Firewall configuration being reverted when pushing config from Panorama

Firewall configuration being reverted when pushing config from Panorama

11373
Created On 10/02/20 23:04 PM - Last Modified 03/14/25 23:24 PM


Symptom




Environment


  • Panorama managed Firewalls
  • PAN-OS 9.1.0 or later
     


Cause


  • During config push from Panorama to firewall, one of below conditions is encountered.
  • Firewall temporarily loss connectivity to Panorama for more than 10 seconds.
  • There is a security policy that deny the existing connectivity between firewall and panorama (tcp/3978).
  • Firewall system log will have following relevant events.

    Time                Severity Subtype Object EventID ID Description
    ===============================================================================
    YYYY/MM/DD 16:29:59 info     general    general 0  Config installed
    YYYY/MM/DD 16:30:02 info     panoram    panoram 0  JobId=xx: Performing panorama connectivity check (attempt 1 of 1)
    YYYY/MM/DD 16:30:12 critical panoram    panoram 0  JobId=xx: Panorama connectivity check failed for xx.xx.xx.xx. Reason: TCP channel setup failed, reverting configuration


Resolution


Option 1:

  1. Disable "Enable automated commit recovery"
  2. Select Device > Setup > Management > Panorama Settings > Uncheck "Enable automated commit recovery"

Option 2:

  1. Increase "Number of attempts to check for Panorama connectivity" to prevent the "commit recovery" (being reverted back) too quickly if only temporary connectivity loss is expected between Firewall and Panorama
  2. Select Device > Setup > Management > Panorama Settings > Number of attempts to check for Panorama connectivity > Replace "1" (default) with higher number

     


Actions
  • Print
  • Copy Link

    https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u000000HB3CCAW&lang=en_US&refURL=http%3A%2F%2Fknowledgebase.paloaltonetworks.com%2FKCSArticleDetail

Choose Language