Panorama is unable to generate complete device state backup for Multi Vsys Firewalls
78
Created On 04/28/26 15:58 PM - Last Modified 09/02/26 22:15 PM
Symptom
- Backups generated via Panorama lack configuration data for all Virtual Systems.
- The exported file size is significantly smaller than expected.
- Standard backup procedures (KCS 000003995) do not yield a full configuration.
Environment
- Management: Panorama
- Device: Firewalls with Multi-Vsys mode active.
- Affected Versions: PAN-OS 11.1.6-hx
Cause
- The save device-state command fails to parse the XML structure of Multi-Vsys configurations.
- Current implementation only supports the XML positioning of the policy/vsys tag used in single-vsys devices.
Resolution
- Upgrade:
The permanent fix is currently targeted in these versions: 12.2.0, 12.1.8, 11.2.14, 11.1.17 - Workaround:
Generate the device state locally from the firewall for the entire configuration backup.