user-id-agent unexpected here

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.
Palo Alto Networks Approved
Palo Alto Networks Approved
Community Expert Verified
Community Expert Verified

user-id-agent unexpected here

L2 Linker

Hello, 

 

i just update pan os from 9.1.6 to 10. 

And on one of the firewall i get error:

..........
Validation Error:
user-id-agent unexpected here
vsys is invalid
[edit]

 

Could you please advice were can be the problem.

Thank you!

1 accepted solution

Accepted Solutions

Cyber Elite
Cyber Elite

I also experience the same issue on PA when Upgraded from 9.1.14 to 10.1.10h

Fix was 

 

1. Perform configuration backup.
2. Navigate to Device > Setup >Operations Click on Save named configuration snapshot to save the configuration locally
3. Navigate to Device > Setup >Operations click on 'Revert to last saved configuration'
4. Push configuration from Panorama.

 

Regards

MP

Help the community: Like helpful comments and mark solutions.

View solution in original post

5 REPLIES 5

Cyber Elite
Cyber Elite

@stef,

Sounds like the configuration didn't migrate properly. I'd try just going into the 'User Identification' settings under the Device tab and opening up the 'User-ID Agents' tab and verifying that these settings look correct for your environment. Then go into each entry and just hit OK. Sometimes that's enough to get the GUI to straighten things out for you without having to dive into the XML file.

L0 Member

I also received this error while trying to push changes from Panorama to the firewall after upgrading to V10. Luckly, it only occurred on one PA-850, which was in my QA environment.     Downgrading from 10.0.4 to 9.1.7 (original) didn't fix the issue.    

 

What I did to fix the issue was force the template values from Panorama to the Firewall which allowed the commit to be successful.  Before you do this make sure you have a backup copy of the existing configuration of the affected firewall.   Make sure that the template values on the Panorama doesn't change/break your management interface.     

Step 1:  Force values from Panorama

Step 2: Reload saved config and commit. 

 

This should clear up the errors and allow you to push new changes.

L0 Member

I faced the same error, I exported the config, opened the XML and searched for user-id-agent, once I found that line I deleted it (it was one single open tag with no beginning/ending), re-imported the config and the commit was successful.

Cyber Elite
Cyber Elite

I also experience the same issue on PA when Upgraded from 9.1.14 to 10.1.10h

Fix was 

 

1. Perform configuration backup.
2. Navigate to Device > Setup >Operations Click on Save named configuration snapshot to save the configuration locally
3. Navigate to Device > Setup >Operations click on 'Revert to last saved configuration'
4. Push configuration from Panorama.

 

Regards

MP

Help the community: Like helpful comments and mark solutions.

Would like to bump this - I was in the same situation .. upgraded firewall from 9.1.14 to 10.1.10-h1, had the same errors OP was posting, errors are vague and difficult to track down in config. Followed this procedure and it fixed the errors with no impact. Hoping this was a one-off and this does not happen on more firewalls..

  • 1 accepted solution
  • 7607 Views
  • 5 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!