<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Trouble after upgrading to 4.1 in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/trouble-after-upgrading-to-4-1/m-p/8923#M6519</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I did some more testing.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I removed all custom services from my policies (luckily the firewall is still in setup phase)&lt;/P&gt;&lt;P&gt;after that I got the same problem with the certificate of the captive portal and Web gui certificate. So I also delted those and now I can finally "commit all" to the devices from panorama.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But as soon as I add a custom service defined on the panorama to a policy I get the error as mentioned above.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I can also commit when i create the service in the device context and add it to a Rule.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So do I need to recreate all my services on the device context now and use those?&lt;/P&gt;&lt;P&gt;Strangely&amp;nbsp; I have no Problem with my addresses in the rules which I also created in the panorama context.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 16 Nov 2011 15:03:35 GMT</pubDate>
    <dc:creator>saint-paul</dc:creator>
    <dc:date>2011-11-16T15:03:35Z</dc:date>
    <item>
      <title>Trouble after upgrading to 4.1</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/trouble-after-upgrading-to-4-1/m-p/8922#M6518</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I was currently running 4.0.5 on panorama and HA active passive 2050 cluster.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The upgrade ran rather smoothly.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;has something changed for service declaration in 4.1?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I define my addresses and custom services on the panorama which I sync to the HA cluster members after committing on the panorama.&lt;/P&gt;&lt;P&gt;My policies are defined on the first cluster member which are automatically HA-synced to the second member of the cluster.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I now wanted to add a a new service, so I did as always and created a new service declaration on panorama and committed it.&lt;/P&gt;&lt;P&gt;After that operation a cluster showed out of sync as it always does after comitting on the panorama.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When I now click on commit all for the cluster members in panorama I get a error message:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;rulebase -&amp;gt; security -&amp;gt; rules -&amp;gt; External Web access -&amp;gt; service 'sp_8080' is not an allowed keyword.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When I remove this service from this policy I get the same error but in the next policy rule which also contains a custom service.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Commiting on the device also works.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What can I do?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 16 Nov 2011 10:10:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/trouble-after-upgrading-to-4-1/m-p/8922#M6518</guid>
      <dc:creator>saint-paul</dc:creator>
      <dc:date>2011-11-16T10:10:55Z</dc:date>
    </item>
    <item>
      <title>Re: Trouble after upgrading to 4.1</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/trouble-after-upgrading-to-4-1/m-p/8923#M6519</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I did some more testing.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I removed all custom services from my policies (luckily the firewall is still in setup phase)&lt;/P&gt;&lt;P&gt;after that I got the same problem with the certificate of the captive portal and Web gui certificate. So I also delted those and now I can finally "commit all" to the devices from panorama.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But as soon as I add a custom service defined on the panorama to a policy I get the error as mentioned above.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I can also commit when i create the service in the device context and add it to a Rule.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So do I need to recreate all my services on the device context now and use those?&lt;/P&gt;&lt;P&gt;Strangely&amp;nbsp; I have no Problem with my addresses in the rules which I also created in the panorama context.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 16 Nov 2011 15:03:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/trouble-after-upgrading-to-4-1/m-p/8923#M6519</guid>
      <dc:creator>saint-paul</dc:creator>
      <dc:date>2011-11-16T15:03:35Z</dc:date>
    </item>
    <item>
      <title>Re: Trouble after upgrading to 4.1</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/trouble-after-upgrading-to-4-1/m-p/8924#M6520</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Is your setup running 4.0.5 on the managed firewalls and 4.1.0 on Panorama?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If this is the case then you should open a case with support.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 16 Nov 2011 17:48:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/trouble-after-upgrading-to-4-1/m-p/8924#M6520</guid>
      <dc:creator>mschuricht</dc:creator>
      <dc:date>2011-11-16T17:48:08Z</dc:date>
    </item>
    <item>
      <title>Re: Trouble after upgrading to 4.1</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/trouble-after-upgrading-to-4-1/m-p/8925#M6521</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;No, everything is running on 4.1&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 17 Nov 2011 07:29:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/trouble-after-upgrading-to-4-1/m-p/8925#M6521</guid>
      <dc:creator>saint-paul</dc:creator>
      <dc:date>2011-11-17T07:29:47Z</dc:date>
    </item>
    <item>
      <title>Re: Trouble after upgrading to 4.1</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/trouble-after-upgrading-to-4-1/m-p/8926#M6522</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Please open a support case so we can investigate the issue. It sounds like a bug.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 18 Nov 2011 02:52:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/trouble-after-upgrading-to-4-1/m-p/8926#M6522</guid>
      <dc:creator>mschuricht</dc:creator>
      <dc:date>2011-11-18T02:52:15Z</dc:date>
    </item>
    <item>
      <title>Re: Trouble after upgrading to 4.1</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/trouble-after-upgrading-to-4-1/m-p/8927#M6523</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Edit:&lt;/P&gt;&lt;P&gt;I must have done something wrong yesterday, because today I noted that it doesn't work..&lt;/P&gt;&lt;P&gt;Still get the mesage when commiting to "managed devices.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;vsys -&amp;gt; vsys1 -&amp;gt; rulebase -&amp;gt; security -&amp;gt; rules -&amp;gt; External Web access -&amp;gt; service 'test' is not an allowed keyword&lt;BR /&gt;vsys -&amp;gt; vsys1 -&amp;gt; rulebase -&amp;gt; security -&amp;gt; rules -&amp;gt; External Web access -&amp;gt; service 'test' is not a valid reference&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;/Edit:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I think I solved the problem.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I noted a problem while creating&amp;nbsp; new tunnel interfaces, those interfaces where grey while pre update created interfaces where green.&lt;/P&gt;&lt;P&gt;I then noted that only the new interfaces had vsys1 next to them.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So I activated&amp;nbsp; the virtual system feature on the devices. After this I had the reassign security zones and vsys to all interfaces.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I also had to maunally remove global protect entries from the config xml as I could not get the error message away via the web gui.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 23 Nov 2011 08:38:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/trouble-after-upgrading-to-4-1/m-p/8927#M6523</guid>
      <dc:creator>saint-paul</dc:creator>
      <dc:date>2011-11-23T08:38:07Z</dc:date>
    </item>
  </channel>
</rss>

