PAN, added it back to the device groups. did a "commit and push" and that was successful. when into the local FW and everything matches up now. PAN and local FW Vsys are all matched up.&lt;/P&gt;</description>
      <pubDate>Tue, 25 Jan 2022 13:52:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/can-t-commit-from-panorama-due-to-mis-match-vsys-number-between/m-p/460896#M680</guid>
      <dc:creator>SAugustin</dc:creator>
      <dc:date>2022-01-25T13:52:04Z</dc:date>
    </item>
  </channel>
</rss>

