Enhanced Security Measures in Place:   To ensure a safer experience, we’ve implemented additional, temporary security measures for all users.

Problem with export&push config to newly added firewall in panorama

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

Problem with export&push config to newly added firewall in panorama

L2 Linker

Hello,

 

We are trying to add new firewall to panorama . We follow the steps from the instruction for adding HA cluster to Panorama. But when we get to the step with export&push device config we get an error:

  • Validation Error:
  • plugins unexpected here
  • vsys is invalid

 

Software version of panorama and firewalls is 11.0.1-h2

 

We tried several suggestions that we found in previous posts - uninstalling plugins on both panorama and firewalls,  restart management server process, load config and force commit etc. but there is no success. Same error.

 

Can you suggest what and were should we look at .

 

Thanks in advance!

 

 

4 REPLIES 4

Community Team Member

Hi @stef ,

 

Are the firewalls you have multi-vsys by chance? I see a known issue with 11.0.1 PAN-225337.

LIVEcommunity team member
Stay Secure,
Jay
Don't forget to Like items if a post is helpful to you!

Please help out other users and “Accept as Solution” if a post helps solve your problem !

Read more about how and why to accept solutions.

Hi @JayGolf,

 

the firewalls are pa-440 .  No multi vsys.

L1 Bithead

I saw this issue when there was configuration in Shared in the network/device templates being pushed to single vsys firewalls, by moving all the configuration out of Shared it solved the issue.

 

The whole Shared/Multi-Vsys/Single-vsys  template management between Panorama and the firewalls is really very problematic in my experience, this is one error of many that I have encountered in this, what I'd give for a month to sit with the developers (if there are any left) of Panorama to fix the quality of life issues.

Yes, we had such issues related to shared objects but we manage to fix/bypass them. The only think now is the error with the plugins.

I will open case with palo alto .

PS: "to fix the quality of life" we really need that in next version : )

  • 1164 Views
  • 4 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!