If the device uses policies pushed from Panorama that specify zone names (rather than any) and an attempt to rename that zone is made on the device, an “incompatible zone” and “configuration is invalid” error will occur upon commit.
Attempting to update the zone name in the policy being pushed from Panorama will result in the inability to push that configuration to the device because the zone name is invalid.
Note: Between steps 4 and 5 of this procedure, traffic will not flow through the firewall so it is highly recommended to perform this procedure during off-peak hours.
Create a new zone on the Firewall using the name that the current zone needs to be renamed to and commit the change. This zone will be deleted later but is needed to import the new Panorama config
In Panorama, change the zone name in the policies for the device group containing this device.
Push the new config to the device.
Once it is committed the firewall will NOT pass traffic for this zone until step 5 is completed.
On the Firewall, delete the zone created in step one. Once the zone is deleted rename the old zone with the new name