Troubleshoot Selective Push Blocked Scenarios
Focus
Focus
Panorama

Troubleshoot Selective Push Blocked Scenarios

Table of Contents

Troubleshoot Selective Push Blocked Scenarios

Identify and resolve conditions that block selective push on Panorama, requiring you to perform a full push.

Overview

Panorama blocks selective push and requires a full push when it detects conditions that could result in configuration inconsistencies on managed firewalls. When selective push is blocked, Panorama displays an error message indicating the reason and the required action. In most cases, you must perform a full push to all affected devices before you can resume selective push operations.
The following sections describe each blocking scenario and the steps to resolve the issue.

Selective Push Blocked on Passive Panorama

You attempted to perform a selective push from the passive Panorama in a high availability (HA) deployment. Selective push is supported only from the active Panorama peer.
Resolution: Log in to the active Panorama and perform the selective push from there.

Selective Push Blocked After Master Key Update

The master key on Panorama was updated. A master key change affects encryption of secrets across the configuration, which requires a full push to ensure all managed firewalls receive the complete updated configuration.
Resolution: Perform a full push (Push All Changes) to all managed firewalls before resuming selective push operations.

Selective Push Blocked After HA Failover

A Panorama HA failover occurred, and the new active peer cannot guarantee that all incremental configuration changes tracked for selective push are accurate. A full push is required to restore configuration consistency for the affected devices.
Resolution: Perform a full push to the devices listed in the error message. After the full push completes successfully, you can resume selective push operations.

Full Push Blocked on Passive Panorama

You attempted to perform a full push from the passive Panorama. Configuration pushes (both selective and full) are supported only on the active Panorama peer.
Resolution: Log in to the active Panorama and perform the full push from there.
If a full push is performed from the passive Panorama using the backdoor mechanism, Panorama generates system log messages on both the passive and active peers. The active Panorama then blocks selective push until a full push is performed from the active peer.

Selective Push Blocked Due to Config-Audit Range

The device group or template base configuration version on a managed firewall has fallen outside the config-audit range maintained by Panorama. The config-audit window specifies the number of configuration versions Panorama retains for auditing (default is 100). When the device's base version is older than the earliest version in the audit window, Panorama cannot compute the incremental changes needed for a selective push.
Resolution: Perform a full push to the affected devices. To prevent this from recurring, ensure that you push configuration changes regularly so that device versions remain within the config-audit window. You can also increase the config-audit window size if needed.

Selective Push Blocked Due to Device-Group or Template-Stack Association Change

A managed firewall's device-group or template-stack association was changed. When a device is moved between device groups or template stacks, a full push is required to ensure the device receives the complete configuration from its new association.
Resolution: Perform a full push to the affected devices after changing device-group or template-stack associations.

Selective Push Blocked Due to Device-Group or Template-Stack Hierarchy Change

The device-group or template-stack hierarchy was modified. This includes renaming, moving, adding, or removing device groups or template stacks from the hierarchy. Panorama cannot compute incremental changes when the structural relationships between configuration containers change.
Resolution: Perform a full push to all affected devices. After the hierarchy stabilizes and a full push completes, you can resume selective push operations.

Selective Push Blocked Due to Missing Anchor Rule or Unpushed Rule Move

A security rule operation (such as move, multi-move, or multi-clone) references an anchor rule that is either not found in the configuration to be pushed or has been moved by another administrator whose changes have not been pushed. Selective push cannot resolve the correct rule ordering without the anchor rule being in the expected position.
Resolution: Perform a full push. Before pushing, review the unpushed changes from other administrators listed in the error message. You may need to coordinate with those administrators to include their changes in the push, or perform a full push to ensure all rule positions are synchronized.

Push Failure Due to ReplayDB Update Error

Panorama encountered an internal error while updating the ReplayDB during the push operation. This is a transient error that does not indicate a permanent configuration issue.
Resolution: Retry the push operation. If the error persists after multiple attempts, generate a diagnostic file and contact Palo Alto Networks technical support for assistance.