- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
09-07-2020 08:03 AM
Hi All,
We are running PA with firmware 9.0.4
Getting errors while "disabling" not required/unsed IPSec tunnel.
Error: tunnel interface tunnel.50 encap interface is not set.
Error: parse tunnel member failed.
Error: error parse qos tunnel group
Error: error parse tunnel-traffic group list
Error: alloc obj iterator failed
Error: QoS configuration error.
(Module: device)
Commit Failed.
however one more tunnel (eg: tunnel.60)we can successfully disabled.
- IKE gateway of both tunnels (tun.50 and tun.60) are diferent.
- Both tunnels sharing share IPSec crypto & IKE crypto.
please help for reason and solution.
09-07-2020 07:06 PM
I'm hoping that you meant 9.1.4 and not 9.0.4, if not you should really consider updating to the latest supported maintenance release as you're multiple versions behind at this point.
I'm assuming that you are more comfortable with the GUI; enter tunnel.50 in the search box and verify that you aren't referencing tunnel.50 in the rest of your configuration, because it sounds like you are. You can otherwise export the running-config.xml and simply search for tunnel.50 and verify that you don't have it referenced and if you do remove it.
08-23-2022 12:12 PM
Hello Guys,
I have the same problem. What did you do to resolve this?
Error: tunnel interface tunnel.17encap interface is not set.
Error: parse tunnel member failed.
Error: error parse qos tunnel group
Error: error parse tunnel-traffic group list
Error: alloc obj iterator failed
Error: QoS configuration error.
(Module: device)
Commit Failed.
08-23-2022 02:56 PM
Hello @Wilian1984
it looks like that QoS is preventing you to disable ipsec tunnel. Could you navigate to: Network > QoS, then select the interface that is used to build ipsec tunnel (untrust), then navigate to Tunneled Traffic and remove "tunnel.17", then you should be able to disable it from: IKE Gateways and IPSec Tunnels and commit.
Kind Regards
Pavel
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!