Enhanced Security Measures in Place:   To ensure a safer experience, we’ve implemented additional, temporary security measures for all users.

Reference not valid--Panorama

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

Reference not valid--Panorama

L4 Transporter

Hello,

 

Trying to deploy a new subinterface via a Panorama template to two PA-3060 devices but getting error below
 
  •  Validation Error:
  • import -> network -> interface 'ethernet1/6.52' is not a valid reference
  • import -> network -> interface is invalid
  • Commit failed
 
It doesn't matter what name or VLAN ID I give the interface, it does not allow to deploy the template to the devices.  We do have template override on the devices for that interface, however I cannot create it manually on the devices because then I can't create rules via Panorama.
Already tried with and without the security zone, checked App and Threat DB match, Panorama and two units are 7.0.3. Checked known bug issues...
 
 
Panorama config:
 
 
P.png
Device config:
 
D.png
Any suggestion?
 
Thanks in advance.
1 accepted solution

Accepted Solutions

L4 Transporter

Hello,

 

Just wanted to let provide an update/solution for the issue incase someone also faces similar problem.

During maintenance window, performed the following.

 

Back up firewall configuration
Remove Panorama Settings (IP address and Don’t import anything)
Click OK
Edit it again and enable both Policy and Device objects.
Click OK
From Panorama, commit Device Group (including the new sub-interface).

 

Thanks.

View solution in original post

4 REPLIES 4

Cyber Elite
Cyber Elite

one thing that pops up is the absense of a vsys in that interface (the 'none' bit), you may need to set the vsys

 

else, try deleting the interface, push the config, re-create the interface, push again

Tom Piens
PANgurus - Strata specialist; config reviews, policy optimization

L4 Transporter

Hello,

 

Just wanted to let provide an update/solution for the issue incase someone also faces similar problem.

During maintenance window, performed the following.

 

Back up firewall configuration
Remove Panorama Settings (IP address and Don’t import anything)
Click OK
Edit it again and enable both Policy and Device objects.
Click OK
From Panorama, commit Device Group (including the new sub-interface).

 

Thanks.

L3 Networker

I have faced same issue. To resolve did following steps :

1. Reverted the changes

2. First added interface through panorama

3. Then added sub-interface successfully

HI Farzana,

 

i am having the same issue.

my panorama version is 9.1.14-h1.

on your solution you mention remove panorama settings. i have removed it. do i need to commit it first before i push the config from panorama?

ImranFarooq_0-1678959771702.png

 

Thanks in advance

  • 1 accepted solution
  • 25458 Views
  • 4 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!