Panorama Push to Firewall Validation error: global-protect -> global-protect-gateway -> gp-gw -> remote-user-tunnel-configs -> gp-users -> split-tunneling -> access-route address-object is an invalid ipv4/v6 address
Symptom
Using an Address Object or Address Group Object inside the GlobalProtect configuration in Panorama.
Then, the following push to the firewall fails with a validation error:
Details:
. Validation Error:
. global-protect -> global-protect-gateway -> gp-gw -> remote-user-tunnel-configs -> gp-users -> split-tunneling -> access-route address-object is an invalid ipv4/v6 address
. global-protect -> global-protect-gateway -> gp-gw -> remote-user-tunnel-configs -> gp-users -> split-tunneling -> access-route 'address-object' is not a valid reference
. global-protect -> global-protect-gateway -> gp-gw -> remote-user-tunnel-configs -> gp-users -> split-tunneling -> access-route is invalid
. Invalid access-routes address-object in tunnel gp-gw-tunnel
. (Module: rasmgr)
. Parsing GlobalProtect gateway multi user configs failure
. (Module: rasmgr)
. client rasmgr phase 1 failure
. Commit failedEnvironment
- Panorama
- NGFW
- PAN-OS
Cause
The object exists in the Device Group configuration, but GlobalProtect is configured in the Templates.
Panorama does not push the Address Object to the firewall, because it is not used in the Device Group Policy.
During the validation, the Device Group does not check if the object is used by the GP configuration in the Templates.
During the validation, the GP configuration fails because the object does not exist because it was not pushed by Panorama.
If the object is not used in the policy, it is not sent to the firewall and the firewall cannot validate the GP configuration using that object.
Resolution
As a workaround, use one of the followings:
- Use the address object in the policy.
- Do not use an address object in the GP configuration, but rather use manual entries of IP addresses, or variables.
- Select the Panorama option to Push all the objects to the firewalls, including the non-used objects (this can create a limit issue on the firewalls).