- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
11-25-2020 09:52 AM
Hi
I have a Panorama appliance and i am configuring our firewalls for global protect VPN, but i noticed once i pushed out the config for the gateway, it fails as the because it says the tunnel interface doesnt have a virtual router!
I checked my config on the panorama and i have pushed out a default router, zones and interfaces to both firewalls. I have then override changes locally on each firewall for the default router, but when i dive further into this on each firewall it seems that the tunnel interfaces on the firewalls that read only and have the virtual router missing. On the Panorama it seems fine but on the firewalls it just wont go through.
Has anyone else noticed tunnel interfaces configured on a Panorama being read only on a firewall?
11-25-2020 10:25 AM
Hi @Dan_Fleming
When you override interfaces in the firewall , virtual router also will be overrided. Check the icon colour near by Virtual router name , if it is fully green it will accept changes from panorama . If it is partially green and yellow it will not accept changes from the panorama push.
Thanks,
Ram
11-26-2020 06:46 AM
Thanks but i know how the override works and it has flowed through most of the settings on the firewalls but when i look at the tunnel settings on the firewall there is no override option see screen shot below.
But if i go to the ethernet interfaces for example you can see the override and revert icons at the bottom, as well as assigned to the interfaces that i have changed. This is the same as the virtual router as well just for what ever reason the tunnel interfaces arent getting the override or revert options come up directly on the firewall
08-09-2021 02:08 AM
Hi Dan,
Can you share if you got this issue fixed?
Thank you.
01-10-2022 08:52 AM
Hi Dan,
We are also facing same issue , can you suggest for the same
Awaiting for your reply
01-10-2022 08:54 AM
We are also facing same issue , can you suggest for the same
Awaiting for your reply
05-08-2023 05:23 AM
Same issue, I am also trying with the cli command override, but not luck
Server error : Cannot override /config/devices/entry[@name='localhost.localdomain']/network/interface/tunnel, not valid override object
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!