Plugin validation failure with errors 'domain-list unexpected here' & 'dns-servers is invalid' after plugin upgrade to 2.2

Plugin validation failure with errors 'domain-list unexpected here' & 'dns-servers is invalid' after plugin upgrade to 2.2

7801
Created On 04/05/22 02:44 AM - Last Modified 01/19/23 04:23 AM


Symptom


  • Panorama is managing Prisma Access and running Cloud service plugin 2.0 or 2.1
  • Cloud service plugin is upgraded to version 2.2
  • Now, the commit & validation on Panorama fails with the following errors. The failures are within the scope of Mobile user onboarding.
plugins -> cloud_services -> mobile-users -> onboarding -> company.gpcloudservice.com -> dns-servers -> worldwide -> domain-list unexpected here
plugins -> cloud_services -> mobile-users -> onboarding -> company.gpcloudservice.com -> dns-servers is invalid
Note: - No changes were made in the DNS configuration for Mobile users.


Environment


  • Panorama managing Prisma Access with Mobile users onboarded. 
  • Cloud service plugin 2.0 or above upgraded to version 2.2 preferred.


Cause


The error is due to incomplete migration of DNS specific configuration for mobile users from plugin earlier plugins to plugin 2.2
This issue can also show up if the correct plugin upgrade path  is not followed when upgrading to plugin 3.0 or above.
 


Resolution


  1. Upgrade the cloud service plugin to 2.2-h30 or above.
    1. If this step does not help, Proceed to the next steps.
  2. Edit the Panorama > Cloud services> Configuration > Mobile user > Edit onboarding >Network services
  3. Delete and reconfigure the DNS rules with the custom DNS and corresponding domain name list as applicable. 
  4. Perform another commit now which should be successful.
  5. If upgrading to plugin 3.0/3.1 or 3.2, follow the upgrade path from release notes. As a rule of thumb, each version of plugin upgrade needs to be done. For example, If upgrading from 2.1 to 3.2, Follow the path below.
           2.1 > 2.2 (latest hotfix) > 3.0 (latest hotfix) > 3.1 (latest hotfix) > 3.2  (latest hotfix)


Additional Information


  • Make sure there is a domain list when configuring a custom DNS server.
  • Downgrade of plugin can also help if a commit is urgent but Not recommended. 
  • Check the Panorama version and Cloud service plugin compatibility 

Prisma Access and Panorama Version Compatibility



Actions
  • Print
  • Copy Link

    https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u0000004NvxCAE&lang=en_US&refURL=http%3A%2F%2Fknowledgebase.paloaltonetworks.com%2FKCSArticleDetail

Choose Language