Troubleshoot Selective Push Blocked Scenarios
Identify and resolve conditions that block selective push on Panorama, requiring you
to perform a full push.
Overview
Panorama blocks selective push and requires a full push when it detects conditions
that could result in configuration inconsistencies on managed firewalls. When
selective push is blocked, Panorama displays an error message indicating the reason
and the required action. In most cases, you must perform a full push to all affected
devices before you can resume selective push operations.
The following sections describe each blocking scenario and the steps to resolve the
issue.
Selective Push Blocked on Passive Panorama
You attempted to perform a selective push from the passive Panorama in a high
availability (HA) deployment. Selective push is supported only from the active
Panorama peer.
Resolution: Log in to the active Panorama and perform the selective push from
there.
Selective Push Blocked After Master Key Update
The master key on Panorama was updated. A master key change affects encryption of
secrets across the configuration, which requires a full push to ensure all managed
firewalls receive the complete updated configuration.
Resolution: Perform a full push (Push All Changes) to
all managed firewalls before resuming selective push operations.
Selective Push Blocked After HA Failover
A Panorama HA failover occurred, and the new active peer cannot guarantee that all
incremental configuration changes tracked for selective push are accurate. A full
push is required to restore configuration consistency for the affected devices.
Resolution: Perform a full push to the devices listed in the error message.
After the full push completes successfully, you can resume selective push
operations.
Full Push Blocked on Passive Panorama
You attempted to perform a full push from the passive Panorama. Configuration pushes
(both selective and full) are supported only on the active Panorama peer.
Resolution: Log in to the active Panorama and perform the full push from
there.
If a full push is performed from the passive Panorama using the backdoor mechanism,
Panorama generates system log messages on both the passive and active peers. The
active Panorama then blocks selective push until a full push is performed from the
active peer.
Selective Push Blocked Due to Config-Audit Range
The device group or template base configuration version on a managed firewall has
fallen outside the config-audit range maintained by Panorama. The config-audit
window specifies the number of configuration versions Panorama retains for auditing
(default is 100). When the device's base version is older than the earliest version
in the audit window, Panorama cannot compute the incremental changes needed for a
selective push.
Resolution: Perform a full push to the affected devices. To prevent this from
recurring, ensure that you push configuration changes regularly so that device
versions remain within the config-audit window. You can also increase the
config-audit window size if needed.
Selective Push Blocked Due to Device-Group or Template-Stack Association
Change
A managed firewall's device-group or template-stack association was changed. When a
device is moved between device groups or template stacks, a full push is required to
ensure the device receives the complete configuration from its new association.
Resolution: Perform a full push to the affected devices after changing
device-group or template-stack associations.
Selective Push Blocked Due to Device-Group or Template-Stack Hierarchy
Change
The device-group or template-stack hierarchy was modified. This includes renaming,
moving, adding, or removing device groups or template stacks from the hierarchy.
Panorama cannot compute incremental changes when the structural relationships
between configuration containers change.
Resolution: Perform a full push to all affected devices. After the hierarchy
stabilizes and a full push completes, you can resume selective push operations.
Selective Push Blocked Due to Missing Anchor Rule or Unpushed Rule Move
A security rule operation (such as move, multi-move, or multi-clone) references an
anchor rule that is either not found in the configuration to be pushed or has been
moved by another administrator whose changes have not been pushed. Selective push
cannot resolve the correct rule ordering without the anchor rule being in the
expected position.
Resolution: Perform a full push. Before pushing, review the unpushed changes
from other administrators listed in the error message. You may need to coordinate
with those administrators to include their changes in the push, or perform a full
push to ensure all rule positions are synchronized.
Push Failure Due to ReplayDB Update Error
Panorama encountered an internal error while updating the ReplayDB during the push
operation. This is a transient error that does not indicate a permanent
configuration issue.
Resolution: Retry the push operation. If the error persists after multiple
attempts, generate a diagnostic file and contact Palo Alto Networks technical
support for assistance.