Unable to push changes to firewall from SCM. Getting Validation errors
333
Created On 10/10/25 01:42 AM - Last Modified 05/19/26 21:30 PM
Symptom
Getting validation errors while pushing from SCM to firewall. Check that there are multiple snippets listed below.
[info]: devices -> localhost.localdomain -> snippet -> AWS-VM-Dual-Arm-Default -> zone -> trust-zone -> network -> zone-protection-profile 'best-practice' is not a valid reference
[info]: devices -> localhost.localdomain -> snippet -> AWS-VM-Dual-Arm-Default -> zone -> trust-zone -> network -> zone-protection-profile is invalid
[info]: devices -> localhost.localdomain -> snippet -> GCP-VM-Default -> zone -> trust-zone -> network -> zone-protection-profile 'best-practice' is not a valid reference
[info]: devices -> localhost.localdomain -> snippet -> GCP-VM-Default -> zone -> trust-zone -> network -> zone-protection-profile is invalid
[info]: devices -> localhost.localdomain -> snippet -> Azure-VM-Default -> zone -> trust-zone -> network -> zone-protection-profile 'best-practice' is not a valid reference
[info]: devices -> localhost.localdomain -> snippet -> Azure-VM-Default -> zone -> trust-zone -> network -> zone-protection-profile is invalid
Environment
PA-450
SCM
Cause
This is occurring because the snippet containing the zone-protection-profile was not attached to the All folder.
Resolution
1. The duplicate uuid of the best-practice zone protection profile for AIRS-SLR-AWS-Default snippet was updated in the config and reloaded.
2. The above snippet was attached to the global folder
Additional Information
N/A