Commit Validation Error Referring To Build-In EDL Objects "panw-highrisk-ip-list" & "panw-known-ip-list"

Commit Validation Error Referring To Build-In EDL Objects "panw-highrisk-ip-list" & "panw-known-ip-list"

37605
Created On 11/20/19 10:45 AM - Last Modified 07/30/21 17:13 PM


Symptom


  • Configuration validation error referring to build-in External Dynamic List [EDL] Objects "panw-highrisk-ip-list" & "panw-known-ip-list" during local firewall commit or while pushing configuration from Panorama to the managed firewalls.
  • CLI Output:
Validation Error:
rulebase -> security -> rules -> EDL-Test -> destination 'panw-highrisk-ip-list' is not an allowed keyword
rulebase -> security -> rules -> EDL-Test -> destination panw-highrisk-ip-list is an invalid ipv4/v6 address
rulebase -> security -> rules -> EDL-Test -> destination panw-highrisk-ip-list invalid range start IP
rulebase -> security -> rules -> EDL-Test -> destination 'panw-highrisk-ip-list' is not a valid reference
rulebase -> security -> rules -> EDL-Test -> destination 'panw-known-ip-list' is not an allowed keyword
rulebase -> security -> rules -> EDL-Test -> destination panw-known-ip-list is an invalid ipv4/v6 address
rulebase -> security -> rules -> EDL-Test -> destination panw-known-ip-list invalid range start IP
rulebase -> security -> rules -> EDL-Test -> destination 'panw-known-ip-list' is not a valid reference
rulebase -> security -> rules -> EDL-Test -> destination is invalid
  • WebUI Output: 
     User-added image
 


Environment


  • Firewalls [Hardware and VM]
  • Panorama 


Cause


  • "Panw-highrisk-ip-list" & "Panw-known-ip-list" are build-in External Dynamic List [EDL] Objects and this will appear on the firewall only when Dynamic Updates like "Applications and Threats" and "Antivirus" are installed on the firewall.


Resolution


Download and install below dynamic Updates on the firewall to resolve this issue.
  1. "Applications and Threats"   -    WebUI login >> Device >> Dynamic Updates >> Download & Install "Applications and Threats".
  2. "Antivirus"                            -    WebUI login >> Device >> Dynamic Updates >> Download & Install "Antivirus".


Actions
  • Print
  • Copy Link

    https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000PNZgCAO&refURL=http%3A%2F%2Fknowledgebase.paloaltonetworks.com%2FKCSArticleDetail

Choose Language