Cannot create custom region

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Cannot create custom region

L2 Linker

Running 10.1.6-h3 and in Panorama I go to objects, regions and click add but it won't let me add an IP Address.  We only allow US traffic using a deny policy for anything other than the US and I have a need to add a single IP address in another country without allowing the whole country. 

 

I have two other custom regions but even editing those I can't see or edit the IP Address area. 

 

Anyone else not able to add a custom region?

5 REPLIES 5

Cyber Elite
Cyber Elite

on 10.1.6-h3 I'm able to create custom regions, but i need to click 'create' explicitly and then i need to manually delete 'None' before i can enter an IP

 

Screenshot 2022-07-14 at 13.50.27.pngScreenshot 2022-07-14 at 13.53.54.png

Tom Piens
PANgurus - Strata specialist; config reviews, policy optimization

L2 Linker

I don't get the "None" IP address and cannot add one

@KurtHinson - Did you find any fix for this? I also can not add or delete IPs from custom regions (or even view the existing entries, though they do show up in the overall region list).

Community Team Member

Hi @Adrian_Jensen ,

 

Which version are you running ?

For reaper it seems to be working fine in 10.1.6-h3.

I'm testing it on 11.1.6 and it's working as well.

@KurtHinson , I don't get the "OK" to appear until I click "Create ****" first and then click outside the window.  Only then does the OK button appears and the custom object appears in my Region list once I click OK.

kiwi_0-1765547927483.png

kiwi_1-1765547954186.png

 

Once I click OK they end up in my Regions list :

kiwi_2-1765548004671.png

 

Hope this helps,

 

LIVEcommunity team member, CISSP
Cheers,
Kiwi
Please help out other users and “Accept as Solution” if a post helps solve your problem !

Read more about how and why to accept solutions.

L6 Presenter

Hello @kiwi 

I am running 10.2.9-h21 across my firewalls. 3 of them had this problem (1 stand-alone, 1 HA pair) with not being able to view/add/delete IP address entries from an existing custom region object. I could add a new region object, but not add IP addresses to those either. When trying to add/delete you would just get a red box around the address field. The stand-alone was fixed after a reboot do to a major failure (more on that in a minute), the HA pair seems to have fixed itself after generating a tech support file. Unfortunately, I don't have screenshots at the time, but this is what is looked like:

2025-12-12_094641.png

Trying to add an entry to an existing object (or new object):

2025-12-12_094916.png

 

Based on some KBs and previous threads discussing errors with duplicate custom/default region names causing commit and edit problems, I ran a "debug device-server reset id-manager type vsys-region" and "debug device-server reset id-manager type all" on my standalone firewall, to try to reset the custom region object list. This caused all traffic matching the "CDN" custom region to start being denied in the matching allow Security rule. I deleted the CDN object and all Security rule references, which caused traffic to show as allowed again in the appropriate rules, but my VPN ends users still couldn't access internal/external resources. Traffic logs showed the traffic flowing in both directions, but it appeared the firewall wasn't actually forwarding return traffic back to the end user.

 

I was forced to reboot the firewall, at which point everything started working normally and I could add/delete entries from custom region again in the stand-alone firewall. I opened a ticket with PA support. In prep for discussing with support, I also generated a TSF on both my HA firewall. Afterwards I found I could edit custom region entries again. I hadn't made any changes on the HA up to that point, so it appears the TSF generation somehow fixed the HA system. I have since successfully added entries on the HA.

 

This "unable to edit region entries" problem is very similar to a known issue with Panorama that was fixed in an earlier PAN-OS release. I haven't been able to find a release note for anything else similar. PA support says the id-manager reset should have been harmless and is what they would have suggested, they are still researching known issues.

  • 3486 Views
  • 5 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!