Panorama Error commit

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

Panorama Error commit

L4 Transporter

Hi,

 

We have a cluster PA (Madrid) in version 5.0.14, and two PA in stand-alone (Singapur, Miami) in version 7.0.6.

We just commited the panorama config but we got a error in cluster PA Madrid.

Panorama in 7.0.6 can handle firewalls in version 5.0.14, right?? How can I get more info about this commited failed??

 Captura.JPG

7 REPLIES 7

Cyber Elite
Cyber Elite

Hi

 

if you click the red text, the commit dialog will pop up and tell you what went wrong

Tom Piens
PANgurus - Strata specialist; config reviews, policy optimization

Yes i know. But it shows "No details"

any log file or anything to know why its out of sync, and commit error.

if there's nothing in the system log, you should be able to connect to the firewall and verify the commit logs locally

Tom Piens
PANgurus - Strata specialist; config reviews, policy optimization

You are right.... looking in firewall local i found this : 'Commit job failed for user panorama - schema verification failed' )

what could it cause this error:

the schema is the way the configuration file is built and it looks like the firewall is not able to process the config file sent by panorama

did you enable features in the panorama templates that 5.0 doesn't support ?

Tom Piens
PANgurus - Strata specialist; config reviews, policy optimization

WE see this in PA ms.log file

 

May 17 09:35:31 Error: pan_cfg_session_is_alive(pan_cfg_mgr.c:13617): username missing in cms request
May 17 09:35:31 Error: pan_cfg_mgr_get_sp_disabled(pan_cfg_mgr.c:2025): failed to fetch: NO_MATCHES
May 17 09:35:32 Error: pan_cfg_mgr_get_tpl_disabled(pan_cfg_mgr.c:2047): failed to fetch: NO_MATCHES
May 17 09:35:32 Error: pan_cfg_mgr_get_sp_disabled(pan_cfg_mgr.c:2025): failed to fetch: NO_MATCHES
May 17 09:35:38 Template name not passed in request, not generating .template-config.xml and .pretrans-template-config.xml files
May 17 09:35:39 Verifying Configuration
May 17 09:35:40 Warning: pan_schema_verify_set_constraints(pan_schema_verify.c:267): Node entry - str 164.x.x.x not found - use refresh uniq hash
May 17 09:35:40 Warning: pan_schema_verify_set_constraints(pan_schema_verify.c:267): Node entry - str 192.x.x.x0/23 not found - use refresh uniq hash
May 17 09:35:41 Warning: pan_schema_verify_set_constraints(pan_schema_verify.c:267): Node entry - str simple-low not found - use refresh uniq hash
May 17 09:35:41 Warning: pan_schema_verify_set_constraints(pan_schema_verify.c:267): Node entry - str BLOCK-simple-client-critical not found - use refresh uniq hash
May 17 09:35:41 Warning: pan_schema_verify_set_constraints(pan_schema_verify.c:267): Node text - str military not found - use refresh uniq hash
May 17 09:35:41 Warning: pan_schema_verify_set_constraints(pan_schema_verify.c:267): Node text - str hacking not found - use refresh uniq hash
May 17 09:35:41 Warning: pan_schema_verify_set_constraints(pan_schema_verify.c:267): Node text - str alcohol-and-tobacco not found - use refresh uniq hash
May 17 09:35:41 Warning: pan_schema_verify_set_constraints(pan_schema_verify.c:267): Node text - str cp_whitelist not found - use refresh uniq hash
May 17 09:35:41 Error: pan_schema_verify_constraints(pan_schema_types.c:404): Not available for PAN-DB near line 26731
May 17 09:35:41 Error: pan_cfg_verify_ex(pan_cfg_commit_handler.c:1004): invalid confgiuration. Schema verification failed.
May 17 09:35:41 <line><![CDATA[profiles -> url-filtering -> Basic_SharedPr -> license-expired Not available for PAN-DB]]></line>
May 17 09:35:41 Error: pan_jobmgr_process_job(pan_job_mgr.c:2914): error verifying commit candidate
May 17 09:35:42 Error: pan_mgmt_get_sysd_string(pan_cfg_status_handler.c:363): failed to fetch cfg.gpdatafile-release-date
May 17 09:35:42 template config file /opt/pancfg/mgmt/template/template-config.xml doesn't exist
May 17 09:35:42 Could not find last pushed template, returning empty template config tree
May 17 09:35:42 file /opt/pancfg/mgmt/template/pretrans-template-config.xml does not exist, not computing md5sum
May 17 09:35:42 =================== mgt-request ===========

  • 3866 Views
  • 7 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!