<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Issue with connecting Expedition to Panorama - Error35 in Expedition Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/expedition-discussions/issue-with-connecting-expedition-to-panorama-error35/m-p/515976#M4199</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/226991"&gt;@Liam_Wynne&lt;/a&gt;&amp;nbsp;&lt;SPAN&gt;In Expedition to avoid SSL Certificates errors we are trusting all source, so it should not be a certificate error.&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;“Curl error code 35” is happening when the SSL handshake is failing, s&lt;/SPAN&gt;&lt;SPAN&gt;omething is blocking the SSL connection between Expedition and the Panorama.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;&lt;SPAN&gt;You could test the connection by executing directly the call using the Expedition CLI:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;curl --insecure&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://urldefense.com/v3/__https://PANORAMA_IP__;!!Mt_FR42WkD9csi9Y!fDjczbkHRh_ohUuiajsFNuWPCVfDpN4Oi4D9ToRA3UNoLHzuJoVl4oSBcTaSgVUhtxp6K4TcvoiZN2XrblBgcQr5ziaGsg$" target="_blank" rel="noopener" data-saferedirecturl="https://www.google.com/url?q=https://urldefense.com/v3/__https://PANORAMA_IP__;!!Mt_FR42WkD9csi9Y!fDjczbkHRh_ohUuiajsFNuWPCVfDpN4Oi4D9ToRA3UNoLHzuJoVl4oSBcTaSgVUhtxp6K4TcvoiZN2XrblBgcQr5ziaGsg$&amp;amp;source=gmail&amp;amp;ust=1664300114304000&amp;amp;usg=AOvVaw2JWMqbW5k_MiezasIOsQkM"&gt;https://PANORAMA_IP&lt;/A&gt;&lt;SPAN&gt;:PANORAMA_&lt;/SPAN&gt;&lt;WBR /&gt;&lt;SPAN&gt;PORT/api?type=keygen -d user=PANORAMA_USER -d password=PANORAMA_PWD&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;For example:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;c&lt;WBR /&gt;url --insecure&amp;nbsp;&lt;A href="https://urldefense.com/v3/__https://10.11.29.168:443/api?type=keygen__;!!Mt_FR42WkD9csi9Y!fDjczbkHRh_ohUuiajsFNuWPCVfDpN4Oi4D9ToRA3UNoLHzuJoVl4oSBcTaSgVUhtxp6K4TcvoiZN2XrblBgcQqEOd6eOg$" target="_blank" rel="noopener" data-saferedirecturl="https://www.google.com/url?q=https://urldefense.com/v3/__https://10.11.29.168:443/api?type%3Dkeygen__;!!Mt_FR42WkD9csi9Y!fDjczbkHRh_ohUuiajsFNuWPCVfDpN4Oi4D9ToRA3UNoLHzuJoVl4oSBcTaSgVUhtxp6K4TcvoiZN2XrblBgcQqEOd6eOg$&amp;amp;source=gmail&amp;amp;ust=1664300114304000&amp;amp;usg=AOvVaw3cOwwlDQGDGx9LcjoK9vTI"&gt;https://10.11.29.168:443/api?&lt;WBR /&gt;type=keygen&lt;/A&gt;&amp;nbsp;-d user=admin -d password=paloalto &amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This command should return API key as result.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Please execute the above command and see if you are getting any errors, also please validate that there’s nothing between Expedition and Panorama that could be blocking the traffic.&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 26 Sep 2022 18:25:10 GMT</pubDate>
    <dc:creator>lychiang</dc:creator>
    <dc:date>2022-09-26T18:25:10Z</dc:date>
    <item>
      <title>Issue with connecting Expedition to Panorama - Error35</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/issue-with-connecting-expedition-to-panorama-error35/m-p/515797#M4192</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Expedition Version: 1.2.38&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I am trying to connect an expedition to Panorama 10.1.6h3 (VMware)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;When I try to add an API key using username/password I get "Error Code 35: The connection with the device cannot be established. Please, report Error Code for improvement"&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I generated an API key for the panorama so I tried that method by adding API key on expedition.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As I found that error 35 relates to SSL Communication I checked that area. The Panorama has an SSL/TLS profile on it's management interface with a cert from their own trusted root CA.&amp;nbsp;&amp;nbsp; I loaded the root CA for the certificate into the Ubuntu CA certificate store as presumed the issue was the expedition could not communicate on SSL with the panorama until it had the root CA to trust the certificate on it's management interface.&amp;nbsp; The CA cert is present and active on Ubuntu as a trusted CA cert. However I still am receiving the same error&amp;nbsp;&amp;nbsp; Error 35 when I add API via username/password option and when I have API key added and try to retrieve contents it does not download. &amp;nbsp; With either method I see logs on the panorama on 443 indicating session end reason of&amp;nbsp; tcp-rst-from-client&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;So it looks like there still an issue with establishing an SSL session to allow retrieval of contents etc&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Does anyone have any ideas how I might try to resolve this?&lt;/P&gt;</description>
      <pubDate>Fri, 23 Sep 2022 09:48:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/issue-with-connecting-expedition-to-panorama-error35/m-p/515797#M4192</guid>
      <dc:creator>Liam_Wynne</dc:creator>
      <dc:date>2022-09-23T09:48:23Z</dc:date>
    </item>
    <item>
      <title>Re: Issue with connecting Expedition to Panorama - Error35</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/issue-with-connecting-expedition-to-panorama-error35/m-p/515820#M4193</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/226991"&gt;@Liam_Wynne&lt;/a&gt;&amp;nbsp;could you please review&amp;nbsp;/home/userSpace/devices/debug.txt , it might give more detail root cause on why the connection is not working.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 23 Sep 2022 15:16:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/issue-with-connecting-expedition-to-panorama-error35/m-p/515820#M4193</guid>
      <dc:creator>lychiang</dc:creator>
      <dc:date>2022-09-23T15:16:00Z</dc:date>
    </item>
    <item>
      <title>Re: Issue with connecting Expedition to Panorama - Error35</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/issue-with-connecting-expedition-to-panorama-error35/m-p/515925#M4194</link>
      <description>&lt;P&gt;Thanks Lychiang - I checked this log and it confirmed issue was SSL negotiation.&lt;/P&gt;</description>
      <pubDate>Mon, 26 Sep 2022 11:53:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/issue-with-connecting-expedition-to-panorama-error35/m-p/515925#M4194</guid>
      <dc:creator>Liam_Wynne</dc:creator>
      <dc:date>2022-09-26T11:53:37Z</dc:date>
    </item>
    <item>
      <title>Re: Issue with connecting Expedition to Panorama - Error35</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/issue-with-connecting-expedition-to-panorama-error35/m-p/515976#M4199</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/226991"&gt;@Liam_Wynne&lt;/a&gt;&amp;nbsp;&lt;SPAN&gt;In Expedition to avoid SSL Certificates errors we are trusting all source, so it should not be a certificate error.&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;“Curl error code 35” is happening when the SSL handshake is failing, s&lt;/SPAN&gt;&lt;SPAN&gt;omething is blocking the SSL connection between Expedition and the Panorama.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;&lt;SPAN&gt;You could test the connection by executing directly the call using the Expedition CLI:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;curl --insecure&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://urldefense.com/v3/__https://PANORAMA_IP__;!!Mt_FR42WkD9csi9Y!fDjczbkHRh_ohUuiajsFNuWPCVfDpN4Oi4D9ToRA3UNoLHzuJoVl4oSBcTaSgVUhtxp6K4TcvoiZN2XrblBgcQr5ziaGsg$" target="_blank" rel="noopener" data-saferedirecturl="https://www.google.com/url?q=https://urldefense.com/v3/__https://PANORAMA_IP__;!!Mt_FR42WkD9csi9Y!fDjczbkHRh_ohUuiajsFNuWPCVfDpN4Oi4D9ToRA3UNoLHzuJoVl4oSBcTaSgVUhtxp6K4TcvoiZN2XrblBgcQr5ziaGsg$&amp;amp;source=gmail&amp;amp;ust=1664300114304000&amp;amp;usg=AOvVaw2JWMqbW5k_MiezasIOsQkM"&gt;https://PANORAMA_IP&lt;/A&gt;&lt;SPAN&gt;:PANORAMA_&lt;/SPAN&gt;&lt;WBR /&gt;&lt;SPAN&gt;PORT/api?type=keygen -d user=PANORAMA_USER -d password=PANORAMA_PWD&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;For example:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;c&lt;WBR /&gt;url --insecure&amp;nbsp;&lt;A href="https://urldefense.com/v3/__https://10.11.29.168:443/api?type=keygen__;!!Mt_FR42WkD9csi9Y!fDjczbkHRh_ohUuiajsFNuWPCVfDpN4Oi4D9ToRA3UNoLHzuJoVl4oSBcTaSgVUhtxp6K4TcvoiZN2XrblBgcQqEOd6eOg$" target="_blank" rel="noopener" data-saferedirecturl="https://www.google.com/url?q=https://urldefense.com/v3/__https://10.11.29.168:443/api?type%3Dkeygen__;!!Mt_FR42WkD9csi9Y!fDjczbkHRh_ohUuiajsFNuWPCVfDpN4Oi4D9ToRA3UNoLHzuJoVl4oSBcTaSgVUhtxp6K4TcvoiZN2XrblBgcQqEOd6eOg$&amp;amp;source=gmail&amp;amp;ust=1664300114304000&amp;amp;usg=AOvVaw3cOwwlDQGDGx9LcjoK9vTI"&gt;https://10.11.29.168:443/api?&lt;WBR /&gt;type=keygen&lt;/A&gt;&amp;nbsp;-d user=admin -d password=paloalto &amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This command should return API key as result.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Please execute the above command and see if you are getting any errors, also please validate that there’s nothing between Expedition and Panorama that could be blocking the traffic.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 26 Sep 2022 18:25:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/issue-with-connecting-expedition-to-panorama-error35/m-p/515976#M4199</guid>
      <dc:creator>lychiang</dc:creator>
      <dc:date>2022-09-26T18:25:10Z</dc:date>
    </item>
  </channel>
</rss>

