- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
09-25-2023 08:55 AM
After importing configuration and after clicking on commit I get this, who know how can I solve it
rulebase -> security -> rules -> permit_common 'permit_common' is already in use
Thanks
09-27-2023 11:30 AM
Hi @Hovo_Khach ,
I woud check your security policy rules and search for that specific rule name to see if there is a duplicate. Another way to check errors on commits is to open up the xml config and control + f and search the keyword the error brings up.
09-27-2023 11:39 AM
@JayGolf already mentioned the best way of doing this, but sometimes looking at the XML is the only way to see duplicates for some configuration aspects. The GUI sometimes just won't display duplicates properly all the time, so this may end up being something that you can only fix in the XML properly.
10-02-2026 12:24 PM
Reviving this thread as I ran into this issue when importing a device from one Panorama into another (and wanting to reuse the exact same config from the local NGFW into the new Panorama as a DG and a TS).
First, it is incredibly important to ensure the config from the old Panorama is added to the device locally (as desired in my case), as well as to ensure the NGFW has the correct authkey from the new Panorama. This process is outlined here: How to move a managed firewall from one Panorama to another - Knowledge Base - Palo Alto Networks
Second (where I got caught up again), you need to follow the migration procedure outlined here when importing the device config into the new Panorama to create the DG, Template, and TS. My stumbling point was not pushing the configuration bundle from Panorama to the newly added firewall to removal all policy rules and objects from its local configuration. Specifically, I ran into the issue outlined by "This step is necessary to prevent duplicate rule or object names, which would cause commit errors when you push the device group configuration from Panorama to the firewall in the next step". The key here is to not first push to the newly created DG and Template/TS, but rather use the "Export or push device config bundle" from Panorama --> Setup --> Operations first, and then push to the newly created DG and Template/TS.
I hope this helps!
Cheers
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!

