Panorama Commit Validation error about hip-profile running PAN-OS 9.1.x or 10.0.x
11773
Created On 08/12/21 21:51 PM - Last Modified 01/12/24 18:10 PM
Symptom
- When attempting to commit/push Panorama getting validation error on config that was unchanged.
- Commit errors are related to HIP Profiles
============================
Validation Error:
devices -> localhost.localdomain -> device-group -> User VPN -> profiles -> hip-profiles -> GPProfile-Hostchecker -> match '("GPProfile-OS-Check" or "GPProfile-AV-Check" )
and "GPProfile-Mobile-OS" ' is invalid. Invalid match criteria
devices -> localhost.localdomain -> device-group -> User VPN -> profiles -> hip-profiles -> GPProfile-Hostchecker -> match is invalid
devices -> localhost.localdomain -> device-group -> User LAN -> profiles -> hip-profiles -> GPProfile-AV-Check -> match 'not ("Traps" )
and "GPProfile-Mobile-OS" ' is invalid. Invalid match criteria
devices -> localhost.localdomain -> device-group -> User LAN -> profiles -> hip-profiles -> GPProfile-AV-Check -> match is invalid
devices -> localhost.localdomain -> device-group -> Admin VPN -> profiles -> hip-profiles -> GPProfile-NDIT Hostchecker -> match '("GPProfile-OS-Check" or "GPProfile-AV-Check" )
and "GPProfile-Mobile-OS" ' is invalid. Invalid match criteria
devices -> localhost.localdomain -> device-group -> Admin VPN -> profiles -> hip-profiles -> GPProfile-Hostchecker -> match is invalid
===============================
Environment
- Panorama
- PAN-OS 9.1.x, 10.0.x
Cause
This is caused by a software issue PAN-166306 fixed on PAN-OS 9.1.10, 10.0.6
Resolution
Upgrade to PAN-OS PAN-OS 9.1.10 or 10.0.6 or higher
or
Workarounds to resolve this issue:
Option 1:
- Restart the following processes:
debug software restart process configd debug software restart process management-server
- Add a test object
- Commit
Option 2:
2. If above doesn't work, then configure objects under 'shared' instead of under Device Group.
Additional Information
PAN-OS 10.0.6 Addressed Issues .
| PAN-166306 | Fixed an issue where commit jobs failed when validating HIP objects and profiles. |
- Restarting the management server process usually doesn't impact packet forwarding, except for the fact that it will log out the administrator. It is always advisable to carry out any process restarts during off-peak hours or within a designated maintenance window.