PANORAMA COMMIT AND PUSH TO FIREWALL FAILS WITH ERROR

Announcements

ATTENTION Customers, All Partners and Employees: The Customer Support Portal (CSP) will be undergoing maintenance and unavailable on Saturday, November 7, 2020, from 11 am to 11 pm PST. Please read our blog for more information.

Reply
Highlighted
L3 Networker

PANORAMA COMMIT AND PUSH TO FIREWALL FAILS WITH ERROR

For the last few days, we have been trying to import firewalls into Panorama and have not been successful at it.

 

Panorama firmware is 9.0.7

Palo Alto firmware: 8.1.13

 

Description of issue: During the importing process, I was able to extract the configs from PA firewall onto the Panorama. However, when I tried to commit the configs back to PA firewall from Panorama. The commit would fail, and the reason for the failure is because there’s missing IP addresses in ‘Objects’.

 

Following is the commit error

 

rulebase -> nat -> rules -> AESG-DNAT-P157-2 -> destination 'Host_13.55.26.51-32' is not an allowed keyword

    rulebase -> nat -> rules -> AESG-DNAT-P157-2 -> destination Host_13.55.26.51-32 is an invalid ipv4/v6 address

    rulebase -> nat -> rules -> AESG-DNAT-P157-2 -> destination Host_13.55.26.51-32 invalid range start IP

    rulebase -> nat -> rules -> AESG-DNAT-P157-2 -> destination 'Host_13.55.26.51-32' is not a valid reference

    rulebase -> nat -> rules -> AESG-DNAT-P157-2 -> destination is invalid

 

Error: Failed to find address 'Host_13.55.26.51-32'

    Error: Unknown address 'Host_13.55.26.51-32'

    Error: Failed to parse nat policy

    (Module: device)

    Config 'AGENT-CONFIG':

    GlobalProtect App Dynamic Configuration misses information for 'show-system-tray-notifications'.

    (Module: sslvpn)

    Commit failed

 

it seems like the problem is with the missing objects during the importing process. As an example, the total amount of addresses on the firewall is 490. However, we can only see 460 after the configs have been copied over from Panorama to the firewall.

 

We have also tried adding  Host_13.55.26.51-32' manually to panorama as a shared object but still cannot commit 

 

we did upgrade our Panorama firmware recently from 9.0.4 --- > 9.0.7. And our firewall firmware from 8.0.13 -> 8.1.13

Highlighted
L7 Applicator

Push the templates first, then push the policy

 

(Also please don't put your subject in all caps, this is a professional forum )

Tom Piens - PANgurus.com
New to PAN-OS or getting ready to take the PCNSE? check out amazon.com/dp/1789956374
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!

The Live Community thanks you for your participation!