Palo Alto Networks Knowledgebase: Panorama and AWS invalid reference commit error

Panorama and AWS invalid reference commit error

1153
Created On 08/05/19 19:57 PM - Last Updated 08/05/19 20:11 PM
Resolution

Setup

Palo Alto Networks firewalls being deployed on AWS and managed by Panorama.

 

Symptom/Issue

After performing the following steps, the commit fails as a result of an invalid reference to the cert from templates for the decryption policy in DG (Device Group). Cross-references between DG and template are based on common devices being present in both. If changes are made, then commit is expected to fail. At least one device needs to be common.


Note: The firewalls are auto-scaled on an as-needed basis, so they may end up deleting all instances of firewalls at a single point of time.

 

Steps

  • Add a few firewalls to device group and template, configured a bunch of policies: NAT rules and decryption policy referencing a certificate from a Template.
  • Commits the changes and pushes them to the devices. Works fine.
  • Later, due to the auto-scaling all the devices from the device group and template are deleted, after which the user cannot commit to Panorama due to an invalid reference to the cert from Templates for the Decryption policy in DG (Device Group).

 

Cause

Cross-references between DG and template are based on common devices being present in both. If changes are made such that there are no common devices, then commit is expected to fail. At least one device needs to be common in both configs.

 

Workaround/Resolution

We recommend that you create a dummy device in the device group or always have a single firewall instance running, in order to avoid the commit error.

 

Owner: apasupulati



Attachments
Actions
  • Print
  • Copy Link

    https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClZHCA0&refURL=http%3A%2F%2Fknowledgebase.paloaltonetworks.com%2FKCSArticleDetail

Attachments
Choose Language