|
Strata Cloud Manager Release 2026.r3.0
|
When you push a zone configuration from Strata Cloud Manager to
Panorama, the push does not complete if the zone's user-ACL
include-list references address objects or address groups defined
outside the Shared Device Group. Panorama validation rejects these
references because the zone's user-ACL only accepts addresses from
the vsys-specific or shared address space.
This is a PAN-OS limitation. Strata Cloud Manager cannot override
Panorama's address reference validation.
Workaround: Move the address objects and address groups referenced
in zone user-ACL include-lists to the Shared Device Group before
pushing the configuration to Panorama.
|