Panorama commit to the firewall failing due to error message: overlapping subnet subnet with address
416
Created On 03/11/25 10:34 AM - Last Modified 10/16/25 23:40 PM
Symptom
The Panorama commit and Push is failing due to following error message:
Autogenerated SDWAN configuration In router VR: address 10.255.255.252/32 on interface tunnel.901 has overlapping subnet with address 10.255.255.252/32 on interface loopback.901. (Module: routed)
client routed phase 1 failure
Commit failed
Environment
- NGFW managed using Panorama
- Secure SDWAN configured on the environment
- BGP enabled on the SDWAN plugin configuration
- Value of Loopback address configured under the BGP setting of SDWAN device falls with the subnet of VPN address pool of the SDWAN VPN cluster e.g. the BGP Loopback address is set to
10.255.255.252while the VPN address pool is set to10.255.255.0/24
Cause
The SDWAN BGP Loopback address setting on the Panorama creates a loopback interface with set address on the firewall; therefore assigning a value that falls within the VPN address pool subnet may cause conflict with SDWAN tunnel interface addresses on the firewall.
Resolution
- Goto Panorama > SD-WAN > Devices > Select the device where Commit is failing
- Change the value of Loopback address under the BGP tab; assign a value that does not fall within the subnet assigned for VPN address pool of cluster (value found under Panorama > SD-WAN > VPN Clusters)
- Commit and Push to device
Additional Information
https://docs.paloaltonetworks.com/sd-wan/2-1/sd-wan-admin/configure-sd-wan/create-a-vpn-cluster