I have tied my Panorama into Expedition so that I can create a Project and import the Panorama config into it. I've done this and went into one of the device groups and did some bulk changes. (log forwarding profile set for all rules, log on end and not on start for all, and a security profile on all) Then I generate the api calls and send just the security policy call back. I then take a look at Panorama and the rules look like they should however when I try to validate the policy I get a "Invalid service value combination, Failed to parse security policy" message.
How can I track down why this is happening?
We recently corrected a bug related to service timeout.
Could you try to update your Expedition, generate the API calls again and try to send them to the Panorama?
If you click on the generated API call, you should be able to see (and edit) the XML that is being send in the API call.
As the error seems to be related to services, you could do atomic API calls and focus on the API call that refers to the services to be sent.
If you continue having issues, I would suggest that you share this API call with us at fwmigrate at paloaltonetworks dot com
I have the latest version. I was doing atomic and just sending the security policy as nothing else should have changed since all I was doing was modifying the log start/end, log profile, and security profile entries on the rules.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!
The Live Community thanks you for your participation!