Palo Alto issues pushing config changes on Azure VM-FW after update
The End user updated their Palo Azure VM Firewalls on the weekend form 9.1.12 to 10.0.8-h8.
The update itself went through and every hardware Firewall is working fine.
However, they are currently unable to push config changes on VM-Firewalls in Azure.
There is always the following error message.
After checking UserID settings, and they are the same as on all other firewalls.
Solution: The issue got fixed by exporting the config -> Open Config -> Remove "user-id-agent" from the config -> Safe config as XML -> upload config.
Afterwards the commits were possible again!
How did this Happen?
Sounds like the configuration didn't migrate properly. Try just going into the 'User Identification' settings under the Device tab and opening up the 'User-ID Agents' tab and verifying that these settings look correct for your environment. Then go into each entry and just hit "OK". Sometimes that's enough to get the GUI to straighten things out for you without having to dive into the XML file. (solution explanation from B.Pry)