Validation Error with Push to Firewall (Missing service value)

Reply
L2 Linker

Validation Error with Push to Firewall (Missing service value)

Hello, 

 

I've used the migration tool to covert a SideWinder config to Panorama. I send the config via the API to panorama can commit, but when I push to the firewall it fails with the error "Missing service value" and "Failed to parse secuirty policy".

 

Prior to sending the configuration over I fixed any duplicate services or invalid serives. I have also tried atomic and subatomic API calls, but still recieve the error.

L7 Applicator

Re: Validation Error with Push to Firewall (Missing service value)

Hi,

 

Seems a bug, please wsearch by <service/> in your XML and replace it by <service><member>any</member></service> and try again to load. Regards

L2 Linker

Re: Validation Error with Push to Firewall (Missing service value)

Yes, this does appear to work when the services are removed from all rules in this device group. Is there anyway to fix this to avoid manually entering the services for 400 rules?

L2 Linker

Re: Validation Error with Push to Firewall (Missing service value)

There were invalid service groups that were not showing up under service groups with the invalid filter. I copied all the rules over using the CLI set commands, instead of taking the invalid groups as it did with the API push, it set the service to none and then errored out on Panorama Validation, allowing me to see exactly which rules were causing the problem so i could correct

L1 Bithead

Re: Validation Error with Push to Firewall (Missing service value)

(XXX-XXXX (vsys2)
Error: Missing service value
Error: Failed to parse security policy
Module: device)
Configuration is invalid

L1 Bithead

Re: Validation Error with Push to Firewall (Missing service value)

show config running

after copy current config we can edit it for removing invalid object offline?

Once it is modify we can push the confugarion to Panorama?

Pls help on this. Any suggation appriciated. 

L7 Applicator

Re: Validation Error with Push to Firewall (Missing service value)

Please use Expedition instead... MT stopped the development 2 years ago.

L1 Bithead

Re: Validation Error with Push to Firewall (Missing service value)

Thanks for the suggation....

L1 Bithead

Re: Validation Error with Push to Firewall (Missing service value)

8.1.2 version panorama login failure through tacacs+ intermittent. If anyone has any solution to fix it permanently.

Error: 15045 CHAP is not allowed.

 

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!

The Live Community thanks you for your participation!