<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cannot connect VM series firewall to Panorama in AWS in VM-Series in the Public Cloud</title>
    <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/cannot-connect-vm-series-firewall-to-panorama-in-aws/m-p/515893#M1672</link>
    <description>&lt;P&gt;Downgrade device to 10.0.6 both is work for me. Thank&lt;/P&gt;</description>
    <pubDate>Sun, 25 Sep 2022 06:08:41 GMT</pubDate>
    <dc:creator>TPumtes</dc:creator>
    <dc:date>2022-09-25T06:08:41Z</dc:date>
    <item>
      <title>Cannot connect VM series firewall to Panorama in AWS</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/cannot-connect-vm-series-firewall-to-panorama-in-aws/m-p/430558#M1313</link>
      <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="fwlogs.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/35981iE75BCB9AA8AD68CD/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="fwlogs.png" alt="fwlogs.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="panlogs.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/35980i0BFCDE99E7657A6F/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="panlogs.png" alt="panlogs.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="broke.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/35979iC5119958C41B7784/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="broke.png" alt="broke.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We are trying to set up a new deployment in AWS consisting of two firewalls managed by a Panorama server.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For starters, we deployed one firewall and one Panorama instance. They are in the same VPC, different subnets. Security groups currently allow all TCP to/from the Panorama server and the firewall.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Both Panorama and the firewall have been licensed successfully and have a device certificate retrieved after generating an OTP.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;They are both on version 10.0.7.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The both have the predefined certificates specified under the secure communication settings&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So....after specifying the Panorama IP on the firewall, and attempting to add the firewall to Panorama, we see it still has a status of disconnected.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Looking in the system logs on the firewall shows a bunch of entries that basically follow the pattern "connected to Panorama Server", followed immediately by "Disconnected from Panorama Server"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;On the Panorama server, the pattern is "'Client authentication successful PAN-OS ver: 10.0.7 Panorama ver:10.0.7 Client IP: x.x.x.x Server IP: y.y.y.y Client CN: xxxxxxxxx", followed by "added bootstrapped device xxxxxxx to candidate configuration", followed by "xxxxxx connected", followed by "Device xxxxx disconnected from the server" all in rapid succession. That last event has "tls-session-disconnected" which makes me think maybe this is cert based (?)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Does anyone know what may cause this behavior? We are brand new to palo, so thinking it may very well be a layer 8 thing, just stumped as to what.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for the help!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;UPDATE: Looks like maybe this is a bug with 10.0.7///downgraded to 10.0.6 and it's connected now.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;UPDATE 2: This looks to maybe be a code bug...I downgraded both panorama and the FW to 10.0.6. and everything started to work.&lt;/P&gt;</description>
      <pubDate>Wed, 01 Sep 2021 15:10:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/cannot-connect-vm-series-firewall-to-panorama-in-aws/m-p/430558#M1313</guid>
      <dc:creator>JakeKremer</dc:creator>
      <dc:date>2021-09-01T15:10:10Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot connect VM series firewall to Panorama in AWS</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/cannot-connect-vm-series-firewall-to-panorama-in-aws/m-p/436589#M1344</link>
      <description>&lt;P&gt;Downgrade of devices only worked for me, Panorama is still at 10.0.7 and it works now.&lt;/P&gt;</description>
      <pubDate>Sat, 25 Sep 2021 18:27:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/cannot-connect-vm-series-firewall-to-panorama-in-aws/m-p/436589#M1344</guid>
      <dc:creator>DIRTT</dc:creator>
      <dc:date>2021-09-25T18:27:44Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot connect VM series firewall to Panorama in AWS</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/cannot-connect-vm-series-firewall-to-panorama-in-aws/m-p/515893#M1672</link>
      <description>&lt;P&gt;Downgrade device to 10.0.6 both is work for me. Thank&lt;/P&gt;</description>
      <pubDate>Sun, 25 Sep 2022 06:08:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/cannot-connect-vm-series-firewall-to-panorama-in-aws/m-p/515893#M1672</guid>
      <dc:creator>TPumtes</dc:creator>
      <dc:date>2022-09-25T06:08:41Z</dc:date>
    </item>
  </channel>
</rss>

