Auto commit failing after enabling Advanced Routing Engine
2289
Created On 04/03/24 22:16 PM - Last Modified 07/15/24 21:09 PM
Symptom
- Advanced Routing Engine enabled on the firewall.
- Autocommit starts failing and starts looping. "show jobs processed" displays the issue.
> show jobs processed
Enqueued Dequeued ID PositionInQ Type Status Result Completed
------------------------------------------------------------------------------------------------------------------------------------------
2024/03/26 22:28:24 22:28:24 164 Exec ACT PEND 10%
2024/03/26 22:28:18 22:28:18 163 AutoCom ACT PEND 0%
2024/03/26 22:28:03 22:28:03 162 AutoCom FIN FAIL 22:28:16
2024/03/26 22:27:48 22:27:48 161 AutoCom FIN FAIL 22:28:01
- Configd logs (less mp-log configd.log) display validation failed message for routed.
2024-03-26 22:29:12.802 +0000 client routed reported error: Config validation failed for LR:CORP, refer logs for more info.(Module: routed)
- Viewing routed logs (less mp-log routed.log) shows issue with BGP router-id configuration.
2024-03-26 22:11:10,241 [91m ERROR[0m: vtysh failed to process new configuration: vtysh (mark file) exited with status 2:
b'line 91: % Unknown command: bgp router-id 10.129.254.225/32 \n\nEnvironment
- Palo Alto Firewalls
- PAN-OS 10.x and above
- AutoCommit
Cause
- The router-ID configured in the routing protocols contains the '/32' pattern in them.
- The special character of '/' is not processed correctly.
Resolution
- Remove the '/32' pattern from the BGP / OSPF Router ID configuration.
- Perform a commit force.
Additional Information
The upcoming release of software will resolve the issue as well.