<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Server error : Partial commit is not allowed. Full commit must be completed. in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/server-error-partial-commit-is-not-allowed-full-commit-must-be/m-p/172436#M54402</link>
    <description>&lt;P&gt;Or another admin changed something?&lt;/P&gt;&lt;P&gt;But I also think it's &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;s&amp;nbsp;possibility 2 (if you didn't create an EDL reachable over https, so that it requires a certificate profile; or a new log forwarding profile and you created the required serverprofile at the same time; and probably more possibilities ...)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 21 Aug 2017 17:23:26 GMT</pubDate>
    <dc:creator>Remo</dc:creator>
    <dc:date>2017-08-21T17:23:26Z</dc:date>
    <item>
      <title>Server error : Partial commit is not allowed. Full commit must be completed.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/server-error-partial-commit-is-not-allowed-full-commit-must-be/m-p/172406#M54390</link>
      <description>&lt;P&gt;Palo version:&lt;/P&gt;&lt;PRE&gt;vm-license: VM-100
vm-mode: VMWare ESXi
sw-version: 8.0.4&lt;/PRE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am trying to do a partial commit after a change on policy rules.&lt;/P&gt;&lt;P&gt;The following commands usually work. But for some reason, I ended in a state where partial commit/validate is not allowed:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;admin@CST-OCBFW-INT01(active)# validate partial device-and-network excluded

Server error : Partial validate is not allowed. Full commit must be completed.

[edit]                                                                                                                                             
admin@CST-OCBFW-INT01(active)# commit partial device-and-network excluded

Server error : Partial commit is not allowed. Full commit must be completed.

[edit]  &lt;/PRE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The candidate config only has changes on security/rules which is part of the "policy-and-objects" config AFAIK.&lt;/P&gt;&lt;P&gt;What can be the cause of this state?&lt;/P&gt;&lt;P&gt;Can it be fixed so that I can issue a partial commit and avoid doing a seemingly useless full commit? Or does it mandatorily requires a full commit?&lt;/P&gt;</description>
      <pubDate>Mon, 21 Aug 2017 15:22:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/server-error-partial-commit-is-not-allowed-full-commit-must-be/m-p/172406#M54390</guid>
      <dc:creator>hgiguelay</dc:creator>
      <dc:date>2017-08-21T15:22:07Z</dc:date>
    </item>
    <item>
      <title>Re: Server error : Partial commit is not allowed. Full commit must be completed.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/server-error-partial-commit-is-not-allowed-full-commit-must-be/m-p/172432#M54398</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/51161"&gt;@hgiguelay&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Generally this would only appear if a security policy references something that falls within the device-and-network, as you are attempting to exclude that it wouldn't be able to validate or commit the config.&amp;nbsp;&lt;/P&gt;&lt;P&gt;1) Verify nothing you have configured actually relies on anything within the device-and-network config&lt;/P&gt;&lt;P&gt;2) Something got loopy and you just need to do an actual full commit instead of a partial.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 21 Aug 2017 17:01:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/server-error-partial-commit-is-not-allowed-full-commit-must-be/m-p/172432#M54398</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2017-08-21T17:01:43Z</dc:date>
    </item>
    <item>
      <title>Re: Server error : Partial commit is not allowed. Full commit must be completed.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/server-error-partial-commit-is-not-allowed-full-commit-must-be/m-p/172436#M54402</link>
      <description>&lt;P&gt;Or another admin changed something?&lt;/P&gt;&lt;P&gt;But I also think it's &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;s&amp;nbsp;possibility 2 (if you didn't create an EDL reachable over https, so that it requires a certificate profile; or a new log forwarding profile and you created the required serverprofile at the same time; and probably more possibilities ...)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 21 Aug 2017 17:23:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/server-error-partial-commit-is-not-allowed-full-commit-must-be/m-p/172436#M54402</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2017-08-21T17:23:26Z</dc:date>
    </item>
    <item>
      <title>Re: Server error : Partial commit is not allowed. Full commit must be completed.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/server-error-partial-commit-is-not-allowed-full-commit-must-be/m-p/172579#M54427</link>
      <description>&lt;P&gt;Thanx for your help!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I don't exactly remember what I did to reach this state, but I checked that only security/rules were changed in the GUI "commit/preview changes" and in the CLI:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;root@cst-ocbvpn-int01:/# diff -u &amp;lt;(panxapi.py -xrs) &amp;lt;(panxapi.py -Xro 'show config candidate')
show: success
op: success
--- /dev/fd/63    2017-08-21 14:38:12.174880000 +0000
+++ /dev/fd/62    2017-08-21 14:38:12.174880000 +0000
@@ -1759,89 +1759,109 @@
             &amp;lt;security&amp;gt;
               &amp;lt;rules&amp;gt;
                 &amp;lt;entry name="tpl_deny_paloappdefault"&amp;gt;
+                  &amp;lt;action&amp;gt;deny&amp;lt;/action&amp;gt;
+                  &amp;lt;application&amp;gt;
+                    &amp;lt;member&amp;gt;any&amp;lt;/member&amp;gt;
...
+                  &amp;lt;/destination&amp;gt;
+                  &amp;lt;rule-type&amp;gt;interzone&amp;lt;/rule-type&amp;gt;
                 &amp;lt;/entry&amp;gt;
               &amp;lt;/rules&amp;gt;
             &amp;lt;/security&amp;gt;&lt;/PRE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So in the current state, I only have changes in "policy-and-objects".&lt;/P&gt;&lt;P&gt;Of course many of those policy changes "point" to device-and-config "objects" (log-forwarding, services, etc), but there are no changes in device-and-config in the diff.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Maybe I did some changes on device-and-config that made the Palo "flag" the next commit has needing to be full, and then reverted those changes prior to the commit.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Anyway, I'll try and reproduce and better track what were my actions.&lt;/P&gt;</description>
      <pubDate>Tue, 22 Aug 2017 10:00:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/server-error-partial-commit-is-not-allowed-full-commit-must-be/m-p/172579#M54427</guid>
      <dc:creator>hgiguelay</dc:creator>
      <dc:date>2017-08-22T10:00:20Z</dc:date>
    </item>
  </channel>
</rss>

