<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic PANORAMA COMMIT AND PUSH TO FIREWALL FAILS WITH ERROR in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/panorama-commit-and-push-to-firewall-fails-with-error/m-p/324961#M82912</link>
    <description>&lt;P&gt;&lt;SPAN&gt;For the last few days, we have been trying to import firewalls into Panorama and have not been successful at it.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Panorama firmware is&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;9.0.7&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Palo Alto firmware: 8.1.13&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Description of issue: During the importing process, I was able to extract the configs from PA firewall onto the Panorama. However, when I tried to commit the configs back to PA firewall from Panorama. The commit would fail, and the reason for the failure is because there’s missing IP addresses in ‘Objects’.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Following is the commit error&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;rulebase -&amp;gt; nat -&amp;gt; rules -&amp;gt; AESG-DNAT-P157-2 -&amp;gt; destination 'Host_13.55.26.51-32' is not an allowed keyword&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; rulebase -&amp;gt; nat -&amp;gt; rules -&amp;gt; AESG-DNAT-P157-2 -&amp;gt; destination Host_13.55.26.51-32 is an invalid ipv4/v6 address&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; rulebase -&amp;gt; nat -&amp;gt; rules -&amp;gt; AESG-DNAT-P157-2 -&amp;gt; destination Host_13.55.26.51-32 invalid range start IP&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; rulebase -&amp;gt; nat -&amp;gt; rules -&amp;gt; AESG-DNAT-P157-2 -&amp;gt; destination 'Host_13.55.26.51-32' is not a valid reference&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; rulebase -&amp;gt; nat -&amp;gt; rules -&amp;gt; AESG-DNAT-P157-2 -&amp;gt; destination is invalid&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Error: Failed to find address 'Host_13.55.26.51-32'&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Error: Unknown address 'Host_13.55.26.51-32'&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Error: Failed to parse nat policy&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; (Module: device)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Config 'AGENT-CONFIG':&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; GlobalProtect App Dynamic Configuration misses information for 'show-system-tray-notifications'.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; (Module: sslvpn)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Commit failed&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;it seems like the problem is with the missing objects during the importing process. As an example, the total amount of addresses on the firewall is 490. However, we can only see 460 after the configs have been copied over from Panorama to the firewall.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;We have also tried adding&amp;nbsp;&amp;nbsp;Host_13.55.26.51-32' manually to panorama as a shared object but still cannot commit&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;we did upgrade our Panorama firmware recently from 9.0.4 --- &amp;gt; 9.0.7. And our firewall firmware from 8.0.13 -&amp;gt; 8.1.13&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 27 Apr 2020 03:48:34 GMT</pubDate>
    <dc:creator>Jatin.Singh</dc:creator>
    <dc:date>2020-04-27T03:48:34Z</dc:date>
    <item>
      <title>PANORAMA COMMIT AND PUSH TO FIREWALL FAILS WITH ERROR</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/panorama-commit-and-push-to-firewall-fails-with-error/m-p/324961#M82912</link>
      <description>&lt;P&gt;&lt;SPAN&gt;For the last few days, we have been trying to import firewalls into Panorama and have not been successful at it.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Panorama firmware is&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;9.0.7&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Palo Alto firmware: 8.1.13&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Description of issue: During the importing process, I was able to extract the configs from PA firewall onto the Panorama. However, when I tried to commit the configs back to PA firewall from Panorama. The commit would fail, and the reason for the failure is because there’s missing IP addresses in ‘Objects’.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Following is the commit error&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;rulebase -&amp;gt; nat -&amp;gt; rules -&amp;gt; AESG-DNAT-P157-2 -&amp;gt; destination 'Host_13.55.26.51-32' is not an allowed keyword&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; rulebase -&amp;gt; nat -&amp;gt; rules -&amp;gt; AESG-DNAT-P157-2 -&amp;gt; destination Host_13.55.26.51-32 is an invalid ipv4/v6 address&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; rulebase -&amp;gt; nat -&amp;gt; rules -&amp;gt; AESG-DNAT-P157-2 -&amp;gt; destination Host_13.55.26.51-32 invalid range start IP&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; rulebase -&amp;gt; nat -&amp;gt; rules -&amp;gt; AESG-DNAT-P157-2 -&amp;gt; destination 'Host_13.55.26.51-32' is not a valid reference&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; rulebase -&amp;gt; nat -&amp;gt; rules -&amp;gt; AESG-DNAT-P157-2 -&amp;gt; destination is invalid&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Error: Failed to find address 'Host_13.55.26.51-32'&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Error: Unknown address 'Host_13.55.26.51-32'&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Error: Failed to parse nat policy&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; (Module: device)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Config 'AGENT-CONFIG':&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; GlobalProtect App Dynamic Configuration misses information for 'show-system-tray-notifications'.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; (Module: sslvpn)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Commit failed&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;it seems like the problem is with the missing objects during the importing process. As an example, the total amount of addresses on the firewall is 490. However, we can only see 460 after the configs have been copied over from Panorama to the firewall.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;We have also tried adding&amp;nbsp;&amp;nbsp;Host_13.55.26.51-32' manually to panorama as a shared object but still cannot commit&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;we did upgrade our Panorama firmware recently from 9.0.4 --- &amp;gt; 9.0.7. And our firewall firmware from 8.0.13 -&amp;gt; 8.1.13&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 27 Apr 2020 03:48:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/panorama-commit-and-push-to-firewall-fails-with-error/m-p/324961#M82912</guid>
      <dc:creator>Jatin.Singh</dc:creator>
      <dc:date>2020-04-27T03:48:34Z</dc:date>
    </item>
    <item>
      <title>Re: PANORAMA COMMIT AND PUSH TO FIREWALL FAILS WITH ERROR</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/panorama-commit-and-push-to-firewall-fails-with-error/m-p/325497#M83002</link>
      <description>&lt;P&gt;Push the templates first, then push the policy&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;(Also please don't put your subject in all caps, this is a professional forum &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt; )&lt;/P&gt;</description>
      <pubDate>Thu, 30 Apr 2020 10:57:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/panorama-commit-and-push-to-firewall-fails-with-error/m-p/325497#M83002</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2020-04-30T10:57:51Z</dc:date>
    </item>
  </channel>
</rss>

