panorama_validate_ipsec_candidate_v2
Validate exact planned IPsec resources using plan ID and hash, then run full Panorama candidate validation without committing changes.
Instructions
[READ-ONLY] Validates the exact IPsec resources captured by a prior plan, using only plan_id and plan_hash, then runs a full Panorama candidate validation. The legacy spec-keyed validation tool remains available. Candidate configuration only; no commit or push is performed.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| plan_id | Yes | Plan id from panorama_plan_ipsec | |
| firewall | No | Target firewall name (from firewalls.json). Required when multiple firewalls are configured; optional otherwise. | |
| plan_hash | Yes | Plan hash from panorama_plan_ipsec |