<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic PanOS 11.1.0 Upgrade - Panorama Refuses to Commit or Push on a Multi-VSYS System in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/panos-11-1-0-upgrade-panorama-refuses-to-commit-or-push-on-a/m-p/569129#M114821</link>
    <description>&lt;P&gt;Hey Team,&lt;BR /&gt;&lt;BR /&gt;Has anyone encountered any problems performing the PanOS 11.1.0 Upgrade? I've encountered the following issue after an upgrade, where PanOS (Panorama) would not commit changes, much less push them to our devices. The configd.log file shows the following:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;2023-12-09 16:36:16.778 +1100 DG-push(selective): Waiting for DG file to be written for XXXX&lt;BR /&gt;2023-12-09 16:36:16.867 +1100 Error: pan_populate_mvsys_policy(pan_cfg_dg_tpl_utils.c:8032): File /opt/pancfg/mgmt/groups/XXXX/panorama-selective-mvsys-config.xml does not exist, aborting&lt;BR /&gt;2023-12-09 16:36:16.867 +1100 Error: pan_cfg_generate_multidg_push_or_diffall_msg_for_device(pan_cfg_shared_policy.c:3980): Failed to populate policy node for XXXX&lt;BR /&gt;2023-12-09 16:36:16.867 +1100 Error: pan_cfg_sp_push(pan_cfg_shared_policy.c:5514): error generating push/diffall request to XXXXXX&lt;BR /&gt;2023-12-09 16:36:16.873 +1100 Error: pan_populate_mvsys_policy(pan_cfg_dg_tpl_utils.c:8032): File /opt/pancfg/mgmt/groups/XXXX/panorama-selective-mvsys-config.xml does not exist, aborting&lt;BR /&gt;2023-12-09 16:36:16.873 +1100 Error: pan_cfg_generate_multidg_push_or_diffall_msg_for_device(pan_cfg_shared_policy.c:3980): Failed to populate policy node for XXXX&lt;BR /&gt;2023-12-09 16:36:16.873 +1100 Error: pan_cfg_sp_push(pan_cfg_shared_policy.c:5514): error generating push/diffall request to XXXXXX&lt;BR /&gt;2023-12-09 16:36:16.927 +1100 DG-push(selective): Waiting for DG file to be written for XXXX&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It looks to me like an upgrade migration process didn't work when we moved from PanOS 10.2.7 (we did a multi-hop upgrade, but it was working at this step as far as we knew as we did changes to GlobalProtect configuration at this point).&lt;/P&gt;</description>
    <pubDate>Sat, 09 Dec 2023 06:47:13 GMT</pubDate>
    <dc:creator>nccbrettsmith</dc:creator>
    <dc:date>2023-12-09T06:47:13Z</dc:date>
    <item>
      <title>PanOS 11.1.0 Upgrade - Panorama Refuses to Commit or Push on a Multi-VSYS System</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/panos-11-1-0-upgrade-panorama-refuses-to-commit-or-push-on-a/m-p/569129#M114821</link>
      <description>&lt;P&gt;Hey Team,&lt;BR /&gt;&lt;BR /&gt;Has anyone encountered any problems performing the PanOS 11.1.0 Upgrade? I've encountered the following issue after an upgrade, where PanOS (Panorama) would not commit changes, much less push them to our devices. The configd.log file shows the following:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;2023-12-09 16:36:16.778 +1100 DG-push(selective): Waiting for DG file to be written for XXXX&lt;BR /&gt;2023-12-09 16:36:16.867 +1100 Error: pan_populate_mvsys_policy(pan_cfg_dg_tpl_utils.c:8032): File /opt/pancfg/mgmt/groups/XXXX/panorama-selective-mvsys-config.xml does not exist, aborting&lt;BR /&gt;2023-12-09 16:36:16.867 +1100 Error: pan_cfg_generate_multidg_push_or_diffall_msg_for_device(pan_cfg_shared_policy.c:3980): Failed to populate policy node for XXXX&lt;BR /&gt;2023-12-09 16:36:16.867 +1100 Error: pan_cfg_sp_push(pan_cfg_shared_policy.c:5514): error generating push/diffall request to XXXXXX&lt;BR /&gt;2023-12-09 16:36:16.873 +1100 Error: pan_populate_mvsys_policy(pan_cfg_dg_tpl_utils.c:8032): File /opt/pancfg/mgmt/groups/XXXX/panorama-selective-mvsys-config.xml does not exist, aborting&lt;BR /&gt;2023-12-09 16:36:16.873 +1100 Error: pan_cfg_generate_multidg_push_or_diffall_msg_for_device(pan_cfg_shared_policy.c:3980): Failed to populate policy node for XXXX&lt;BR /&gt;2023-12-09 16:36:16.873 +1100 Error: pan_cfg_sp_push(pan_cfg_shared_policy.c:5514): error generating push/diffall request to XXXXXX&lt;BR /&gt;2023-12-09 16:36:16.927 +1100 DG-push(selective): Waiting for DG file to be written for XXXX&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It looks to me like an upgrade migration process didn't work when we moved from PanOS 10.2.7 (we did a multi-hop upgrade, but it was working at this step as far as we knew as we did changes to GlobalProtect configuration at this point).&lt;/P&gt;</description>
      <pubDate>Sat, 09 Dec 2023 06:47:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/panos-11-1-0-upgrade-panorama-refuses-to-commit-or-push-on-a/m-p/569129#M114821</guid>
      <dc:creator>nccbrettsmith</dc:creator>
      <dc:date>2023-12-09T06:47:13Z</dc:date>
    </item>
    <item>
      <title>Re: PanOS 11.1.0 Upgrade - Panorama Refuses to Commit or Push on a Multi-VSYS System</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/panos-11-1-0-upgrade-panorama-refuses-to-commit-or-push-on-a/m-p/569572#M114864</link>
      <description>&lt;P&gt;Hello&lt;/P&gt;
&lt;P&gt;Instead of a selective push, why are you not doing a full commit?&lt;BR /&gt;i have seen generally, errors, when the PANOS needs a full commit (vs selective) and fails/errors when it is not done.&lt;/P&gt;
&lt;P&gt;Maybe be a CLI command of "commit force" to see if that helps.&lt;/P&gt;</description>
      <pubDate>Wed, 13 Dec 2023 01:37:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/panos-11-1-0-upgrade-panorama-refuses-to-commit-or-push-on-a/m-p/569572#M114864</guid>
      <dc:creator>S.Cantwell</dc:creator>
      <dc:date>2023-12-13T01:37:22Z</dc:date>
    </item>
    <item>
      <title>Re: PanOS 11.1.0 Upgrade - Panorama Refuses to Commit or Push on a Multi-VSYS System</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/panos-11-1-0-upgrade-panorama-refuses-to-commit-or-push-on-a/m-p/569590#M114866</link>
      <description>&lt;P&gt;Hi There,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In the end it was found to be a bug within version 10.2.5 and its migration of our configuration. The panorama creates a "default" log collection profile again during the upgrade and this cannot be committed as the firewalls also come out of the box with the uprade with a "default" collection profile. To resolve, you must rename one or both of these configurations to allow the commit to succeed. A selective commit did not work, and additionally, the following setting must be changed:&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Select Panorama &amp;gt; Setup &amp;gt; Management and edit the Panorama Settings to enabled Shared Unused Address and Service Objects with Devices.&lt;BR /&gt;&lt;BR /&gt;Once this is done, then the commit will be attempted with an error displayed about the conflict. Resolve the conflict and you can get on with the upgrade.&lt;BR /&gt;&lt;BR /&gt;References:&amp;nbsp;&lt;A href="https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-release-notes/pan-os-10-2-5-known-and-addressed-issues/pan-os-10-2-5-known-issues" target="_blank"&gt;PAN-OS 10.2.5 Known Issues (paloaltonetworks.com)&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;See&amp;nbsp;PAN-225337&lt;BR /&gt;&lt;BR /&gt;Thankyou for advising of the commit force functionality via the CLI however.&lt;/P&gt;
&lt;P&gt;&lt;LI-WRAPPER&gt;&lt;/LI-WRAPPER&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 13 Dec 2023 02:15:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/panos-11-1-0-upgrade-panorama-refuses-to-commit-or-push-on-a/m-p/569590#M114866</guid>
      <dc:creator>nccbrettsmith</dc:creator>
      <dc:date>2023-12-13T02:15:14Z</dc:date>
    </item>
  </channel>
</rss>

