We are migrating multiple Cisco ASA pairs into PA-3260. PANOS 9.0.7, Expedition 220.127.116.11. Initially we are testing using a single ASA at a time. At least one of the "simpler" ASAs seems to migrate cleanly. Our "main" ASA is more complex. After working to clean duplicates and etc, we are able to get to the point where the Commit Check does not generate any errors. Yet, the firewall indicates simply that the Configuration is invalid. The XML is about 94k lines long! Is there any guidance on what we could look for either in Expedition or in the PAN, in order to resolve this and get to a clean potential configuration? Our intention is to then use this as our new base configuration, and add the easier ASAs into it through Expedition.
I would recommend opening a TAC case to see if you can identify why you are receiving this error. There can be different reasons why this error is present, I know in the past even when creating config changes within the firewall itself I received these every once in a while and TAC helped me identify why. I know this happened when you uploaded a XML configuration but with no error output it is really hard for us to identify what portion of the config is the problem or if there is an issue with the firewall processing this request.
Palo Alto Networks TAC should be more helpful with your problem.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!