rulebase -> security -> rules -> permit_common 'permit_common' is already in use

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

rulebase -> security -> rules -> permit_common 'permit_common' is already in use

L0 Member

After importing configuration and after clicking on commit I get this, who know how can I solve it
rulebase -> security -> rules -> permit_common 'permit_common' is already in use

Thanks

3 REPLIES 3

Community Team Member

Hi @Hovo_Khach ,

 

I woud check your security policy rules and search for that specific rule name to see if there is a duplicate. Another way to check errors on commits is to open up the xml config and control + f and search the keyword the error brings up. 

LIVEcommunity team member
Stay Secure,
Jay
Don't forget to Like items if a post is helpful to you!

Please help out other users and “Accept as Solution” if a post helps solve your problem !

Read more about how and why to accept solutions.

Cyber Elite

@Hovo_Khach,

@JayGolf already mentioned the best way of doing this, but sometimes looking at the XML is the only way to see duplicates for some configuration aspects. The GUI sometimes just won't display duplicates properly all the time, so this may end up being something that you can only fix in the XML properly. 

L3 Networker

Reviving this thread as I ran into this issue when importing a device from one Panorama into another (and wanting to reuse the exact same config from the local NGFW into the new Panorama as a DG and a TS). 

 

First, it is incredibly important to ensure the config from the old Panorama is added to the device locally (as desired in my case), as well as to ensure the NGFW has the correct authkey from the new Panorama. This process is outlined here: How to move a managed firewall from one Panorama to another - Knowledge Base - Palo Alto Networks

 

Second (where I got caught up again), you need to follow the migration procedure outlined here when importing the device config into the new Panorama to create the DG, Template, and TS.  My stumbling point was not pushing the configuration bundle from Panorama to the newly added firewall to removal all policy rules and objects from its local configuration. Specifically, I ran into the issue outlined by "This step is necessary to prevent duplicate rule or object names, which would cause commit errors when you push the device group configuration from Panorama to the firewall in the next step". The key here is to not first push to the newly created DG and Template/TS, but rather use the "Export or push device config bundle" from Panorama --> Setup --> Operations first, and then push to the newly created DG and Template/TS. 

 

I hope this helps! 

 

Cheers 

 

 

 

 

  • 1744 Views
  • 3 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!