Schema Verification Failed

Reply
Highlighted
L4 Transporter

Schema Verification Failed

Greetings,

I am kind of stuck on a problem for which I am unable to find a resolution ... When I commit on my secondary device after adding a network setting, it fails with an error message "response page -> sslvpn-custom-login-page" unexpected here.

Nowhere did I add the response page on either the active or the passive device.  When the commit fails, I get an email alert with the reason stating "opaque: Commit job failed for user xxxx - schema verification failed".

I do not have this issue on the active device.  The active PAN commits well and the configuration does sync across, but when I do a change very specific for the passive it fails with the above messages.  I am having this problem ever since I have upgraded to version 5.0.7.

Tried looking wherever possible and nowhere do I find a trace of the custom response page.

Any thoughts guys???

Many Thanks

Kalyan


Accepted Solutions
L3 Networker

Re: Schema Verification Failed

I have seen this before, the verification is failing due to an invalid reference made for an object that does not exist.

i would recommend you to save, export the candidate config and find and remove the reference  under "response page -> sslvpn-custom-login-page" manually.

View solution in original post


All Replies
Highlighted
L6 Presenter

Re: Schema Verification Failed

Can you compare both config(active passive) as xml if anything you see strange about response page(different) ?

L3 Networker

Re: Schema Verification Failed

I have seen this before, the verification is failing due to an invalid reference made for an object that does not exist.

i would recommend you to save, export the candidate config and find and remove the reference  under "response page -> sslvpn-custom-login-page" manually.

View solution in original post

Highlighted
L4 Transporter

Re: Schema Verification Failed

Hey Guys... I have done the manual configuration checks and could not find anything related to response page -> sslvpn-custom-login page. The configuration between the active and passive perfectly idetical as well.

Highlighted
L6 Presenter

Re: Schema Verification Failed

You can export Active config and then import it to Passive.

Before commit change all values(management and HA config especially) related to

High Availability Synchronization

Then it should work.

Highlighted
L4 Transporter

Re: Schema Verification Failed

I will not permitted to do this on the live units specially when the configurations do synchronize.

Secondly, I do not have spare PA-5050s to play with or for a matter of fact no spare PAs to play with...

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!

The Live Community thanks you for your participation!