Panorama Commit Validation error about hip-profile running PAN-OS 9.1.x or 10.0.x

Panorama Commit Validation error about hip-profile running PAN-OS 9.1.x or 10.0.x

11773
Created On 08/12/21 21:51 PM - Last Modified 01/12/24 18:10 PM


Symptom


  • When attempting to commit/push Panorama getting validation error on config that was unchanged.
  • Commit errors are related to HIP Profiles
============================
Validation Error:
devices -> localhost.localdomain -> device-group -> User VPN -> profiles -> hip-profiles -> GPProfile-Hostchecker -> match '("GPProfile-OS-Check" or "GPProfile-AV-Check" ) 
and "GPProfile-Mobile-OS" ' is invalid. Invalid match criteria
devices -> localhost.localdomain -> device-group -> User VPN -> profiles -> hip-profiles -> GPProfile-Hostchecker -> match is invalid
devices -> localhost.localdomain -> device-group -> User LAN -> profiles -> hip-profiles -> GPProfile-AV-Check -> match 'not ("Traps" ) 
and "GPProfile-Mobile-OS" ' is invalid. Invalid match criteria
devices -> localhost.localdomain -> device-group -> User LAN -> profiles -> hip-profiles -> GPProfile-AV-Check -> match is invalid
devices -> localhost.localdomain -> device-group -> Admin VPN -> profiles -> hip-profiles -> GPProfile-NDIT Hostchecker -> match '("GPProfile-OS-Check" or "GPProfile-AV-Check" ) 
and "GPProfile-Mobile-OS" ' is invalid. Invalid match criteria
devices -> localhost.localdomain -> device-group -> Admin VPN -> profiles -> hip-profiles -> GPProfile-Hostchecker -> match is invalid
===============================
 


Environment


  • Panorama
  • PAN-OS 9.1.x, 10.0.x


Cause


This is caused by a software issue PAN-166306 fixed on PAN-OS 9.1.10, 10.0.6
 


Resolution


Upgrade to PAN-OS PAN-OS 9.1.10 or 10.0.6 or higher
or

Workarounds to resolve this issue:
Option 1:
  1. Restart the following processes:
debug software restart process configd 
debug software restart process management-server
  1. Add a test object
  2. Commit

Option 2:
2. If above doesn't work, then configure objects under 'shared' instead of under Device Group.


Additional Information


PAN-OS 10.0.6 Addressed Issues .

PAN-166306Fixed an issue where commit jobs failed when validating HIP objects and profiles.

  • Restarting the management server process usually doesn't impact packet forwarding, except for the fact that it will log out the administrator. It is always advisable to carry out any process restarts during off-peak hours or within a designated maintenance window.


Actions
  • Print
  • Copy Link

    https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u0000004LbvCAE&lang=en_US&refURL=http%3A%2F%2Fknowledgebase.paloaltonetworks.com%2FKCSArticleDetail

Choose Language