I have a Panorama- 10.1.4-H4 (upgraded from 10.1.3) on AWS and two other firewalls both at 10.0.9 on AWS.
After upgrading, Panorama, I cannot just commit. Throws an error saying plugins unexpected here (for schema verification failed-reverted the config and when trying to commit after that gives the plugin error)
I see below difference in the candidate and running configs when validating (after reverting the config):
I do not see any bugs or any one else facing similar issue.
It looks like a corrupt candidate configuration. But I am afraid if I force commit/force commit it will affect the prod environment specially as it says in the validation process the plugins will be deleted.
Plugin for Panorama: 3.0.2
Plugin for Firewalls: 2.14
If you try a commit force and the running config is corrupted, you will still probably get an error and the commit will not be successful.
If you want, export your configuration off, and password protect it. Attach to this thread and then PM directly with the password, then I will download it and try on my Panorama and see if I can figure it out. 😛 Always glad to assist the Community.
I just solved by myself the problem.
I mistake to not upgrading the vm_series plugin from 2.0.x to 2.1.x before upgrading the PAN-OS.
So I roolback the panorama to 10.0.11, upgraded the plugin, made a commit, and push the configuration
If the commit doesn't appear, change something, like a description somewhere, and after proceed to commit and push the configuration on the the vm (my case azure one).
For index research my error where
devices -> localhost.localdomain -> template -> azr-ext -> config -> devices -> localhost.localdomain -> deviceconfig -> plugins unexpected here
devices -> localhost.localdomain -> template -> azr-ext -> config -> devices -> localhost.localdomain -> deviceconfig is invalid
devices -> localhost.localdomain -> template-stack -> azr_stack -> config -> devices -> localhost.localdomain -> deviceconfig -> plugins unexpected here
devices -> localhost.localdomain -> template-stack -> azr_stack -> config -> devices -> localhost.localdomain -> deviceconfig is invalid
For both versione xml use the same schema, so I don't know why it says it's unexpected, btw I solved updating before the plugin.
This is likely caused by an incompatible vm_series plugins version on Panorama.
I had to upgrade my plugins version to from 2.0.x to 2.1.13 to resolve this.
See vm series plugins compatibility matrix for references https://docs.paloaltonetworks.com/compatibility-matrix/vm-series-firewalls/vm-series-plugin-compatib...
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!