<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic AWS PAN-OS 11 Interfaces never become active in VM-Series in the Public Cloud</title>
    <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/aws-pan-os-11-interfaces-never-become-active/m-p/570777#M2067</link>
    <description>&lt;P&gt;I'm trying to bring up a new PAN-OS 11.1 instances in AWS, installed from&amp;nbsp;&lt;SPAN&gt;aws-marketplace/PA-VM-AWS-11.1.0-f1260463-68e1-4bfb-bf2e-075c2664c1d7. I am able to reach the management IP address, both SSH and the web UI are working. However the two intended network interfaces never appear in "show interface all" nor in the UI Network &amp;gt; Interfaces &amp;gt; Ethernet.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;I created three subnets within the VPC and three Elastic Network Interfaces, which are attached to the EC2 instance.&lt;/SPAN&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;SPAN&gt;The eni used for the management interface and for the WAN have Elastic IP addresses attached.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;The subnets for MGMT and LAN have a routing table with a default route pointing to the ENI.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;The subnet for the WAN has a routing table with a default route pointing to the Internet Gateway for the VPC.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;From the AWS EC2 instance tab:&lt;/SPAN&gt;&lt;/P&gt;
&lt;TABLE class="awsui_table_wih1l_1l1xk_144 awsui_table-layout-fixed_wih1l_1l1xk_150" role="table" width="1231px" aria-rowcount="-1"&gt;
&lt;THEAD class="awsui_thead-active_wih1l_1l1xk_300"&gt;
&lt;TR data-selection-item="all" aria-rowindex="1"&gt;
&lt;TH class="awsui_header-cell_1spae_1xghj_93" scope="col" width="153.078px"&gt;
&lt;DIV class="awsui_header-cell-content_1spae_1xghj_164" data-focus-id="sorting-control-networkInterfaceId"&gt;
&lt;DIV id="table-header-941-1703436063562-6789" class="awsui_header-cell-text_1spae_1xghj_225"&gt;Interface ID&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/TH&gt;
&lt;TH class="awsui_header-cell_1spae_1xghj_93" scope="col" width="101.617px"&gt;
&lt;DIV class="awsui_header-cell-content_1spae_1xghj_164" data-focus-id="sorting-control-description"&gt;
&lt;DIV id="table-header-943-1703436063562-7303" class="awsui_header-cell-text_1spae_1xghj_225"&gt;Description&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/TH&gt;
&lt;TH class="awsui_header-cell_1spae_1xghj_93" scope="col" width="40px"&gt;
&lt;DIV class="awsui_header-cell-content_1spae_1xghj_164" data-focus-id="sorting-control-ipv4Prefixes"&gt;
&lt;DIV id="table-header-945-1703436063563-4197" class="awsui_header-cell-text_1spae_1xghj_225"&gt;IPv4 Prefixes&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/TH&gt;
&lt;TH class="awsui_header-cell_1spae_1xghj_93" scope="col" width="40px"&gt;
&lt;DIV class="awsui_header-cell-content_1spae_1xghj_164" data-focus-id="sorting-control-ipv6Prefixes"&gt;
&lt;DIV id="table-header-947-1703436063563-6325" class="awsui_header-cell-text_1spae_1xghj_225"&gt;IPv6 Prefixes&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/TH&gt;
&lt;TH class="awsui_header-cell_1spae_1xghj_93" scope="col" width="93.8359px"&gt;
&lt;DIV class="awsui_header-cell-content_1spae_1xghj_164" data-focus-id="sorting-control-publicIP"&gt;
&lt;DIV id="table-header-949-1703436063563-1502" class="awsui_header-cell-text_1spae_1xghj_225"&gt;Public IPv4 address&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/TH&gt;
&lt;TH class="awsui_header-cell_1spae_1xghj_93" scope="col" width="104.414px"&gt;
&lt;DIV class="awsui_header-cell-content_1spae_1xghj_164" data-focus-id="sorting-control-PrivateIpv4"&gt;
&lt;DIV id="table-header-951-1703436063563-8643" class="awsui_header-cell-text_1spae_1xghj_225"&gt;Private IPv4 address&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/TH&gt;
&lt;TH class="awsui_header-cell_1spae_1xghj_93" scope="col" width="73.8359px"&gt;
&lt;DIV class="awsui_header-cell-content_1spae_1xghj_164" data-focus-id="sorting-control-attachmentStatus"&gt;
&lt;DIV id="table-header-963-1703436063563-6539" class="awsui_header-cell-text_1spae_1xghj_225"&gt;Attachment status&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/TH&gt;
&lt;TH class="awsui_header-cell_1spae_1xghj_93" scope="col" width="159.305px"&gt;
&lt;DIV class="awsui_header-cell-content_1spae_1xghj_164" data-focus-id="sorting-control-vpcID"&gt;
&lt;DIV id="table-header-965-1703436063563-9221" class="awsui_header-cell-text_1spae_1xghj_225"&gt;VPC ID&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/TH&gt;
&lt;TH class="awsui_header-cell_1spae_1xghj_93" scope="col" width="162.164px"&gt;
&lt;DIV class="awsui_header-cell-content_1spae_1xghj_164" data-focus-id="sorting-control-subnetID"&gt;
&lt;DIV id="table-header-967-1703436063563-8645" class="awsui_header-cell-text_1spae_1xghj_225"&gt;Subnet ID&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/TH&gt;
&lt;TH class="awsui_header-cell_1spae_1xghj_93" scope="col" width="71.7578px"&gt;
&lt;DIV class="awsui_header-cell-content_1spae_1xghj_164" data-focus-id="sorting-control-sourceDestCheck"&gt;
&lt;DIV id="table-header-971-1703436063563-9620" class="awsui_header-cell-text_1spae_1xghj_225"&gt;Source / destination check&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/TH&gt;
&lt;TH class="awsui_header-cell_1spae_1xghj_93" scope="col" width="157.039px"&gt;
&lt;DIV class="awsui_header-cell-content_1spae_1xghj_164" data-focus-id="sorting-control-securityGroups"&gt;
&lt;DIV id="table-header-973-1703436063563-7999" class="awsui_header-cell-text_1spae_1xghj_225"&gt;Security groups&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/TH&gt;
&lt;TH class="awsui_header-cell_1spae_1xghj_93" scope="col" width="72.9531px"&gt;
&lt;DIV class="awsui_header-cell-content_1spae_1xghj_164" data-focus-id="sorting-control-interfaceType"&gt;
&lt;DIV id="table-header-975-1703436063563-4161" class="awsui_header-cell-text_1spae_1xghj_225"&gt;Interface type&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/TH&gt;
&lt;/TR&gt;
&lt;/THEAD&gt;
&lt;TBODY&gt;
&lt;TR class="awsui_row_wih1l_1l1xk_301" data-selection-item="item"&gt;
&lt;TD width="153.078px" class="awsui_body-cell_c6tup_6wa2x_93 awsui_body-cell-first-row_c6tup_6wa2x_145"&gt;
&lt;DIV class="awsui_text-content_6absk_12mq6_94"&gt;eni-09c...&lt;/DIV&gt;
&lt;/TD&gt;
&lt;TD width="101.617px" class="awsui_body-cell_c6tup_6wa2x_93 awsui_body-cell-first-row_c6tup_6wa2x_145"&gt;MGMT&lt;/TD&gt;
&lt;TD width="40px" class="awsui_body-cell_c6tup_6wa2x_93 awsui_body-cell-first-row_c6tup_6wa2x_145"&gt;–&lt;/TD&gt;
&lt;TD width="40px" class="awsui_body-cell_c6tup_6wa2x_93 awsui_body-cell-first-row_c6tup_6wa2x_145"&gt;–&lt;/TD&gt;
&lt;TD width="93.8359px" class="awsui_body-cell_c6tup_6wa2x_93 awsui_body-cell-first-row_c6tup_6wa2x_145"&gt;52.25.x.y&lt;/TD&gt;
&lt;TD width="104.414px" class="awsui_body-cell_c6tup_6wa2x_93 awsui_body-cell-first-row_c6tup_6wa2x_145"&gt;10.0.6.71&lt;/TD&gt;
&lt;TD width="73.8359px" class="awsui_body-cell_c6tup_6wa2x_93 awsui_body-cell-first-row_c6tup_6wa2x_145"&gt;attached&lt;/TD&gt;
&lt;TD width="159.305px" class="awsui_body-cell_c6tup_6wa2x_93 awsui_body-cell-first-row_c6tup_6wa2x_145"&gt;
&lt;DIV class="awsui_text-content_6absk_12mq6_94"&gt;vpc-0d2...b90&lt;/DIV&gt;
&lt;/TD&gt;
&lt;TD width="162.164px" class="awsui_body-cell_c6tup_6wa2x_93 awsui_body-cell-first-row_c6tup_6wa2x_145"&gt;
&lt;DIV class="awsui_text-content_6absk_12mq6_94"&gt;subnet-036...&lt;/DIV&gt;
&lt;/TD&gt;
&lt;TD width="71.7578px" class="awsui_body-cell_c6tup_6wa2x_93 awsui_body-cell-first-row_c6tup_6wa2x_145"&gt;enabled&lt;/TD&gt;
&lt;TD width="157.039px" class="awsui_body-cell_c6tup_6wa2x_93 awsui_body-cell-first-row_c6tup_6wa2x_145"&gt;
&lt;DIV class="awsui_text-content_6absk_12mq6_94"&gt;sg-093...&lt;/DIV&gt;
&lt;/TD&gt;
&lt;TD width="72.9531px" class="awsui_body-cell_c6tup_6wa2x_93 awsui_body-cell-first-row_c6tup_6wa2x_145"&gt;Elastic network interface&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR class="awsui_row_wih1l_1l1xk_301" data-selection-item="item"&gt;
&lt;TD width="153.078px" class="awsui_body-cell_c6tup_6wa2x_93"&gt;
&lt;DIV class="awsui_text-content_6absk_12mq6_94"&gt;eni-062...&lt;/DIV&gt;
&lt;/TD&gt;
&lt;TD width="101.617px" class="awsui_body-cell_c6tup_6wa2x_93"&gt;WAN&lt;/TD&gt;
&lt;TD width="40px" class="awsui_body-cell_c6tup_6wa2x_93"&gt;–&lt;/TD&gt;
&lt;TD width="40px" class="awsui_body-cell_c6tup_6wa2x_93"&gt;–&lt;/TD&gt;
&lt;TD width="93.8359px" class="awsui_body-cell_c6tup_6wa2x_93"&gt;35.82.x.y&lt;/TD&gt;
&lt;TD width="104.414px" class="awsui_body-cell_c6tup_6wa2x_93"&gt;10.0.64.130&lt;/TD&gt;
&lt;TD width="73.8359px" class="awsui_body-cell_c6tup_6wa2x_93"&gt;attached&lt;/TD&gt;
&lt;TD width="159.305px" class="awsui_body-cell_c6tup_6wa2x_93"&gt;
&lt;DIV class="awsui_text-content_6absk_12mq6_94"&gt;vpc-0d2...b90&lt;/DIV&gt;
&lt;/TD&gt;
&lt;TD width="162.164px" class="awsui_body-cell_c6tup_6wa2x_93"&gt;
&lt;DIV class="awsui_text-content_6absk_12mq6_94"&gt;subnet-025...&lt;/DIV&gt;
&lt;/TD&gt;
&lt;TD width="71.7578px" class="awsui_body-cell_c6tup_6wa2x_93"&gt;disabled&lt;/TD&gt;
&lt;TD width="157.039px" class="awsui_body-cell_c6tup_6wa2x_93"&gt;
&lt;DIV class="awsui_text-content_6absk_12mq6_94"&gt;sg-083...&lt;/DIV&gt;
&lt;/TD&gt;
&lt;TD width="72.9531px" class="awsui_body-cell_c6tup_6wa2x_93"&gt;Elastic network interface&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR class="awsui_row_wih1l_1l1xk_301" data-selection-item="item"&gt;
&lt;TD width="153.078px" class="awsui_body-cell_c6tup_6wa2x_93 awsui_body-cell-last-row_c6tup_6wa2x_148"&gt;
&lt;DIV class="awsui_text-content_6absk_12mq6_94"&gt;eni-06b...&lt;/DIV&gt;
&lt;/TD&gt;
&lt;TD width="101.617px" class="awsui_body-cell_c6tup_6wa2x_93 awsui_body-cell-last-row_c6tup_6wa2x_148"&gt;LAN&lt;/TD&gt;
&lt;TD width="40px" class="awsui_body-cell_c6tup_6wa2x_93 awsui_body-cell-last-row_c6tup_6wa2x_148"&gt;–&lt;/TD&gt;
&lt;TD width="40px" class="awsui_body-cell_c6tup_6wa2x_93 awsui_body-cell-last-row_c6tup_6wa2x_148"&gt;–&lt;/TD&gt;
&lt;TD width="93.8359px" class="awsui_body-cell_c6tup_6wa2x_93 awsui_body-cell-last-row_c6tup_6wa2x_148"&gt;–&lt;/TD&gt;
&lt;TD width="104.414px" class="awsui_body-cell_c6tup_6wa2x_93 awsui_body-cell-last-row_c6tup_6wa2x_148"&gt;10.0.137.103&lt;/TD&gt;
&lt;TD width="73.8359px" class="awsui_body-cell_c6tup_6wa2x_93 awsui_body-cell-last-row_c6tup_6wa2x_148"&gt;attached&lt;/TD&gt;
&lt;TD width="159.305px" class="awsui_body-cell_c6tup_6wa2x_93 awsui_body-cell-last-row_c6tup_6wa2x_148"&gt;
&lt;DIV class="awsui_text-content_6absk_12mq6_94"&gt;vpc-0d2...b90&lt;/DIV&gt;
&lt;/TD&gt;
&lt;TD width="162.164px" class="awsui_body-cell_c6tup_6wa2x_93 awsui_body-cell-last-row_c6tup_6wa2x_148"&gt;
&lt;DIV class="awsui_text-content_6absk_12mq6_94"&gt;subnet-03c...&lt;/DIV&gt;
&lt;/TD&gt;
&lt;TD width="71.7578px" class="awsui_body-cell_c6tup_6wa2x_93 awsui_body-cell-last-row_c6tup_6wa2x_148"&gt;disabled&lt;/TD&gt;
&lt;TD width="157.039px" class="awsui_body-cell_c6tup_6wa2x_93 awsui_body-cell-last-row_c6tup_6wa2x_148"&gt;
&lt;DIV class="awsui_text-content_6absk_12mq6_94"&gt;sg-07f...&lt;/DIV&gt;
&lt;/TD&gt;
&lt;TD width="72.9531px" class="awsui_body-cell_c6tup_6wa2x_93 awsui_body-cell-last-row_c6tup_6wa2x_148"&gt;Elastic network interface&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;P&gt;&lt;BR /&gt;--------&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;In "show system state" I see the MAC addresses of the Elastic Network Interfaces I expect. sys.s1.p1.hwaddr is the MAC address of&amp;nbsp;eni-062... intended for the WAN, and&amp;nbsp;sys.s1.p2.hwaddr is the MAC address of&amp;nbsp;eni-06b... intended for the LAN.&lt;/P&gt;
&lt;PRE&gt;admin@PA-VM&amp;gt; show system state&lt;BR /&gt;…&lt;BR /&gt;sys.s1.p1.bus: 0000:00:06.0&lt;BR /&gt;sys.s1.p1.capability: [ auto, 10Mb/s-half, 10Mb/s-full, 100Mb/s-half, 100Mb/s-full, 1Gb/s-half, 1Gb/s-full, 10Gb/s-half, 10Gb/s-full, 25Gb/s-half, 25Gb/s-full, 40Gb/s-half, 40Gb/s-full, 100Gb/s-half, 100Gb/s-full, ]&lt;BR /&gt;sys.s1.p1.cfg: { 'breakout': False, 'fec': 0, 'mode': Disabled, 'pause-frames': True, 'setting': auto, }&lt;BR /&gt;sys.s1.p1.detail: { }&lt;BR /&gt;sys.s1.p1.driver: net_ena&lt;BR /&gt;sys.s1.p1.eni:&lt;BR /&gt;sys.s1.p1.hwaddr: 06:71:1a:54:54:9d&lt;BR /&gt;sys.s1.p1.mtu: 1504&lt;BR /&gt;sys.s1.p1.phy: { 'link-partner': { }, 'media': CAT5, 'type': Ethernet, }&lt;BR /&gt;sys.s1.p1.rate: { 'duration': 28560, 'last-sample': 2023-12-23 22:18:40, 'rx-broadcast': 0, 'rx-bytes': 0, 'rx-multicast': 0, 'rx-unicast': 0, 'tx-broadcast': 0, 'tx-bytes': 0, 'tx-multicast': 0, 'tx-unicast': 0, }&lt;BR /&gt;sys.s1.p1.state: board_port_autoneg&lt;BR /&gt;sys.s1.p1.stats: { 'link-down': 0, 'rx-broadcast': 0, 'rx-bytes': 22824, 'rx-discards': 0, 'rx-error': 0, 'rx-missed-error': 0, 'rx-multicast': 0, 'rx-unicast': 523, 'tx-broadcast': 0, 'tx-bytes': 0, 'tx-error': 0, 'tx-multicast': 0, 'tx-unicast': 0, }&lt;BR /&gt;sys.s1.p1.status: { 'link': Down, 'mode': Disabled, 'pause-frames': True, 'setting': Unknown, 'type': RJ45, }&lt;BR /&gt;…&lt;BR /&gt;sys.s1.p2.bus: 0000:00:07.0&lt;BR /&gt;sys.s1.p2.capability: [ auto, 10Mb/s-half, 10Mb/s-full, 100Mb/s-half, 100Mb/s-full, 1Gb/s-half, 1Gb/s-full, 10Gb/s-half, 10Gb/s-full, 25Gb/s-half, 25Gb/s-full, 40Gb/s-half, 40Gb/s-full, 100Gb/s-half, 100Gb/s-full, ]&lt;BR /&gt;sys.s1.p2.cfg: { 'breakout': False, 'fec': 0, 'mode': Disabled, 'pause-frames': True, 'setting': auto, }&lt;BR /&gt;sys.s1.p2.detail: { }&lt;BR /&gt;sys.s1.p2.driver: net_ena&lt;BR /&gt;sys.s1.p2.eni:&lt;BR /&gt;sys.s1.p2.hwaddr: 06:62:fb:e5:5e:9f&lt;BR /&gt;sys.s1.p2.mtu: 1504&lt;BR /&gt;sys.s1.p2.phy: { 'link-partner': { }, 'media': CAT5, 'type': Ethernet, }&lt;BR /&gt;sys.s1.p2.rate: { 'duration': 28560, 'last-sample': 2023-12-23 22:18:40, 'rx-broadcast': 0, 'rx-bytes': 0, 'rx-multicast': 0, 'rx-unicast': 0, 'tx-broadcast': 0, 'tx-bytes': 0, 'tx-multicast': 0, 'tx-unicast': 0, }&lt;BR /&gt;sys.s1.p2.state: board_port_autoneg&lt;BR /&gt;sys.s1.p2.stats: { 'link-down': 0, 'rx-broadcast': 0, 'rx-bytes': 21252, 'rx-discards': 0, 'rx-error': 0, 'rx-missed-error': 0, 'rx-multicast': 0, 'rx-unicast': 506, 'tx-broadcast': 0, 'tx-bytes': 0, 'tx-error': 0, 'tx-multicast': 0, 'tx-unicast': 0, }&lt;BR /&gt;sys.s1.p2.status: { 'link': Down, 'mode': Disabled, 'pause-frames': True, 'setting': Unknown, 'type': RJ45, }&lt;/PRE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;However no interfaces appear in "show interface all" and the Web UI never shows their status as green.&lt;/P&gt;
&lt;PRE&gt;admin@PA-VM&amp;gt; show interface all&lt;BR /&gt;&lt;BR /&gt;total configured hardware interfaces: 0&lt;BR /&gt;&lt;BR /&gt;name id speed/duplex/state mac address&lt;BR /&gt;--------------------------------------------------------------------------------&lt;BR /&gt;&lt;BR /&gt;aggregation groups: 0&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;total configured logical interfaces: 0&lt;BR /&gt;&lt;BR /&gt;name id vsys zone forwarding tag address&lt;BR /&gt;------------------- ----- ---- ---------------- ------------------------ ------ ------------------&lt;/PRE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;--------&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In other posts I've read that this means the interface is not configured. I set the interface type of the first two Ethernet interfaces to Layer3, created a management profile which allows ICMP ping, and set their IP address to use DHCP.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The ENI which I'm intending as the WAN interface has a public IPv4 Elastic IP address associated with it, which I would expect means AWS should respond to a DHCP request for that interface at least.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2023-12-24 at 9.01.21 AM.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/56087i415A17FF01AB81E9/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Screenshot 2023-12-24 at 9.01.21 AM.png" alt="Screenshot 2023-12-24 at 9.01.21 AM.png" /&gt;&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;--------&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I've rebooted the EC2 instance multiple times, including going all the way to Stopping the instance and then Starting it again to ensure any new device tree will be properly handled at boot.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'm running out of ideas of what to try. What else could be preventing PAN from seeing these links as configured and active?&lt;/P&gt;</description>
    <pubDate>Sun, 24 Dec 2023 17:07:52 GMT</pubDate>
    <dc:creator>DGentry</dc:creator>
    <dc:date>2023-12-24T17:07:52Z</dc:date>
    <item>
      <title>AWS PAN-OS 11 Interfaces never become active</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/aws-pan-os-11-interfaces-never-become-active/m-p/570777#M2067</link>
      <description>&lt;P&gt;I'm trying to bring up a new PAN-OS 11.1 instances in AWS, installed from&amp;nbsp;&lt;SPAN&gt;aws-marketplace/PA-VM-AWS-11.1.0-f1260463-68e1-4bfb-bf2e-075c2664c1d7. I am able to reach the management IP address, both SSH and the web UI are working. However the two intended network interfaces never appear in "show interface all" nor in the UI Network &amp;gt; Interfaces &amp;gt; Ethernet.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;I created three subnets within the VPC and three Elastic Network Interfaces, which are attached to the EC2 instance.&lt;/SPAN&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;SPAN&gt;The eni used for the management interface and for the WAN have Elastic IP addresses attached.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;The subnets for MGMT and LAN have a routing table with a default route pointing to the ENI.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;The subnet for the WAN has a routing table with a default route pointing to the Internet Gateway for the VPC.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;From the AWS EC2 instance tab:&lt;/SPAN&gt;&lt;/P&gt;
&lt;TABLE class="awsui_table_wih1l_1l1xk_144 awsui_table-layout-fixed_wih1l_1l1xk_150" role="table" width="1231px" aria-rowcount="-1"&gt;
&lt;THEAD class="awsui_thead-active_wih1l_1l1xk_300"&gt;
&lt;TR data-selection-item="all" aria-rowindex="1"&gt;
&lt;TH class="awsui_header-cell_1spae_1xghj_93" scope="col" width="153.078px"&gt;
&lt;DIV class="awsui_header-cell-content_1spae_1xghj_164" data-focus-id="sorting-control-networkInterfaceId"&gt;
&lt;DIV id="table-header-941-1703436063562-6789" class="awsui_header-cell-text_1spae_1xghj_225"&gt;Interface ID&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/TH&gt;
&lt;TH class="awsui_header-cell_1spae_1xghj_93" scope="col" width="101.617px"&gt;
&lt;DIV class="awsui_header-cell-content_1spae_1xghj_164" data-focus-id="sorting-control-description"&gt;
&lt;DIV id="table-header-943-1703436063562-7303" class="awsui_header-cell-text_1spae_1xghj_225"&gt;Description&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/TH&gt;
&lt;TH class="awsui_header-cell_1spae_1xghj_93" scope="col" width="40px"&gt;
&lt;DIV class="awsui_header-cell-content_1spae_1xghj_164" data-focus-id="sorting-control-ipv4Prefixes"&gt;
&lt;DIV id="table-header-945-1703436063563-4197" class="awsui_header-cell-text_1spae_1xghj_225"&gt;IPv4 Prefixes&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/TH&gt;
&lt;TH class="awsui_header-cell_1spae_1xghj_93" scope="col" width="40px"&gt;
&lt;DIV class="awsui_header-cell-content_1spae_1xghj_164" data-focus-id="sorting-control-ipv6Prefixes"&gt;
&lt;DIV id="table-header-947-1703436063563-6325" class="awsui_header-cell-text_1spae_1xghj_225"&gt;IPv6 Prefixes&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/TH&gt;
&lt;TH class="awsui_header-cell_1spae_1xghj_93" scope="col" width="93.8359px"&gt;
&lt;DIV class="awsui_header-cell-content_1spae_1xghj_164" data-focus-id="sorting-control-publicIP"&gt;
&lt;DIV id="table-header-949-1703436063563-1502" class="awsui_header-cell-text_1spae_1xghj_225"&gt;Public IPv4 address&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/TH&gt;
&lt;TH class="awsui_header-cell_1spae_1xghj_93" scope="col" width="104.414px"&gt;
&lt;DIV class="awsui_header-cell-content_1spae_1xghj_164" data-focus-id="sorting-control-PrivateIpv4"&gt;
&lt;DIV id="table-header-951-1703436063563-8643" class="awsui_header-cell-text_1spae_1xghj_225"&gt;Private IPv4 address&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/TH&gt;
&lt;TH class="awsui_header-cell_1spae_1xghj_93" scope="col" width="73.8359px"&gt;
&lt;DIV class="awsui_header-cell-content_1spae_1xghj_164" data-focus-id="sorting-control-attachmentStatus"&gt;
&lt;DIV id="table-header-963-1703436063563-6539" class="awsui_header-cell-text_1spae_1xghj_225"&gt;Attachment status&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/TH&gt;
&lt;TH class="awsui_header-cell_1spae_1xghj_93" scope="col" width="159.305px"&gt;
&lt;DIV class="awsui_header-cell-content_1spae_1xghj_164" data-focus-id="sorting-control-vpcID"&gt;
&lt;DIV id="table-header-965-1703436063563-9221" class="awsui_header-cell-text_1spae_1xghj_225"&gt;VPC ID&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/TH&gt;
&lt;TH class="awsui_header-cell_1spae_1xghj_93" scope="col" width="162.164px"&gt;
&lt;DIV class="awsui_header-cell-content_1spae_1xghj_164" data-focus-id="sorting-control-subnetID"&gt;
&lt;DIV id="table-header-967-1703436063563-8645" class="awsui_header-cell-text_1spae_1xghj_225"&gt;Subnet ID&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/TH&gt;
&lt;TH class="awsui_header-cell_1spae_1xghj_93" scope="col" width="71.7578px"&gt;
&lt;DIV class="awsui_header-cell-content_1spae_1xghj_164" data-focus-id="sorting-control-sourceDestCheck"&gt;
&lt;DIV id="table-header-971-1703436063563-9620" class="awsui_header-cell-text_1spae_1xghj_225"&gt;Source / destination check&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/TH&gt;
&lt;TH class="awsui_header-cell_1spae_1xghj_93" scope="col" width="157.039px"&gt;
&lt;DIV class="awsui_header-cell-content_1spae_1xghj_164" data-focus-id="sorting-control-securityGroups"&gt;
&lt;DIV id="table-header-973-1703436063563-7999" class="awsui_header-cell-text_1spae_1xghj_225"&gt;Security groups&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/TH&gt;
&lt;TH class="awsui_header-cell_1spae_1xghj_93" scope="col" width="72.9531px"&gt;
&lt;DIV class="awsui_header-cell-content_1spae_1xghj_164" data-focus-id="sorting-control-interfaceType"&gt;
&lt;DIV id="table-header-975-1703436063563-4161" class="awsui_header-cell-text_1spae_1xghj_225"&gt;Interface type&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/TH&gt;
&lt;/TR&gt;
&lt;/THEAD&gt;
&lt;TBODY&gt;
&lt;TR class="awsui_row_wih1l_1l1xk_301" data-selection-item="item"&gt;
&lt;TD width="153.078px" class="awsui_body-cell_c6tup_6wa2x_93 awsui_body-cell-first-row_c6tup_6wa2x_145"&gt;
&lt;DIV class="awsui_text-content_6absk_12mq6_94"&gt;eni-09c...&lt;/DIV&gt;
&lt;/TD&gt;
&lt;TD width="101.617px" class="awsui_body-cell_c6tup_6wa2x_93 awsui_body-cell-first-row_c6tup_6wa2x_145"&gt;MGMT&lt;/TD&gt;
&lt;TD width="40px" class="awsui_body-cell_c6tup_6wa2x_93 awsui_body-cell-first-row_c6tup_6wa2x_145"&gt;–&lt;/TD&gt;
&lt;TD width="40px" class="awsui_body-cell_c6tup_6wa2x_93 awsui_body-cell-first-row_c6tup_6wa2x_145"&gt;–&lt;/TD&gt;
&lt;TD width="93.8359px" class="awsui_body-cell_c6tup_6wa2x_93 awsui_body-cell-first-row_c6tup_6wa2x_145"&gt;52.25.x.y&lt;/TD&gt;
&lt;TD width="104.414px" class="awsui_body-cell_c6tup_6wa2x_93 awsui_body-cell-first-row_c6tup_6wa2x_145"&gt;10.0.6.71&lt;/TD&gt;
&lt;TD width="73.8359px" class="awsui_body-cell_c6tup_6wa2x_93 awsui_body-cell-first-row_c6tup_6wa2x_145"&gt;attached&lt;/TD&gt;
&lt;TD width="159.305px" class="awsui_body-cell_c6tup_6wa2x_93 awsui_body-cell-first-row_c6tup_6wa2x_145"&gt;
&lt;DIV class="awsui_text-content_6absk_12mq6_94"&gt;vpc-0d2...b90&lt;/DIV&gt;
&lt;/TD&gt;
&lt;TD width="162.164px" class="awsui_body-cell_c6tup_6wa2x_93 awsui_body-cell-first-row_c6tup_6wa2x_145"&gt;
&lt;DIV class="awsui_text-content_6absk_12mq6_94"&gt;subnet-036...&lt;/DIV&gt;
&lt;/TD&gt;
&lt;TD width="71.7578px" class="awsui_body-cell_c6tup_6wa2x_93 awsui_body-cell-first-row_c6tup_6wa2x_145"&gt;enabled&lt;/TD&gt;
&lt;TD width="157.039px" class="awsui_body-cell_c6tup_6wa2x_93 awsui_body-cell-first-row_c6tup_6wa2x_145"&gt;
&lt;DIV class="awsui_text-content_6absk_12mq6_94"&gt;sg-093...&lt;/DIV&gt;
&lt;/TD&gt;
&lt;TD width="72.9531px" class="awsui_body-cell_c6tup_6wa2x_93 awsui_body-cell-first-row_c6tup_6wa2x_145"&gt;Elastic network interface&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR class="awsui_row_wih1l_1l1xk_301" data-selection-item="item"&gt;
&lt;TD width="153.078px" class="awsui_body-cell_c6tup_6wa2x_93"&gt;
&lt;DIV class="awsui_text-content_6absk_12mq6_94"&gt;eni-062...&lt;/DIV&gt;
&lt;/TD&gt;
&lt;TD width="101.617px" class="awsui_body-cell_c6tup_6wa2x_93"&gt;WAN&lt;/TD&gt;
&lt;TD width="40px" class="awsui_body-cell_c6tup_6wa2x_93"&gt;–&lt;/TD&gt;
&lt;TD width="40px" class="awsui_body-cell_c6tup_6wa2x_93"&gt;–&lt;/TD&gt;
&lt;TD width="93.8359px" class="awsui_body-cell_c6tup_6wa2x_93"&gt;35.82.x.y&lt;/TD&gt;
&lt;TD width="104.414px" class="awsui_body-cell_c6tup_6wa2x_93"&gt;10.0.64.130&lt;/TD&gt;
&lt;TD width="73.8359px" class="awsui_body-cell_c6tup_6wa2x_93"&gt;attached&lt;/TD&gt;
&lt;TD width="159.305px" class="awsui_body-cell_c6tup_6wa2x_93"&gt;
&lt;DIV class="awsui_text-content_6absk_12mq6_94"&gt;vpc-0d2...b90&lt;/DIV&gt;
&lt;/TD&gt;
&lt;TD width="162.164px" class="awsui_body-cell_c6tup_6wa2x_93"&gt;
&lt;DIV class="awsui_text-content_6absk_12mq6_94"&gt;subnet-025...&lt;/DIV&gt;
&lt;/TD&gt;
&lt;TD width="71.7578px" class="awsui_body-cell_c6tup_6wa2x_93"&gt;disabled&lt;/TD&gt;
&lt;TD width="157.039px" class="awsui_body-cell_c6tup_6wa2x_93"&gt;
&lt;DIV class="awsui_text-content_6absk_12mq6_94"&gt;sg-083...&lt;/DIV&gt;
&lt;/TD&gt;
&lt;TD width="72.9531px" class="awsui_body-cell_c6tup_6wa2x_93"&gt;Elastic network interface&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR class="awsui_row_wih1l_1l1xk_301" data-selection-item="item"&gt;
&lt;TD width="153.078px" class="awsui_body-cell_c6tup_6wa2x_93 awsui_body-cell-last-row_c6tup_6wa2x_148"&gt;
&lt;DIV class="awsui_text-content_6absk_12mq6_94"&gt;eni-06b...&lt;/DIV&gt;
&lt;/TD&gt;
&lt;TD width="101.617px" class="awsui_body-cell_c6tup_6wa2x_93 awsui_body-cell-last-row_c6tup_6wa2x_148"&gt;LAN&lt;/TD&gt;
&lt;TD width="40px" class="awsui_body-cell_c6tup_6wa2x_93 awsui_body-cell-last-row_c6tup_6wa2x_148"&gt;–&lt;/TD&gt;
&lt;TD width="40px" class="awsui_body-cell_c6tup_6wa2x_93 awsui_body-cell-last-row_c6tup_6wa2x_148"&gt;–&lt;/TD&gt;
&lt;TD width="93.8359px" class="awsui_body-cell_c6tup_6wa2x_93 awsui_body-cell-last-row_c6tup_6wa2x_148"&gt;–&lt;/TD&gt;
&lt;TD width="104.414px" class="awsui_body-cell_c6tup_6wa2x_93 awsui_body-cell-last-row_c6tup_6wa2x_148"&gt;10.0.137.103&lt;/TD&gt;
&lt;TD width="73.8359px" class="awsui_body-cell_c6tup_6wa2x_93 awsui_body-cell-last-row_c6tup_6wa2x_148"&gt;attached&lt;/TD&gt;
&lt;TD width="159.305px" class="awsui_body-cell_c6tup_6wa2x_93 awsui_body-cell-last-row_c6tup_6wa2x_148"&gt;
&lt;DIV class="awsui_text-content_6absk_12mq6_94"&gt;vpc-0d2...b90&lt;/DIV&gt;
&lt;/TD&gt;
&lt;TD width="162.164px" class="awsui_body-cell_c6tup_6wa2x_93 awsui_body-cell-last-row_c6tup_6wa2x_148"&gt;
&lt;DIV class="awsui_text-content_6absk_12mq6_94"&gt;subnet-03c...&lt;/DIV&gt;
&lt;/TD&gt;
&lt;TD width="71.7578px" class="awsui_body-cell_c6tup_6wa2x_93 awsui_body-cell-last-row_c6tup_6wa2x_148"&gt;disabled&lt;/TD&gt;
&lt;TD width="157.039px" class="awsui_body-cell_c6tup_6wa2x_93 awsui_body-cell-last-row_c6tup_6wa2x_148"&gt;
&lt;DIV class="awsui_text-content_6absk_12mq6_94"&gt;sg-07f...&lt;/DIV&gt;
&lt;/TD&gt;
&lt;TD width="72.9531px" class="awsui_body-cell_c6tup_6wa2x_93 awsui_body-cell-last-row_c6tup_6wa2x_148"&gt;Elastic network interface&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;P&gt;&lt;BR /&gt;--------&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;In "show system state" I see the MAC addresses of the Elastic Network Interfaces I expect. sys.s1.p1.hwaddr is the MAC address of&amp;nbsp;eni-062... intended for the WAN, and&amp;nbsp;sys.s1.p2.hwaddr is the MAC address of&amp;nbsp;eni-06b... intended for the LAN.&lt;/P&gt;
&lt;PRE&gt;admin@PA-VM&amp;gt; show system state&lt;BR /&gt;…&lt;BR /&gt;sys.s1.p1.bus: 0000:00:06.0&lt;BR /&gt;sys.s1.p1.capability: [ auto, 10Mb/s-half, 10Mb/s-full, 100Mb/s-half, 100Mb/s-full, 1Gb/s-half, 1Gb/s-full, 10Gb/s-half, 10Gb/s-full, 25Gb/s-half, 25Gb/s-full, 40Gb/s-half, 40Gb/s-full, 100Gb/s-half, 100Gb/s-full, ]&lt;BR /&gt;sys.s1.p1.cfg: { 'breakout': False, 'fec': 0, 'mode': Disabled, 'pause-frames': True, 'setting': auto, }&lt;BR /&gt;sys.s1.p1.detail: { }&lt;BR /&gt;sys.s1.p1.driver: net_ena&lt;BR /&gt;sys.s1.p1.eni:&lt;BR /&gt;sys.s1.p1.hwaddr: 06:71:1a:54:54:9d&lt;BR /&gt;sys.s1.p1.mtu: 1504&lt;BR /&gt;sys.s1.p1.phy: { 'link-partner': { }, 'media': CAT5, 'type': Ethernet, }&lt;BR /&gt;sys.s1.p1.rate: { 'duration': 28560, 'last-sample': 2023-12-23 22:18:40, 'rx-broadcast': 0, 'rx-bytes': 0, 'rx-multicast': 0, 'rx-unicast': 0, 'tx-broadcast': 0, 'tx-bytes': 0, 'tx-multicast': 0, 'tx-unicast': 0, }&lt;BR /&gt;sys.s1.p1.state: board_port_autoneg&lt;BR /&gt;sys.s1.p1.stats: { 'link-down': 0, 'rx-broadcast': 0, 'rx-bytes': 22824, 'rx-discards': 0, 'rx-error': 0, 'rx-missed-error': 0, 'rx-multicast': 0, 'rx-unicast': 523, 'tx-broadcast': 0, 'tx-bytes': 0, 'tx-error': 0, 'tx-multicast': 0, 'tx-unicast': 0, }&lt;BR /&gt;sys.s1.p1.status: { 'link': Down, 'mode': Disabled, 'pause-frames': True, 'setting': Unknown, 'type': RJ45, }&lt;BR /&gt;…&lt;BR /&gt;sys.s1.p2.bus: 0000:00:07.0&lt;BR /&gt;sys.s1.p2.capability: [ auto, 10Mb/s-half, 10Mb/s-full, 100Mb/s-half, 100Mb/s-full, 1Gb/s-half, 1Gb/s-full, 10Gb/s-half, 10Gb/s-full, 25Gb/s-half, 25Gb/s-full, 40Gb/s-half, 40Gb/s-full, 100Gb/s-half, 100Gb/s-full, ]&lt;BR /&gt;sys.s1.p2.cfg: { 'breakout': False, 'fec': 0, 'mode': Disabled, 'pause-frames': True, 'setting': auto, }&lt;BR /&gt;sys.s1.p2.detail: { }&lt;BR /&gt;sys.s1.p2.driver: net_ena&lt;BR /&gt;sys.s1.p2.eni:&lt;BR /&gt;sys.s1.p2.hwaddr: 06:62:fb:e5:5e:9f&lt;BR /&gt;sys.s1.p2.mtu: 1504&lt;BR /&gt;sys.s1.p2.phy: { 'link-partner': { }, 'media': CAT5, 'type': Ethernet, }&lt;BR /&gt;sys.s1.p2.rate: { 'duration': 28560, 'last-sample': 2023-12-23 22:18:40, 'rx-broadcast': 0, 'rx-bytes': 0, 'rx-multicast': 0, 'rx-unicast': 0, 'tx-broadcast': 0, 'tx-bytes': 0, 'tx-multicast': 0, 'tx-unicast': 0, }&lt;BR /&gt;sys.s1.p2.state: board_port_autoneg&lt;BR /&gt;sys.s1.p2.stats: { 'link-down': 0, 'rx-broadcast': 0, 'rx-bytes': 21252, 'rx-discards': 0, 'rx-error': 0, 'rx-missed-error': 0, 'rx-multicast': 0, 'rx-unicast': 506, 'tx-broadcast': 0, 'tx-bytes': 0, 'tx-error': 0, 'tx-multicast': 0, 'tx-unicast': 0, }&lt;BR /&gt;sys.s1.p2.status: { 'link': Down, 'mode': Disabled, 'pause-frames': True, 'setting': Unknown, 'type': RJ45, }&lt;/PRE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;However no interfaces appear in "show interface all" and the Web UI never shows their status as green.&lt;/P&gt;
&lt;PRE&gt;admin@PA-VM&amp;gt; show interface all&lt;BR /&gt;&lt;BR /&gt;total configured hardware interfaces: 0&lt;BR /&gt;&lt;BR /&gt;name id speed/duplex/state mac address&lt;BR /&gt;--------------------------------------------------------------------------------&lt;BR /&gt;&lt;BR /&gt;aggregation groups: 0&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;total configured logical interfaces: 0&lt;BR /&gt;&lt;BR /&gt;name id vsys zone forwarding tag address&lt;BR /&gt;------------------- ----- ---- ---------------- ------------------------ ------ ------------------&lt;/PRE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;--------&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In other posts I've read that this means the interface is not configured. I set the interface type of the first two Ethernet interfaces to Layer3, created a management profile which allows ICMP ping, and set their IP address to use DHCP.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The ENI which I'm intending as the WAN interface has a public IPv4 Elastic IP address associated with it, which I would expect means AWS should respond to a DHCP request for that interface at least.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2023-12-24 at 9.01.21 AM.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/56087i415A17FF01AB81E9/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Screenshot 2023-12-24 at 9.01.21 AM.png" alt="Screenshot 2023-12-24 at 9.01.21 AM.png" /&gt;&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;--------&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I've rebooted the EC2 instance multiple times, including going all the way to Stopping the instance and then Starting it again to ensure any new device tree will be properly handled at boot.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'm running out of ideas of what to try. What else could be preventing PAN from seeing these links as configured and active?&lt;/P&gt;</description>
      <pubDate>Sun, 24 Dec 2023 17:07:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/aws-pan-os-11-interfaces-never-become-active/m-p/570777#M2067</guid>
      <dc:creator>DGentry</dc:creator>
      <dc:date>2023-12-24T17:07:52Z</dc:date>
    </item>
    <item>
      <title>Re: AWS PAN-OS 11 Interfaces never become active</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/aws-pan-os-11-interfaces-never-become-active/m-p/571035#M2068</link>
      <description>&lt;P&gt;This was marked as spam when posted, I've been trying other things for a couple days.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;One thing was to shut down the PAN-OS 11.1 VM and start up an EC2 instance with one of the earlier bundles running PAN-OS 9. This one is able to boot the image but I cannot log in, either via SSH nor web.&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;SSH appears to be because we require Instance Metadata v2, which breaks the SSH authorized_key support in the PAN-OS 9 instance.&amp;nbsp;&lt;A href="https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/new-vm-asks-for-password-using-ssh/m-p/533831/highlight/true#M1838" target="_blank" rel="noopener"&gt;https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/new-vm-asks-for-password-using-ssh/m-p/533831/highlight/true#M1838&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;The instructions say to use SSH to change the admin password before trying to log in using the WebUI, which I couldn't do because of this.&amp;nbsp;Web UI login rejects admin/admin. They might change the default password in the AMI images, to protect people from leaving an open router login on an AWS address.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;PAN-OS 11.1 is apparently able to use instance metadata v2 to handle its SSH authorized_keys. However it does make me wonder if the interfaces not coming up is somehow related to instance metadata. I don't currently have an environment with metadata v1 supported to try it.&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;An EC2 instance can retrieve information about elastic network interfaces using:&amp;nbsp;&lt;/SPAN&gt;&lt;A class="_3t5uN8xUmg0TOwRCOGQEcU" href="http://169.254.169.254/latest/meta-data/network/interfaces/" target="_blank" rel="noopener nofollow ugc"&gt;http://169.254.169.254/latest/meta-data/network/interfaces/&lt;/A&gt;&lt;BR /&gt;&lt;SPAN&gt;I'll be that is what the PAN VM Series does.&amp;nbsp;With metadata v2, that code would need to know how to fetch and add a&amp;nbsp;&lt;CODE class="_34q3PgLsx9zIU5BiSOjFoM"&gt;X-aws-ec2-metadata-token&lt;/CODE&gt;&lt;BR /&gt;They appear to have added this support for SSH authorized_keys, but I bet the Interface handling code does not.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 27 Dec 2023 22:31:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/aws-pan-os-11-interfaces-never-become-active/m-p/571035#M2068</guid>
      <dc:creator>DGentry</dc:creator>
      <dc:date>2023-12-27T22:31:41Z</dc:date>
    </item>
    <item>
      <title>Re: AWS PAN-OS 11 Interfaces never become active</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/aws-pan-os-11-interfaces-never-become-active/m-p/571057#M2069</link>
      <description>&lt;P&gt;Confirmed that the lack of metadata v1 is part of the problem. I've enabled instance metadata v1 on the PAN-OS 11.1 instance, and now it is a step closer:&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;CODE class="_34q3PgLsx9zIU5BiSOjFoM"&gt;debug show vm-series interfaces all&lt;/CODE&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;now shows the correct Elastic Network Interface. Previously, the Eni column was blank. The interfaces still don't come up,&amp;nbsp;&lt;/P&gt;
&lt;P class="_1qeIAgB0cPwnLhDF9XSiJM"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="_1qeIAgB0cPwnLhDF9XSiJM"&gt;&lt;CODE class="_34q3PgLsx9zIU5BiSOjFoM"&gt;admin@PA-VM&amp;gt; debug show vm-series interfaces all&lt;/CODE&gt;&lt;BR /&gt;&lt;CODE class="_34q3PgLsx9zIU5BiSOjFoM"&gt;Interface Base-OS_port&amp;nbsp; &amp;nbsp; Base-OS_MAC&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; PCI-ID&amp;nbsp; &amp;nbsp;Driver&amp;nbsp; Eni&lt;/CODE&gt;&lt;BR /&gt;&lt;CODE class="_34q3PgLsx9zIU5BiSOjFoM"&gt;&amp;nbsp;mgt&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; eth0&amp;nbsp; 06:61:22:d2:24:f9&amp;nbsp; 0000:00:05.0&amp;nbsp; &amp;nbsp; &amp;nbsp; ena&lt;/CODE&gt;&lt;BR /&gt;&lt;CODE class="_34q3PgLsx9zIU5BiSOjFoM"&gt;&amp;nbsp;Ethernet1/1&amp;nbsp; eth1&amp;nbsp; 06:10:fd:9c:14:23&amp;nbsp; 0000:00:06.0&amp;nbsp; net_ena&amp;nbsp; eni-0f6500e5&lt;/CODE&gt;&lt;BR /&gt;&lt;CODE class="_34q3PgLsx9zIU5BiSOjFoM"&gt;&amp;nbsp;Ethernet1/2&amp;nbsp; eth2&amp;nbsp; 06:7e:43:5b:b9:35&amp;nbsp; 0000:00:07.0&amp;nbsp; net_ena&amp;nbsp; eni-05a70efe&lt;/CODE&gt;&lt;BR /&gt;&lt;CODE class="_34q3PgLsx9zIU5BiSOjFoM"&gt;&lt;A href="mailto:admin@PA-VM&amp;gt;" target="_blank" rel="noopener"&gt;admin@PA-VM&amp;gt;&lt;/A&gt;&lt;/CODE&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 29 Dec 2023 15:40:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/aws-pan-os-11-interfaces-never-become-active/m-p/571057#M2069</guid>
      <dc:creator>DGentry</dc:creator>
      <dc:date>2023-12-29T15:40:16Z</dc:date>
    </item>
    <item>
      <title>Re: AWS PAN-OS 11 Interfaces never become active</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/aws-pan-os-11-interfaces-never-become-active/m-p/571063#M2070</link>
      <description>&lt;P&gt;Confirmed that the lack of metadata v1 is the problem. After enabling instance metadata v1 on the PAN-OS 11.1 VM,&lt;CODE class="_34q3PgLsx9zIU5BiSOjFoM"&gt;debug show vm-series interfaces all&lt;/CODE&gt;&amp;nbsp;shows the correct Elastic Network Interface. Previously, the Eni column was blank.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="_1qeIAgB0cPwnLhDF9XSiJM"&gt;After committing the config again and rebooting again, success! The links came up.&lt;/P&gt;
&lt;PRE class="_3GnarIQX9tD_qsgXkfSDz1"&gt;&lt;CODE class="_34q3PgLsx9zIU5BiSOjFoM"&gt;admin@PA-VM&amp;gt; show interface all

total configured hardware interfaces: 2

name         id  speed/duplex/state   mac address
-------------------------------------------------------
ethernet1/1  16  ukn/ukn/up           06:10:fd:9c:14:23
ethernet1/2  17  ukn/ukn/up           06:7e:43:5b:b9:35

aggregation groups: 0


total configured logical interfaces: 2

name         id  vsys zone  forwarding   tag address
------------ --  ---- ----- ------------ --- ---------------
ethernet1/1  16  1    wan   vr:default   0   10.0.64.180/24
ethernet1/2  17  1    lan   vr:default   0   10.0.128.219/24&lt;/CODE&gt;&lt;/PRE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 29 Dec 2023 15:42:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/aws-pan-os-11-interfaces-never-become-active/m-p/571063#M2070</guid>
      <dc:creator>DGentry</dc:creator>
      <dc:date>2023-12-29T15:42:33Z</dc:date>
    </item>
    <item>
      <title>Re: AWS PAN-OS 11 Interfaces never become active</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/aws-pan-os-11-interfaces-never-become-active/m-p/1234691#M2382</link>
      <description>&lt;P&gt;&lt;SPAN data-olk-copy-source="MessageBody"&gt;Quite often the cause is an incompatibility between the Interface driver and specific instance type.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-olk-copy-source="MessageBody"&gt;By default, it's Data Plane Development Kit (DPDK) mode and certain VM-based AWS instance types that aren't compatible (not dependant on the Cloud Vendor, but on the instance type).&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-olk-copy-source="MessageBody"&gt;So, the solution would be to disable the DPDK, and it will switch it to MMAP (requires reboot).&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;" lang="en-CA"&gt;see what is enabled (dpdk or mmap):&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;" lang="en-CA"&gt;&lt;STRONG&gt;&amp;gt;show system setting dpdk-pkt-io&lt;/STRONG&gt;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;" lang="en-CA"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;" lang="en-CA"&gt;disable dpdk (it will switch to mmap):&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;" lang="en-CA"&gt;&lt;STRONG&gt;&amp;gt;set system setting dpdk-pkt-io off&lt;/STRONG&gt;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;" lang="en-CA"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P lang="en-CA"&gt;I’ve personally encountered this issue twice before, and DPDK was the cause.&lt;/P&gt;</description>
      <pubDate>Fri, 25 Jul 2025 10:33:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/aws-pan-os-11-interfaces-never-become-active/m-p/1234691#M2382</guid>
      <dc:creator>CalinC</dc:creator>
      <dc:date>2025-07-25T10:33:12Z</dc:date>
    </item>
  </channel>
</rss>

