Panorama SDWAN commit "Failed plugin validation"

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Panorama SDWAN commit "Failed plugin validation"

L1 Bithead

I've gone through the full beacon modules and went through instructions here on how to setup SDWAN in my lab (so I think I'm configuring it correctly): https://docs.paloaltonetworks.com/sd-wan/2-2/sd-wan-admin/configure-sd-wan

 

When I get to the part where I add SDWAN devices I get the error at the bottom. I am at a loss, I've tried too many different things to list here. Ideally, I'm hoping someone could direct me to where to find more info about the failure, as this message isn't very helpful (in the CLI plugins-log is empty, no SDWAN log).

 

I've checked my compatibilities here (and below are my current versions): https://docs.paloaltonetworks.com/compatibility-matrix/panorama/plugins

Panorama version: 10.1.11-h1

SD-WAN Plugin version: 2.2.6 (tried 2.2.5 too, only other listed as compatible with 10.1.11)

VM-Series Plugin version: 2.1.14

 

Failure Message:

 

Commit
Completed
Failed
  • Partial changes to commit: changes to configuration by administrators: --
  • Failed plugin validation
1 accepted solution

Accepted Solutions

L1 Bithead

Resolution: I overlooked adding a subnet to Panorama > SD-WAN > VPN Cluster > VPN Address Pool. Once I added this it committed without issue.

 

My scenario was intending a VPN cluster, which auto configures a lot for you (creating interfaces etc.). I'm assuming that if I were missing any other important aspects of that it would probably throw the same, very unhelpful, error. My recommendation would be to make sure you have your predefined zones created, your SD-WAN devices added, VPN address pool,  and VPN cluster configuration in place.

 

Other note: Documentation tells you that it will auto create a virtual router of sdwan-default. You won't see it in the GUI, but if you check the XML file from Panorama, it definitely is there.

View solution in original post

1 REPLY 1

L1 Bithead

Resolution: I overlooked adding a subnet to Panorama > SD-WAN > VPN Cluster > VPN Address Pool. Once I added this it committed without issue.

 

My scenario was intending a VPN cluster, which auto configures a lot for you (creating interfaces etc.). I'm assuming that if I were missing any other important aspects of that it would probably throw the same, very unhelpful, error. My recommendation would be to make sure you have your predefined zones created, your SD-WAN devices added, VPN address pool,  and VPN cluster configuration in place.

 

Other note: Documentation tells you that it will auto create a virtual router of sdwan-default. You won't see it in the GUI, but if you check the XML file from Panorama, it definitely is there.

  • 1 accepted solution
  • 2420 Views
  • 1 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!