<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Unable to enable programmic access for CloudNGFW in Cloud NGFW for AWS Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cloud-ngfw-for-aws-discussions/unable-to-enable-programmic-access-for-cloudngfw/m-p/512629#M376</link>
    <description>&lt;P&gt;Hello @DwighAwesome,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Greetings from Palo Alto Networks!&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Error “… (InvalidClientTokenId) …: The security token included in the request is invalid“&lt;BR /&gt;This error occurs when the user failed to pass authentication. Either the appropriate user is not active or user access keys are not valid.&lt;BR /&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Resolve authentication issues by following steps:&lt;BR /&gt;&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;gt; ensure that the AWS keys repository variables used in the repository are valid, accurate, and contain no spaces or typos&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;gt;ensure that the corresponding user is active in the AWS console&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Note: HTTP Status Code: 403 - The request must contain either a valid (registered) AWS access key ID or X.509 certificate.&lt;BR /&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Thanks and Regards,&lt;BR /&gt;Gopinath Sekar&lt;BR /&gt;Product Specialist&lt;BR /&gt;Palo Alto Networks&lt;BR /&gt;&lt;A href="https://live.paloaltonetworks.com/t5/cloud-ngfw-discussions/bd-p/Cloud_NGFW_Discussion" target="_blank"&gt;https://live.paloaltonetworks.com/t5/cloud-ngfw-discussions/bd-p/Cloud_NGFW_Discussion&lt;/A&gt;.&lt;BR /&gt;*Don’t forget to accept the solution provided!*&lt;/P&gt;</description>
    <pubDate>Tue, 23 Aug 2022 00:35:04 GMT</pubDate>
    <dc:creator>gsekar</dc:creator>
    <dc:date>2022-08-23T00:35:04Z</dc:date>
    <item>
      <title>Unable to enable programmic access for CloudNGFW</title>
      <link>https://live.paloaltonetworks.com/t5/cloud-ngfw-for-aws-discussions/unable-to-enable-programmic-access-for-cloudngfw/m-p/512336#M373</link>
      <description>&lt;P&gt;&lt;A href="https://pan.dev/cloudngfw/aws/api/" target="_blank"&gt;https://pan.dev/cloudngfw/aws/api/&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://github.com/PaloAltoNetworks/cloud-ngfw-aws-examples" target="_blank"&gt;https://github.com/PaloAltoNetworks/cloud-ngfw-aws-examples&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;using the Git Repo's get_pa_token.py I get the following error&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Traceback (most recent call last):&lt;BR /&gt;File "C:\Users\xxxxx\cloud-ngfw-aws-examples\programmatic_access\get_pa_token.py", line 138, in &amp;lt;module&amp;gt;&lt;BR /&gt;assert resp_dict['ResponseStatus']['ErrorCode'] == 0&lt;BR /&gt;AssertionError&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I can't get further to get this setup.&lt;/P&gt;</description>
      <pubDate>Fri, 19 Aug 2022 02:07:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cloud-ngfw-for-aws-discussions/unable-to-enable-programmic-access-for-cloudngfw/m-p/512336#M373</guid>
      <dc:creator>DwightAwesome</dc:creator>
      <dc:date>2022-08-19T02:07:54Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to enable programmic access for CloudNGFW</title>
      <link>https://live.paloaltonetworks.com/t5/cloud-ngfw-for-aws-discussions/unable-to-enable-programmic-access-for-cloudngfw/m-p/512438#M374</link>
      <description>&lt;P&gt;I ran the get_pa_token.py with the debug flag, and I get this:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;PROG_ACC_LOGGER : [DEBUG] 2022-08-20T15:23:08.533Z ResponseText: {"ResponseStatus": {"ErrorCode": 1, "Reason": "Account is not successfully onboarded by FMS. Programmatic Access for CloudNGFWGlobalRulestackAdmin role is not supported."}} |- get_pa_token:134&lt;BR /&gt;Traceback (most recent call last):&lt;BR /&gt;File "C:\Users\Dwight\cloud-ngfw-aws-examples\programmatic_access\get_pa_token.py", line 138, in &amp;lt;module&amp;gt;&lt;BR /&gt;assert resp_dict['ResponseStatus']['ErrorCode'] == 0&lt;BR /&gt;AssertionError&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Not sure where to go from here.&lt;/P&gt;</description>
      <pubDate>Sat, 20 Aug 2022 19:27:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cloud-ngfw-for-aws-discussions/unable-to-enable-programmic-access-for-cloudngfw/m-p/512438#M374</guid>
      <dc:creator>DwightAwesome</dc:creator>
      <dc:date>2022-08-20T19:27:39Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to enable programmic access for CloudNGFW</title>
      <link>https://live.paloaltonetworks.com/t5/cloud-ngfw-for-aws-discussions/unable-to-enable-programmic-access-for-cloudngfw/m-p/512439#M375</link>
      <description>&lt;P&gt;I've gotten further by specifying the cloudrulestackadmin role instead of the&amp;nbsp;cloudglobalrulestackadmin in the get_pa_token.py call. But I get a 403 forbidden when I run the curl command in step 10 of &lt;A href="https://pan.dev/cloudngfw/aws/api/" target="_blank"&gt;https://pan.dev/cloudngfw/aws/api/&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;What am I missing?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;Ultimately, I'm trying to push the firewall rules via terraform, but the setup in &lt;A href="https://medium.com/palo-alto-networks-developer-blog/the-developers-guide-to-palo-alto-networks-cloud-ngfw-for-aws-b8c39c3b9228" target="_blank"&gt;https://medium.com/palo-alto-networks-developer-blog/the-developers-guide-to-palo-alto-networks-cloud-ngfw-for-aws-b8c39c3b9228&lt;/A&gt; isn't working and I get the following&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;│ Error: InvalidClientTokenId: The security token included in the request is invalid.&lt;BR /&gt;│ status code: 403, request id: e8b9428f-0ec4-48ef-a876-aaf616ad0aa1&lt;BR /&gt;│&lt;BR /&gt;│ with provider["registry.terraform.io/paloaltonetworks/cloudngfwaws"],&lt;BR /&gt;│ on PA-Cloud-NGFW.tf line 23, in provider "cloudngfwaws":&lt;BR /&gt;│ 23: provider "cloudngfwaws" {&lt;/P&gt;</description>
      <pubDate>Sat, 20 Aug 2022 20:27:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cloud-ngfw-for-aws-discussions/unable-to-enable-programmic-access-for-cloudngfw/m-p/512439#M375</guid>
      <dc:creator>DwightAwesome</dc:creator>
      <dc:date>2022-08-20T20:27:39Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to enable programmic access for CloudNGFW</title>
      <link>https://live.paloaltonetworks.com/t5/cloud-ngfw-for-aws-discussions/unable-to-enable-programmic-access-for-cloudngfw/m-p/512629#M376</link>
      <description>&lt;P&gt;Hello @DwighAwesome,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Greetings from Palo Alto Networks!&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Error “… (InvalidClientTokenId) …: The security token included in the request is invalid“&lt;BR /&gt;This error occurs when the user failed to pass authentication. Either the appropriate user is not active or user access keys are not valid.&lt;BR /&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Resolve authentication issues by following steps:&lt;BR /&gt;&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;gt; ensure that the AWS keys repository variables used in the repository are valid, accurate, and contain no spaces or typos&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;gt;ensure that the corresponding user is active in the AWS console&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Note: HTTP Status Code: 403 - The request must contain either a valid (registered) AWS access key ID or X.509 certificate.&lt;BR /&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Thanks and Regards,&lt;BR /&gt;Gopinath Sekar&lt;BR /&gt;Product Specialist&lt;BR /&gt;Palo Alto Networks&lt;BR /&gt;&lt;A href="https://live.paloaltonetworks.com/t5/cloud-ngfw-discussions/bd-p/Cloud_NGFW_Discussion" target="_blank"&gt;https://live.paloaltonetworks.com/t5/cloud-ngfw-discussions/bd-p/Cloud_NGFW_Discussion&lt;/A&gt;.&lt;BR /&gt;*Don’t forget to accept the solution provided!*&lt;/P&gt;</description>
      <pubDate>Tue, 23 Aug 2022 00:35:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cloud-ngfw-for-aws-discussions/unable-to-enable-programmic-access-for-cloudngfw/m-p/512629#M376</guid>
      <dc:creator>gsekar</dc:creator>
      <dc:date>2022-08-23T00:35:04Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to enable programmic access for CloudNGFW</title>
      <link>https://live.paloaltonetworks.com/t5/cloud-ngfw-for-aws-discussions/unable-to-enable-programmic-access-for-cloudngfw/m-p/566698#M430</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/230240"&gt;@DwightAwesome&lt;/a&gt;! Were you able to solve this? Just got the same error&lt;/P&gt;</description>
      <pubDate>Wed, 22 Nov 2023 13:10:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cloud-ngfw-for-aws-discussions/unable-to-enable-programmic-access-for-cloudngfw/m-p/566698#M430</guid>
      <dc:creator>YUsachou</dc:creator>
      <dc:date>2023-11-22T13:10:36Z</dc:date>
    </item>
  </channel>
</rss>

