How to Disable Auto Commit in Firewall

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

How to Disable Auto Commit in Firewall

L2 Linker

Is there any way to stop Auto-Commit?

I am facing issues with one of my Palo Alto Firewall where Auto Commit keeps failing and starting again & again.

Due to BUG, it's happening, and solution is to upgrade or downgrade to another release.

 

Whenever I am trying to upgrade/downgrade it gives error that Auto-commit is in queue and cannot install. So, is there any way to stop auto-commit so that I can upgrade/downgrade the device?

 

Thanks in advance!!!!!!!

 

8 REPLIES 8

Cyber Elite
Cyber Elite

What is the error that autocommit fails with?

What is output of 

> debug dataplane internal pdt  bcm show port status

https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u000000HCcXCAW

 

I have seen few cases where autocommit started working after firewall was unplugged from power and plugged back in (was suggested by TAC and worked).

Enterprise Architect, Security @ Cloud Carib Ltd
Palo Alto Networks certified from 2011

Cyber Elite
Cyber Elite

@Ankit1Singh,

TAC should be giving you guidance here, especially if auto-commit is restarting once it's failed. If you haven't already, I'd make sure that whoever you're working with is aware that's happening. The only way that I've ever seen that auto-start killed off is through root access. 

L2 Linker

@Raido_Rattameister  & @BPry  Thanks for your input.

 

I have PA410 new box.

++ Tried with multiple reboot of the firewall still same issue.

++ Tried with the factory-reset, still same issue.

++ Tried to restart the process “logrcvr” still same issue.

++ Tried to restart the mgmt.-server, still same issue.

++ Inside TSF we found the process “logrcvr” keeps crashing.

 

Commit error below:

  • Management server failed to send phase 1 to client logrcvr
  • Commit failed
  • Failed to commit policy to device

I am not able to upgrade or downgrade as the moment I hit Install PAN-OS it says " commit is in queue and can not process this task.

Even From Maintenance mode I check only available image is 11.0.2-h2 which we already factory reset. 

I have the exact same issue, same model and everything, it started when i put it up on 10.1.11 this is a new box. where you able to get this resolved? i'm just trying to get this setup so i can replace the one that died in out branch.

L1 Bithead

Having the same issue on a brand-new PA-410.

 

L0 Member

Dealing with a similar issue on a 445, cert issue forced us to upgrade to 11.0.1-h1 and passive node auto-commit fails repeatedly. Thankfully the active node upgrade went fine. Keep receiving below error on auto-commit jobs. Unable to remove the application from db. 


Error: Duplicate application name 'omron-fins-base'

The issue was resolved by upgrading to the most recent version of PanOS. To be able to upgrade, you need to cancel the autocommit job with 'clear job id <>' and run the upgrade with 'request system software install version <>' at the same second, so upgrade job will be taken by fw first.

Hi,

Is this the 'fix action'  ?

 

We're working with TAC now on an issue that's very similar...

  • 2281 Views
  • 8 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!