Unable to Push Renamed Shared Object from Panorama to Device

Unable to Push Renamed Shared Object from Panorama to Device

30923
Created On 09/25/18 19:44 PM - Last Modified 06/09/23 06:15 AM


Resolution


Issue

  • An address object, called "address_object", is created as Shared in Panorama.
  • The object is pushed to multiple devices and used in some local security policies on each of the devices.
  • Rename object "address_object" to "address1_object" and commit and push changes to devices.
  • The commit on Panorama is OK.
  • The push to the device groups that use the shared object, returns
    Error, the object is used in a rule of "device name"

 

Cause

When an object is renamed the policies using the object are updated during the commit process.  In this case, the policy is local to the device but the object is pushed from Panorama.  Panorama is unable to update the policy/rule on the local device thus the validation check fails.

 

Resolution

There are three options to resolve this issue:

Option 1

Move the security policies which reference the shared object to Panorama.

 

Option 2

Create a new address object reflecting the new object name.  Update the local policies to use the new object then delete the old address object.

 

Option 3

When pushing the config to the device\device group, select the advanced options and check the "Merge with Device Candidate Config" checkbox.

 

owner: jteetsel



Actions
  • Print
  • Copy Link

    https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClcICAS&refURL=http%3A%2F%2Fknowledgebase.paloaltonetworks.com%2FKCSArticleDetail

Choose Language