cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Who Me Too'd this topic

Can't commit from Panorama due to mis-match Vsys number between Pan and local box

L1 Bithead

wanted to know if anyone has ever experienced this issue. recently configured a new Vsys "Vsys6" which was successfully added to the correct Template_stack and device groups. everything worked fine for 2-3 weeks, however last night after adding 2 Sec.policies to the new Vsys. the commit failed. FYI for security i've edited the zone names and policy name.

 

 

  • . In VSYS vsys5 from zone "zone name" of type unknown and to zone "zone name" of type unknown are incompatible in security rule "rule name"
  • . In VSYS vsys5 from zone "zone name" of type unknown and to zone "zone name" of type unknown are incompatible in nat rule "rule name"
  • . In VSYS vsys5 from zone "zone name" of type unknown and to zone "zone name" of type unknown are incompatible in nat rule "rule name"
  • . In VSYS vsys5 from zone "zone name" of type unknown and to zone "zone name" of type unknown are incompatible in nat rule "rule name"
  • . Configuration is invalid

It goes on for a couple more rules where the zone or rule name will change.

 

I've noticed that on the PAN, the Vsys# does not match the name"description" from the Vsys# name"description" on the local boxes. for example on the PAN Vsys5 is named blue and Vsys6 is yellow, but on the local box Vsys5 is Yellow and Vsys6 is blue. I've tried pushing the stack to the boxes but that didnt work, tried reverting but that didn't work either.

 

 

 

Who Me Too'd this topic