|
(PA-5500 Series firewalls in cluster configurations only) When a
firewall node is removed from a PA-5500 Series cluster, after the
cluster commit and reboot, the node starts in standalone mode with a
default virtual wire (vwire) configuration loaded. This default
configuration is missing zone assignments for ports eth1/1 and
eth1/2, which causes commit operations to fail. Even if zones are
manually assigned to these ports, subsequent commit attempts fail
with a "no UUId for rule1" error.
Workaround: Manually assign zone configurations to ports
eth1/1 (for example, untrust) and eth1/2 (for example, trust), then
open and close security policy rule1 without making changes, and
commit. Alternatively, delete the default rule and the default
virtual wire Ethernet interfaces, then commit.
|