- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
Content translations are temporarily unavailable due to site maintenance. We apologize for any inconvenience. Visit our blog to learn more.
05-17-2016 01:50 AM
Hi,
We have a cluster PA (Madrid) in version 5.0.14, and two PA in stand-alone (Singapur, Miami) in version 7.0.6.
We just commited the panorama config but we got a error in cluster PA Madrid.
Panorama in 7.0.6 can handle firewalls in version 5.0.14, right?? How can I get more info about this commited failed??
05-17-2016 02:16 AM
Yes i know. But it shows "No details"
05-17-2016 02:26 AM
any log file or anything to know why its out of sync, and commit error.
05-17-2016 02:53 AM
if there's nothing in the system log, you should be able to connect to the firewall and verify the commit logs locally
05-17-2016 03:11 AM
You are right.... looking in firewall local i found this : 'Commit job failed for user panorama - schema verification failed' )
what could it cause this error:
05-17-2016 04:07 AM
the schema is the way the configuration file is built and it looks like the firewall is not able to process the config file sent by panorama
did you enable features in the panorama templates that 5.0 doesn't support ?
05-17-2016 04:24 AM - edited 05-17-2016 05:51 AM
WE see this in PA ms.log file
May 17 09:35:31 Error: pan_cfg_session_is_alive(pan_cfg_mgr.c:13617): username missing in cms request
May 17 09:35:31 Error: pan_cfg_mgr_get_sp_disabled(pan_cfg_mgr.c:2025): failed to fetch: NO_MATCHES
May 17 09:35:32 Error: pan_cfg_mgr_get_tpl_disabled(pan_cfg_mgr.c:2047): failed to fetch: NO_MATCHES
May 17 09:35:32 Error: pan_cfg_mgr_get_sp_disabled(pan_cfg_mgr.c:2025): failed to fetch: NO_MATCHES
May 17 09:35:38 Template name not passed in request, not generating .template-config.xml and .pretrans-template-config.xml files
May 17 09:35:39 Verifying Configuration
May 17 09:35:40 Warning: pan_schema_verify_set_constraints(pan_schema_verify.c:267): Node entry - str 164.x.x.x not found - use refresh uniq hash
May 17 09:35:40 Warning: pan_schema_verify_set_constraints(pan_schema_verify.c:267): Node entry - str 192.x.x.x0/23 not found - use refresh uniq hash
May 17 09:35:41 Warning: pan_schema_verify_set_constraints(pan_schema_verify.c:267): Node entry - str simple-low not found - use refresh uniq hash
May 17 09:35:41 Warning: pan_schema_verify_set_constraints(pan_schema_verify.c:267): Node entry - str BLOCK-simple-client-critical not found - use refresh uniq hash
May 17 09:35:41 Warning: pan_schema_verify_set_constraints(pan_schema_verify.c:267): Node text - str military not found - use refresh uniq hash
May 17 09:35:41 Warning: pan_schema_verify_set_constraints(pan_schema_verify.c:267): Node text - str hacking not found - use refresh uniq hash
May 17 09:35:41 Warning: pan_schema_verify_set_constraints(pan_schema_verify.c:267): Node text - str alcohol-and-tobacco not found - use refresh uniq hash
May 17 09:35:41 Warning: pan_schema_verify_set_constraints(pan_schema_verify.c:267): Node text - str cp_whitelist not found - use refresh uniq hash
May 17 09:35:41 Error: pan_schema_verify_constraints(pan_schema_types.c:404): Not available for PAN-DB near line 26731
May 17 09:35:41 Error: pan_cfg_verify_ex(pan_cfg_commit_handler.c:1004): invalid confgiuration. Schema verification failed.
May 17 09:35:41 <line><![CDATA[profiles -> url-filtering -> Basic_SharedPr -> license-expired Not available for PAN-DB]]></line>
May 17 09:35:41 Error: pan_jobmgr_process_job(pan_job_mgr.c:2914): error verifying commit candidate
May 17 09:35:42 Error: pan_mgmt_get_sysd_string(pan_cfg_status_handler.c:363): failed to fetch cfg.gpdatafile-release-date
May 17 09:35:42 template config file /opt/pancfg/mgmt/template/template-config.xml doesn't exist
May 17 09:35:42 Could not find last pushed template, returning empty template config tree
May 17 09:35:42 file /opt/pancfg/mgmt/template/pretrans-template-config.xml does not exist, not computing md5sum
May 17 09:35:42 =================== mgt-request ===========
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!