<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Problem with Panorama pushed updates in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/problem-with-panorama-pushed-updates/m-p/374056#M89011</link>
    <description>&lt;P&gt;Hello all,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;i have problems with the security policy push.&lt;/P&gt;&lt;P&gt;When i try to push them the commits fails with :&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;STRONG&gt;.&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;Validation Error:&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;.&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;rulebase -&amp;gt; security -&amp;gt; rules -&amp;gt; ms-ad -&amp;gt; destination 'offices-subnet' is not an allowed keyword&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;.&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;rulebase -&amp;gt; security -&amp;gt; rules -&amp;gt; ms-ad -&amp;gt; destination offices-subnet is an invalid ipv4/v6 address&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;.&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;rulebase -&amp;gt; security -&amp;gt; rules -&amp;gt; ms-ad -&amp;gt; destination offices-subnet invalid range start IP&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;.&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;rulebase -&amp;gt; security -&amp;gt; rules -&amp;gt; ms-ad -&amp;gt; destination 'offices-subnet' is not a valid reference&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;.&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;rulebase -&amp;gt; security -&amp;gt; rules -&amp;gt; ms-ad -&amp;gt; destination is invalid&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;.&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;vsys1&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;.&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;Error: Failed to find address 'offices-subnet'&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;.&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;Error: Unknown address 'offices-subnet'&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;.&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;Error: Failed to parse security policy&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;.&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;(Module: device)&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;.&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;Commit failed&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;it happens with all shared addresses and address-groups. when i remove them, i mean when i push the polices without source/destination address configured, the commit is completed.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Sun, 13 Dec 2020 16:43:07 GMT</pubDate>
    <dc:creator>stef</dc:creator>
    <dc:date>2020-12-13T16:43:07Z</dc:date>
    <item>
      <title>Problem with Panorama pushed updates</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/problem-with-panorama-pushed-updates/m-p/374056#M89011</link>
      <description>&lt;P&gt;Hello all,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;i have problems with the security policy push.&lt;/P&gt;&lt;P&gt;When i try to push them the commits fails with :&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;STRONG&gt;.&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;Validation Error:&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;.&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;rulebase -&amp;gt; security -&amp;gt; rules -&amp;gt; ms-ad -&amp;gt; destination 'offices-subnet' is not an allowed keyword&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;.&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;rulebase -&amp;gt; security -&amp;gt; rules -&amp;gt; ms-ad -&amp;gt; destination offices-subnet is an invalid ipv4/v6 address&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;.&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;rulebase -&amp;gt; security -&amp;gt; rules -&amp;gt; ms-ad -&amp;gt; destination offices-subnet invalid range start IP&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;.&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;rulebase -&amp;gt; security -&amp;gt; rules -&amp;gt; ms-ad -&amp;gt; destination 'offices-subnet' is not a valid reference&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;.&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;rulebase -&amp;gt; security -&amp;gt; rules -&amp;gt; ms-ad -&amp;gt; destination is invalid&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;.&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;vsys1&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;.&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;Error: Failed to find address 'offices-subnet'&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;.&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;Error: Unknown address 'offices-subnet'&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;.&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;Error: Failed to parse security policy&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;.&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;(Module: device)&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;.&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;Commit failed&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;it happens with all shared addresses and address-groups. when i remove them, i mean when i push the polices without source/destination address configured, the commit is completed.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 13 Dec 2020 16:43:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/problem-with-panorama-pushed-updates/m-p/374056#M89011</guid>
      <dc:creator>stef</dc:creator>
      <dc:date>2020-12-13T16:43:07Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with Panorama pushed updates</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/problem-with-panorama-pushed-updates/m-p/374069#M89012</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As per below logs I can assume that IP address /subnets were not properly defined or binded or might be wrong IPs&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Best Regards,&lt;/P&gt;&lt;P&gt;Suresh&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 13 Dec 2020 18:39:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/problem-with-panorama-pushed-updates/m-p/374069#M89012</guid>
      <dc:creator>SureshReddyM</dc:creator>
      <dc:date>2020-12-13T18:39:49Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with Panorama pushed updates</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/problem-with-panorama-pushed-updates/m-p/374070#M89013</link>
      <description>&lt;P&gt;if it was just one address ok , but there is 1000+ records.&amp;nbsp;&lt;/P&gt;&lt;P&gt;They used to worked before.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 13 Dec 2020 19:01:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/problem-with-panorama-pushed-updates/m-p/374070#M89013</guid>
      <dc:creator>stef</dc:creator>
      <dc:date>2020-12-13T19:01:49Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with Panorama pushed updates</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/problem-with-panorama-pushed-updates/m-p/374072#M89014</link>
      <description>&lt;P&gt;Did it all of a sudden stop working or is this a new implementation or upgrade?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;One thing to look for is that on the local firewall Panorama is allowed to push Objects:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="BeardedTree_0-1607889655009.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/29117i9BC78338D5C17C05/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="BeardedTree_0-1607889655009.png" alt="BeardedTree_0-1607889655009.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;As you're stating a blank push of a firewall policy without objects is working I believe this is enabled.&lt;/P&gt;&lt;P&gt;Make sure the Object or Object-Group you're trying to push out isn't bound to a certain firewall but is in the "Shared" object space or Object specifically for that FW.&lt;/P&gt;&lt;P&gt;If the item is a group containing more IP's, FQDN's or Objects it never hurts to check if the actually sub-objects for errors.&lt;/P&gt;</description>
      <pubDate>Sun, 13 Dec 2020 20:06:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/problem-with-panorama-pushed-updates/m-p/374072#M89014</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2020-12-13T20:06:42Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with Panorama pushed updates</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/problem-with-panorama-pushed-updates/m-p/374073#M89015</link>
      <description>&lt;P&gt;They are all shared.&lt;/P&gt;&lt;P&gt;If i create new shared one and push it it is work .&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 13 Dec 2020 20:44:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/problem-with-panorama-pushed-updates/m-p/374073#M89015</guid>
      <dc:creator>stef</dc:creator>
      <dc:date>2020-12-13T20:44:28Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with Panorama pushed updates</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/problem-with-panorama-pushed-updates/m-p/374108#M89019</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/156321"&gt;@stef&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;Is the offices-subnet the only object that you are having an issue with, or is it all of your address and address-group objects? It's not entirely clear from your earlier posts, but I'm assuming that this object is an address-group made up of a bunch of different address objects representative of all of your individual offices. When the commits started to fail, have you logged at the system logs and verified that nobody added in a new range that invalidated the entry? The error in your first post would indicate that someone simply fat fingered an IP address.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 14 Dec 2020 05:05:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/problem-with-panorama-pushed-updates/m-p/374108#M89019</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2020-12-14T05:05:22Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with Panorama pushed updates</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/problem-with-panorama-pushed-updates/m-p/374112#M89022</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;this is only the example. It is address not address set .&amp;nbsp; But the problem is with all other addresses and address-groups to&lt;/P&gt;&lt;P&gt;For example if i remove "&lt;SPAN&gt;offices-subnet" witch is configured as&amp;nbsp; source subnet the error appear for the destination one witch is different&amp;nbsp;and when i remove the destination one the error appear for the source&amp;nbsp;object of the next policy, and so on and so on.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;If i create new address-group or address and populate it in the policy there is no problem.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 14 Dec 2020 05:49:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/problem-with-panorama-pushed-updates/m-p/374112#M89022</guid>
      <dc:creator>stef</dc:creator>
      <dc:date>2020-12-14T05:49:31Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with Panorama pushed updates</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/problem-with-panorama-pushed-updates/m-p/374299#M89036</link>
      <description>&lt;P&gt;How were the object created initially? The way you're explaining it sounds to me like an import gone wrong where the firewall/Panorama did load the Object but something is "off" with the way it's in the running XML.&lt;/P&gt;</description>
      <pubDate>Mon, 14 Dec 2020 20:04:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/problem-with-panorama-pushed-updates/m-p/374299#M89036</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2020-12-14T20:04:03Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with Panorama pushed updates</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/problem-with-panorama-pushed-updates/m-p/374300#M89037</link>
      <description>&lt;P&gt;Another quick thought would be a Panorama running a newer version and using features that are not supported on the firewall you're pushing it to.&lt;/P&gt;</description>
      <pubDate>Mon, 14 Dec 2020 20:06:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/problem-with-panorama-pushed-updates/m-p/374300#M89037</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2020-12-14T20:06:26Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with Panorama pushed updates</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/problem-with-panorama-pushed-updates/m-p/374301#M89038</link>
      <description>&lt;P&gt;I import them via cli.&lt;/P&gt;&lt;P&gt;They used to work&lt;/P&gt;</description>
      <pubDate>Mon, 14 Dec 2020 21:38:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/problem-with-panorama-pushed-updates/m-p/374301#M89038</guid>
      <dc:creator>stef</dc:creator>
      <dc:date>2020-12-14T21:38:48Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with Panorama pushed updates</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/problem-with-panorama-pushed-updates/m-p/375770#M89215</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;updating panorama to 9.1.6 and Restart configd daemon fixed the issue .&lt;/P&gt;&lt;P&gt;Thank you all&lt;/P&gt;</description>
      <pubDate>Tue, 22 Dec 2020 08:53:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/problem-with-panorama-pushed-updates/m-p/375770#M89215</guid>
      <dc:creator>stef</dc:creator>
      <dc:date>2020-12-22T08:53:30Z</dc:date>
    </item>
  </channel>
</rss>

