<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Connection to Panorama for new deployment failing in Next-Generation Firewall Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/connection-to-panorama-for-new-deployment-failing/m-p/577253#M2651</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have the following issue I am running panorama 10.2.7h3 my new device P440 is also running 10.2.7h3.&lt;/P&gt;
&lt;P&gt;When I want to onboard the device into panorama it is not working.&lt;/P&gt;
&lt;P&gt;I am onboarding the device with Authenticatio keys.&lt;/P&gt;
&lt;P&gt;Following the below procedure.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/panorama/10-2/panorama-admin/manage-firewalls/add-a-firewall-as-a-managed-device" target="_blank"&gt;Add a Firewall as a Managed Device (paloaltonetworks.com)&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;I have also reset the secure communication on the PA440&amp;nbsp; and tried removing adding the serials from panorama.&lt;/P&gt;
&lt;P&gt;The connection doesn't come up.&lt;/P&gt;
&lt;P&gt;In the ms.log file i am getting the following.&lt;/P&gt;
&lt;P&gt;Seems to be related to SSL.&lt;/P&gt;
&lt;P&gt;2024-02-14 15:49:05.844 +0100 COMM: connection established. sock=24 remote ip=10.255.125.50 port=3978 local port=54018&lt;BR /&gt;2024-02-14 15:49:05.844 +0100 cms agent: Pre. send buffer limit=46080. s=24&lt;BR /&gt;2024-02-14 15:49:05.844 +0100 cms agent: Post. send buffer limit=425984. s=24&lt;BR /&gt;2024-02-14 15:49:05.844 +0100 Error: cs_load_certs_ex(cs_common.c:544): keyfile not exists&lt;BR /&gt;2024-02-14 15:49:05.844 +0100 Error: pan_cmsa_tcp_channel_setup(src_panos/cms_agent.c:1340): cms agent: cs_load_certs_ex failed2024-02-14 15:49:05.845 +0100 cmsa: client will use default context&lt;BR /&gt;2024-02-14 15:49:05.846 +0100 Error: _get_current_cert(sc3_utils.c:117): sdb node 'cfg.ms.ca' does not exist ret -5&lt;BR /&gt;2024-02-14 15:49:05.846 +0100 Error: sc3_ca_exists(sc3_certs.c:229): SC3: Failed to get the current CA name.&lt;BR /&gt;2024-02-14 15:49:05.846 +0100 Warning: sc3_init_sc3(sc3_utils.c:360): SC3: Failed to get the Current CC name&lt;BR /&gt;2024-02-14 15:49:05.846 +0100 SC3: CA: '', CC/CSR: 'd41d48e6-c7da-4a61-8307-79ce0cc33ff7'&lt;BR /&gt;2024-02-14 15:49:05.846 +0100 Error: _get_current_cert(sc3_utils.c:117): sdb node 'cfg.ms.ca' does not exist ret -5&lt;BR /&gt;2024-02-14 15:49:05.846 +0100 Warning: sc3_get_current_sc3(sc3_utils.c:184): SC3: failed to get SNI&lt;BR /&gt;2024-02-14 15:49:05.846 +0100 Warning: sc3_get_current_sc3(sc3_utils.c:187): SC3: failed to get CCN&lt;BR /&gt;2024-02-14 15:49:05.847 +0100 Warning: sc3_init_sctx(sc3_ctx.c:302): SC3: not set, skip cert loading&lt;BR /&gt;2024-02-14 15:49:05.847 +0100 SC3A: using SNI (from AK): 4591c212-e525-4d70-92fb-4f5243dff4af&lt;BR /&gt;2024-02-14 15:49:05.847 +0100 SC3A: using sc3 ctx with no cert&lt;BR /&gt;2024-02-14 15:49:05.901 +0100 Error: pan_cmsa_tcp_channel_setup(src_panos/cms_agent.c:1719): panorama agent: SSL connect error. sock=24 err=5&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Am i missing something?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;taking a pcap also show that panoram is just resetting the connection.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="zGomez_0-1707923254038.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/57627iC1F2A46ED602CCE6/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="zGomez_0-1707923254038.png" alt="zGomez_0-1707923254038.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Any help on this would be appreciated.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 14 Feb 2024 15:08:30 GMT</pubDate>
    <dc:creator>zGomez</dc:creator>
    <dc:date>2024-02-14T15:08:30Z</dc:date>
    <item>
      <title>Connection to Panorama for new deployment failing</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/connection-to-panorama-for-new-deployment-failing/m-p/577253#M2651</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have the following issue I am running panorama 10.2.7h3 my new device P440 is also running 10.2.7h3.&lt;/P&gt;
&lt;P&gt;When I want to onboard the device into panorama it is not working.&lt;/P&gt;
&lt;P&gt;I am onboarding the device with Authenticatio keys.&lt;/P&gt;
&lt;P&gt;Following the below procedure.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/panorama/10-2/panorama-admin/manage-firewalls/add-a-firewall-as-a-managed-device" target="_blank"&gt;Add a Firewall as a Managed Device (paloaltonetworks.com)&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;I have also reset the secure communication on the PA440&amp;nbsp; and tried removing adding the serials from panorama.&lt;/P&gt;
&lt;P&gt;The connection doesn't come up.&lt;/P&gt;
&lt;P&gt;In the ms.log file i am getting the following.&lt;/P&gt;
&lt;P&gt;Seems to be related to SSL.&lt;/P&gt;
&lt;P&gt;2024-02-14 15:49:05.844 +0100 COMM: connection established. sock=24 remote ip=10.255.125.50 port=3978 local port=54018&lt;BR /&gt;2024-02-14 15:49:05.844 +0100 cms agent: Pre. send buffer limit=46080. s=24&lt;BR /&gt;2024-02-14 15:49:05.844 +0100 cms agent: Post. send buffer limit=425984. s=24&lt;BR /&gt;2024-02-14 15:49:05.844 +0100 Error: cs_load_certs_ex(cs_common.c:544): keyfile not exists&lt;BR /&gt;2024-02-14 15:49:05.844 +0100 Error: pan_cmsa_tcp_channel_setup(src_panos/cms_agent.c:1340): cms agent: cs_load_certs_ex failed2024-02-14 15:49:05.845 +0100 cmsa: client will use default context&lt;BR /&gt;2024-02-14 15:49:05.846 +0100 Error: _get_current_cert(sc3_utils.c:117): sdb node 'cfg.ms.ca' does not exist ret -5&lt;BR /&gt;2024-02-14 15:49:05.846 +0100 Error: sc3_ca_exists(sc3_certs.c:229): SC3: Failed to get the current CA name.&lt;BR /&gt;2024-02-14 15:49:05.846 +0100 Warning: sc3_init_sc3(sc3_utils.c:360): SC3: Failed to get the Current CC name&lt;BR /&gt;2024-02-14 15:49:05.846 +0100 SC3: CA: '', CC/CSR: 'd41d48e6-c7da-4a61-8307-79ce0cc33ff7'&lt;BR /&gt;2024-02-14 15:49:05.846 +0100 Error: _get_current_cert(sc3_utils.c:117): sdb node 'cfg.ms.ca' does not exist ret -5&lt;BR /&gt;2024-02-14 15:49:05.846 +0100 Warning: sc3_get_current_sc3(sc3_utils.c:184): SC3: failed to get SNI&lt;BR /&gt;2024-02-14 15:49:05.846 +0100 Warning: sc3_get_current_sc3(sc3_utils.c:187): SC3: failed to get CCN&lt;BR /&gt;2024-02-14 15:49:05.847 +0100 Warning: sc3_init_sctx(sc3_ctx.c:302): SC3: not set, skip cert loading&lt;BR /&gt;2024-02-14 15:49:05.847 +0100 SC3A: using SNI (from AK): 4591c212-e525-4d70-92fb-4f5243dff4af&lt;BR /&gt;2024-02-14 15:49:05.847 +0100 SC3A: using sc3 ctx with no cert&lt;BR /&gt;2024-02-14 15:49:05.901 +0100 Error: pan_cmsa_tcp_channel_setup(src_panos/cms_agent.c:1719): panorama agent: SSL connect error. sock=24 err=5&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Am i missing something?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;taking a pcap also show that panoram is just resetting the connection.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="zGomez_0-1707923254038.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/57627iC1F2A46ED602CCE6/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="zGomez_0-1707923254038.png" alt="zGomez_0-1707923254038.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Any help on this would be appreciated.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 14 Feb 2024 15:08:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/connection-to-panorama-for-new-deployment-failing/m-p/577253#M2651</guid>
      <dc:creator>zGomez</dc:creator>
      <dc:date>2024-02-14T15:08:30Z</dc:date>
    </item>
    <item>
      <title>Re: Connection to Panorama for new deployment failing</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/connection-to-panorama-for-new-deployment-failing/m-p/577274#M2656</link>
      <description>&lt;P&gt;I am having this same problem with 10.2.6 on both Panorama and FW 3220. I just spent two days with support and they are escalating.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I even changed my MGMT Interface MTU as recommended by this article even though I am not seeing large packets.&lt;BR /&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u000000wkjSCAQ&amp;amp;lang=en_US%E2%80%A9" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u000000wkjSCAQ&amp;amp;lang=en_US%E2%80%A9&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 14 Feb 2024 20:58:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/connection-to-panorama-for-new-deployment-failing/m-p/577274#M2656</guid>
      <dc:creator>StanleyWilson</dc:creator>
      <dc:date>2024-02-14T20:58:34Z</dc:date>
    </item>
    <item>
      <title>Re: Connection to Panorama for new deployment failing</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/connection-to-panorama-for-new-deployment-failing/m-p/577297#M2657</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/211799"&gt;@zGomez&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;it looks like you might be hitting an issue in this KB:&amp;nbsp;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u000000wkjSCAQ" target="_self"&gt; Managed Firewalls showing disconnected from the Panorama even though network connectivity is good&lt;/A&gt;. Could you check whether following this KB resolves the issue?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Kind Regards&lt;/P&gt;
&lt;P&gt;Pavel&lt;/P&gt;</description>
      <pubDate>Thu, 15 Feb 2024 04:50:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/connection-to-panorama-for-new-deployment-failing/m-p/577297#M2657</guid>
      <dc:creator>PavelK</dc:creator>
      <dc:date>2024-02-15T04:50:22Z</dc:date>
    </item>
    <item>
      <title>Re: Connection to Panorama for new deployment failing</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/connection-to-panorama-for-new-deployment-failing/m-p/577623#M2672</link>
      <description>&lt;P&gt;Hi Pavel,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have followed the above article but this did not solve my problem(first thing i tried actually).&amp;nbsp; It turned out that I needed to allow SSL on the policy as an application, it was no longer recognized as panorama on the first connection.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;I really have no idea why this is and what has changed.&amp;nbsp; Since the panorama app id allow implicitly ssl on the first connection. (connection to panorma was passing multiple firewalls )&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;But is solved my panorama connection by allowing ssl in the policy.&lt;/P&gt;</description>
      <pubDate>Mon, 19 Feb 2024 07:25:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/connection-to-panorama-for-new-deployment-failing/m-p/577623#M2672</guid>
      <dc:creator>zGomez</dc:creator>
      <dc:date>2024-02-19T07:25:14Z</dc:date>
    </item>
    <item>
      <title>Re: Connection to Panorama for new deployment failing</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/connection-to-panorama-for-new-deployment-failing/m-p/579826#M2797</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/211799"&gt;@zGomez&lt;/a&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;thank you for reply.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I see. You might have been hitting an issue described in this KB: &lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u000000kI94CAE" target="_self"&gt;Why is traffic on port 3978 Identified as SSL application instead of Panorama application?&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Kind Regards&lt;/P&gt;
&lt;P&gt;Pavel&lt;/P&gt;</description>
      <pubDate>Fri, 08 Mar 2024 22:19:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/connection-to-panorama-for-new-deployment-failing/m-p/579826#M2797</guid>
      <dc:creator>PavelK</dc:creator>
      <dc:date>2024-03-08T22:19:45Z</dc:date>
    </item>
  </channel>
</rss>

