<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Commit not working in passive firewall in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/commit-not-working-in-passive-firewall/m-p/237984#M68187</link>
    <description>&lt;P&gt;Hey&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/97701"&gt;@Venkatesan_radhakrishnan&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Certainly odd. What PAN-OS version are you on?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The management-server log will have more information on why this failed. If you do the following and paste the output we may be able to see why:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;gt; show jobs all&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Grab the ID of the commit that failed&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;gt; less mp-log ms.log&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Press the "/" key to start searching, type the Job-ID of the failed commit and copy the relevant commit logs.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 31 Oct 2018 15:17:28 GMT</pubDate>
    <dc:creator>LukeBullimore</dc:creator>
    <dc:date>2018-10-31T15:17:28Z</dc:date>
    <item>
      <title>Commit not working in passive firewall</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/commit-not-working-in-passive-firewall/m-p/237976#M68186</link>
      <description>&lt;P&gt;When I commit the firewall in active firewall I can able to commit.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When I commit in passive firewall it shows "Error: config push error"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;However I don't need to push the configuration in passive firewall I'm doing this as my HA sync is having issue.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please let me know your comments&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/17376i2006C74D3BF3D3FF/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 31 Oct 2018 15:11:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/commit-not-working-in-passive-firewall/m-p/237976#M68186</guid>
      <dc:creator>Venkatesan_radhakrishnan</dc:creator>
      <dc:date>2018-10-31T15:11:16Z</dc:date>
    </item>
    <item>
      <title>Re: Commit not working in passive firewall</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/commit-not-working-in-passive-firewall/m-p/237984#M68187</link>
      <description>&lt;P&gt;Hey&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/97701"&gt;@Venkatesan_radhakrishnan&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Certainly odd. What PAN-OS version are you on?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The management-server log will have more information on why this failed. If you do the following and paste the output we may be able to see why:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;gt; show jobs all&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Grab the ID of the commit that failed&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;gt; less mp-log ms.log&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Press the "/" key to start searching, type the Job-ID of the failed commit and copy the relevant commit logs.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 31 Oct 2018 15:17:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/commit-not-working-in-passive-firewall/m-p/237984#M68187</guid>
      <dc:creator>LukeBullimore</dc:creator>
      <dc:date>2018-10-31T15:17:28Z</dc:date>
    </item>
    <item>
      <title>Re: Commit not working in passive firewall</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/commit-not-working-in-passive-firewall/m-p/237985#M68188</link>
      <description>&lt;P&gt;8.1.1&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Model 3020&lt;/P&gt;</description>
      <pubDate>Wed, 31 Oct 2018 15:18:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/commit-not-working-in-passive-firewall/m-p/237985#M68188</guid>
      <dc:creator>Venkatesan_radhakrishnan</dc:creator>
      <dc:date>2018-10-31T15:18:56Z</dc:date>
    </item>
    <item>
      <title>Re: Commit not working in passive firewall</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/commit-not-working-in-passive-firewall/m-p/237988#M68190</link>
      <description>&lt;P&gt;Hey&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/97701"&gt;@Venkatesan_radhakrishnan&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Just an FYI, PAN-OS 8.1.1 isn't recommended. No version of PAN-OS 8.1 is at the moment but I would certainly recommend running 8.1.4-h2 if you have to run PAN-OS 8.1.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Likely an upgrade will fix it, or less service impacting you can try a restart of the management-server on the passive (not service effecting) "debug software restart process management-server".&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Where are those management-server logs &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 31 Oct 2018 15:23:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/commit-not-working-in-passive-firewall/m-p/237988#M68190</guid>
      <dc:creator>LukeBullimore</dc:creator>
      <dc:date>2018-10-31T15:23:55Z</dc:date>
    </item>
    <item>
      <title>Re: Commit not working in passive firewall</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/commit-not-working-in-passive-firewall/m-p/237992#M68192</link>
      <description>&lt;P&gt;I will share the management logs soon&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 31 Oct 2018 15:39:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/commit-not-working-in-passive-firewall/m-p/237992#M68192</guid>
      <dc:creator>Venkatesan_radhakrishnan</dc:creator>
      <dc:date>2018-10-31T15:39:21Z</dc:date>
    </item>
    <item>
      <title>Re: Commit not working in passive firewall</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/commit-not-working-in-passive-firewall/m-p/238179#M68220</link>
      <description>&lt;P&gt;2018-11-01 10:06:59.594 +0400 dnscfgmod: Added fqdn resolved ips to config /opt/pancfg/mgmt/devices/localhost.localdomain/.refreshed-candidate.xml&lt;/P&gt;&lt;P&gt;2018-11-01 10:07:00.226 +0400 client routed reported Phase 1 was SUCCESSFUL&lt;/P&gt;&lt;P&gt;2018-11-01 10:07:00.237 +0400 client ha_agent reported Phase 1 was SUCCESSFUL&lt;/P&gt;&lt;P&gt;2018-11-01 10:07:01.429 +0400 client ikemgr reported Phase 1 was SUCCESSFUL&lt;/P&gt;&lt;P&gt;2018-11-01 10:07:01.504 +0400 client dhcpd reported Phase 1 was SUCCESSFUL&lt;/P&gt;&lt;P&gt;2018-11-01 10:07:01.562 +0400 client varrcvr reported Phase 1 was SUCCESSFUL&lt;/P&gt;&lt;P&gt;2018-11-01 10:07:01.718 +0400 client rasmgr reported warning: Warning: tunnel tunnel.100 ipv6 is not enabled. IPv6 address will be ignored!&lt;/P&gt;&lt;P&gt;(Module: rasmgr)&lt;/P&gt;&lt;P&gt;2018-11-01 10:07:01.719 +0400 client rasmgr reported Phase 1 was SUCCESSFUL&lt;/P&gt;&lt;P&gt;2018-11-01 10:07:02.162 +0400 client websrvr reported Phase 1 was SUCCESSFUL&lt;/P&gt;&lt;P&gt;2018-11-01 10:07:02.208 +0400 client sslmgr reported Phase 1 was SUCCESSFUL&lt;/P&gt;&lt;P&gt;2018-11-01 10:07:02.308 +0400 client authd reported Phase 1 was SUCCESSFUL&lt;/P&gt;&lt;P&gt;2018-11-01 10:07:02.315 +0400 client satd reported Phase 1 was SUCCESSFUL&lt;/P&gt;&lt;P&gt;2018-11-01 10:07:02.347 +0400 client pppoed reported Phase 1 was SUCCESSFUL&lt;/P&gt;&lt;P&gt;2018-11-01 10:07:02.457 +0400 client dnsproxyd reported Phase 1 was SUCCESSFUL&lt;/P&gt;&lt;P&gt;2018-11-01 10:07:02.515 +0400 client cryptod reported Phase 1 was SUCCESSFUL&lt;/P&gt;&lt;P&gt;2018-11-01 10:07:02.727 +0400 client l2ctrld reported Phase 1 was SUCCESSFUL&lt;/P&gt;&lt;P&gt;2018-11-01 10:07:02.856 +0400 client cord reported Phase 1 was SUCCESSFUL&lt;/P&gt;&lt;P&gt;2018-11-01 10:07:04.757 +0400 client sslvpn reported Phase 1 was SUCCESSFUL&lt;/P&gt;&lt;P&gt;2018-11-01 10:07:04.970 +0400 client logrcvr reported Phase 1 was SUCCESSFUL&lt;/P&gt;&lt;P&gt;2018-11-01 10:07:10.138 +0400 client device reported error: Error: config push error&lt;/P&gt;&lt;P&gt;(Module: device)&lt;/P&gt;&lt;P&gt;2018-11-01 10:07:10.139 +0400 client device reported Phase 1 FAILED&lt;/P&gt;&lt;P&gt;2018-11-01 10:07:10.940 +0400 client useridd reported Phase 1 was SUCCESSFUL&lt;/P&gt;&lt;P&gt;2018-11-01 10:07:10.940 +0400 All client have responded for validate.&lt;/P&gt;&lt;P&gt;2018-11-01 10:07:10.940 +0400 Client:device has P1 error reported&lt;/P&gt;&lt;P&gt;2018-11-01 10:07:10.940 +0400 Error:&amp;nbsp; pan_mgmt_client_table_do_commit(pan_cfg_commit_jobs.c:3743): phase 1 failed&lt;/P&gt;&lt;P&gt;2018-11-01 10:07:10.950 +0400 EDL cfg(0x2a35000, 0) Releasing candidate EDLs of type IP&lt;/P&gt;&lt;P&gt;2018-11-01 10:07:10.950 +0400 EDL cfg(0x2a35000, 0) Releasing candidate EDLs of type Domain&lt;/P&gt;&lt;P&gt;2018-11-01 10:07:10.950 +0400 EDL cfg(0x2a35000, 0) Releasing candidate EDLs of type URL&lt;/P&gt;&lt;P&gt;2018-11-01 10:07:10.952 +0400 Error:&amp;nbsp; pan_cfg_commit_to_local_device(pan_cfg_commit_handler.c:3223): Validate failed&lt;/P&gt;&lt;P&gt;2018-11-01 10:13:06.945 +0400 client authd reported op command was SUCCESSFUL&lt;/P&gt;&lt;P&gt;2018-11-01 10:13:08.905 +0400 client authd reported op command was SUCCESSFUL&lt;/P&gt;&lt;P&gt;2018-11-01 10:15:00.290 +0400 Checking to purge appstatdb logtype&lt;/P&gt;&lt;P&gt;2018-11-01 10:19:53.205 +0400 client authd reported op command was SUCCESSFUL&lt;/P&gt;&lt;P&gt;2018-11-01 10:19:55.057 +0400 client dagger reported op command was SUCCESSFUL&lt;/P&gt;&lt;P&gt;2018-11-01 10:19:55.299 +0400 template config file /opt/pancfg/mgmt/template/template-config.xml doesn't exist&lt;/P&gt;&lt;P&gt;99%2018-11-01 10:19:55.299 +0400 Could not find last pushed template, returning empty template config tree&lt;/P&gt;&lt;P&gt;2018-11-01 10:19:55.312 +0400 client l2ctrld reported op command was SUCCESSFUL&lt;/P&gt;&lt;P&gt;2018-11-01 10:21:47.578 +0400 client cryptod reported op command was SUCCESSFUL&lt;/P&gt;&lt;P&gt;2018-11-01 10:21:47.674 +0400 Error:&amp;nbsp; pan_cfg_mgr_get_sp_disabled(pan_cfg_mgr.c:7283): failed to fetch: NO_MATCHES&lt;/P&gt;&lt;P&gt;2018-11-01 10:21:48.105 +0400 client authd reported op command was SUCCESSFUL&lt;/P&gt;&lt;P&gt;2018-11-01 10:21:48.917 +0400 client cryptod reported op command was SUCCESSFUL&lt;/P&gt;&lt;P&gt;2018-11-01 10:21:49.004 +0400 Error:&amp;nbsp; pan_cfg_mgr_get_sp_disabled(pan_cfg_mgr.c:7283): failed to fetch: NO_MATCHES&lt;/P&gt;&lt;P&gt;2018-11-01 10:21:49.425 +0400 client authd reported op command was SUCCESSFUL&lt;/P&gt;&lt;P&gt;2018-11-01 10:30:00.692 +0400 Checking to purge appstatdb logtype&lt;/P&gt;&lt;P&gt;2018-11-01 10:33:33.955 +0400 client authd reported op command was SUCCESSFUL&lt;/P&gt;&lt;P&gt;2018-11-01 10:36:14.977 +0400 dnscfgmod: FQDN Refresh: Periodic TTL Expiry Refresh&lt;/P&gt;&lt;P&gt;2018-11-01 10:36:14.977 +0400 dnscfgmod: Main refresh function: (TTL Expiry)&lt;/P&gt;&lt;P&gt;2018-11-01 10:36:14.978 +0400 dnscfgmod:Fqdn refresh job 6360 scheduled&lt;/P&gt;&lt;P&gt;2018-11-01 10:36:14.978 +0400 FqdnRefresh job started processing. Dequeue time=2018/11/01 10:36:14 2018-11-01 10:36:19.750 +0400 dnscfgmod: Resolving fqdns took 5 secs&lt;/P&gt;&lt;P&gt;2018-11-01 10:36:19.750 +0400 Fqdn refresher thread device requested last config&lt;/P&gt;&lt;P&gt;2018-11-01 10:36:20.203 +0400 Warning:&amp;nbsp; pan_hash_init(pan_hash.c:112): nbuckets 100 is not power of 2!&lt;/P&gt;&lt;P&gt;2018-11-01 10:36:20.203 +0400 Warning:&amp;nbsp; pan_hash_init(pan_hash.c:112): nbuckets 100 is not power of 2!&lt;/P&gt;&lt;P&gt;2018-11-01 10:36:20.203 +0400 shm alloc(read-only) 'pan_shm_base' size 104172048&lt;/P&gt;&lt;P&gt;2018-11-01 10:36:20.950 +0400 dnscfgmod: Fqdn pijepkm.work/pijepkm.work could not be resolved&lt;/P&gt;&lt;P&gt;2018-11-01 10:36:20.950 +0400 dnscfgmod: Fqdn vfpurtshsphuwqulm.pw/vfpurtshsphuwqulm.pw could not be resolved&lt;/P&gt;&lt;P&gt;2018-11-01 10:36:20.950 +0400 dnscfgmod: Fqdn ruuvsgbaxbh.work/ruuvsgbaxbh.work could not be resolved&lt;/P&gt;&lt;P&gt;2018-11-01 10:36:20.951 +0400 dnscfgmod: Fqdn smtp.office365.com/smtp.office365.com not used&lt;/P&gt;&lt;P&gt;2018-11-01 10:36:20.951 +0400 dnscfgmod: Fqdn ppa.adnoc/ppa.adnoc.ae not used&lt;/P&gt;&lt;P&gt;2018-11-01 10:36:29.632 +0400 client device reported error: Error: config push error&lt;/P&gt;&lt;P&gt;(Module: device)&lt;/P&gt;&lt;P&gt;2018-11-01 10:36:29.633 +0400 client device reported Phase 1 FAILED&lt;/P&gt;&lt;P&gt;2018-11-01 10:36:29.633 +0400 Error:&amp;nbsp; pan_cfg_refresh_deviceconfig(pan_cfg_commit_jobs.c:3177): phase 1 failed&amp;nbsp; cstate:6 -&amp;nbsp; verify:0&lt;/P&gt;&lt;P&gt;2018-11-01 10:36:29.634 +0400 Error:&amp;nbsp; pan_dnscfg_force_refresh_fqdns_after_fail(pan_cfg_dnscfg.c:3813): Trying to refresh fqdn job after the first retry.Not allowed.&lt;/P&gt;&lt;P&gt;2018-11-01 10:36:29.690 +0400 Error:&amp;nbsp; pan_cfg_dnscfg_refresh_fqdns(pan_cfg_dnscfg.c:4418): Failed to refresh the fqdn.&lt;/P&gt;&lt;P&gt;2018-11-01 10:36:29.757 +0400 Error:&amp;nbsp; pan_jobmgr_process_job(pan_job_mgr.c:3228): Fqdn Refresh job failed&lt;/P&gt;&lt;P&gt;mailclient: Socket timeout. host=172.16.0.33&lt;/P&gt;</description>
      <pubDate>Thu, 01 Nov 2018 10:08:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/commit-not-working-in-passive-firewall/m-p/238179#M68220</guid>
      <dc:creator>Venkatesan_radhakrishnan</dc:creator>
      <dc:date>2018-11-01T10:08:13Z</dc:date>
    </item>
    <item>
      <title>Re: Commit not working in passive firewall</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/commit-not-working-in-passive-firewall/m-p/238565#M68338</link>
      <description>&lt;P&gt;Guys&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have fixed the issue, I gave show management-clients on CLI of passive firewall it displayed the clients running.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I found '*' on the device client, I tried to restart the managment-server and devsrvr but it didn't restart the device client process.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So I restarted the secondary box then it got fixed. If your issue is in Primary box failover to secondary and try it.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;After getting commit to both firewall, HA Issue fixed and configuration are synced now&lt;/P&gt;</description>
      <pubDate>Mon, 05 Nov 2018 09:38:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/commit-not-working-in-passive-firewall/m-p/238565#M68338</guid>
      <dc:creator>Venkatesan_radhakrishnan</dc:creator>
      <dc:date>2018-11-05T09:38:33Z</dc:date>
    </item>
  </channel>
</rss>

