Panorama Push to Firewall fails with error "tunnel.X has no virtual-router configured."

Panorama Push to Firewall fails with error "tunnel.X has no virtual-router configured."

400
Created On 01/28/26 23:54 PM - Last Modified 07/01/26 20:58 PM


Symptom


  • When attempting to commit the configuration from Panorama to a managed device, the commit fails with errors like the below:

 



Environment


  • Panorama
  • Palo Alto Networks Firewall
  • Any PAN-OS


Cause


  • This error commonly arises due to local configuration overrides on the managed firewalls or inconsistencies between the Panorama template and the firewall's running configuration.
  • Example: If the Virtual-Router is overridden on the local device from what is pushed from the Panorama template.



Resolution


  1. Remove the Local override configuration from the managed Firewall or merge it into a Panorama Template.
  2. If this is not possible, i.e Firewall requires a different configuration than other devices in the template, then a new template will need to be created for this particular device(s).

Note: One can also use the Force Template Values setting from Panorama during the Commit operation to resolve the issue, but be aware that this will revert all locally overridden template values and may not be desired!  Only use this method if you are sure that you want the Panorama template settings to override any locally configured values on all of the firewalls in the template.



Actions
  • Print
  • Copy Link

    https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA1Ki000000wkPrKAI&lang=en_US&refURL=http%3A%2F%2Fknowledgebase.paloaltonetworks.com%2FKCSArticleDetail