<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cannot connect Log Collector to Panorama in Panorama Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/panorama-discussions/cannot-connect-log-collector-to-panorama/m-p/518898#M1167</link>
    <description>&lt;P&gt;Hi, sorry for late reply, was on leave last week. I have validated 1) and 2), but what is the command to check 3)?&lt;/P&gt;</description>
    <pubDate>Mon, 24 Oct 2022 11:28:00 GMT</pubDate>
    <dc:creator>alan-griffiths</dc:creator>
    <dc:date>2022-10-24T11:28:00Z</dc:date>
    <item>
      <title>Cannot connect Log Collector to Panorama</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/cannot-connect-log-collector-to-panorama/m-p/517941#M1153</link>
      <description>&lt;P&gt;Going mad here trying to connect a dedicated log collector to a Panorama HA pair.&lt;/P&gt;
&lt;P&gt;Followed this procedure&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/panorama/10-1/panorama-admin/set-up-panorama/set-up-the-panorama-virtual-appliance/set-up-the-panorama-virtual-appliance-as-a-log-collector" target="_blank"&gt;https://docs.paloaltonetworks.com/panorama/10-1/panorama-admin/set-up-panorama/set-up-the-panorama-virtual-appliance/set-up-the-panorama-virtual-appliance-as-a-log-collector&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I get a far as step 12, but after the commit it never reports connected and I never get a status.&lt;/P&gt;
&lt;P&gt;The log collector is reporting disconnected&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;admin@Panorama&amp;gt; show panorama-status

Panorama Server 1 : 10.201.24.12
    Connected     : no
    HA state      : disconnected

Panorama Server 2 : 10.201.25.12
    Connected     : no
    HA state      : disconnected
&lt;/LI-CODE&gt;
&lt;P&gt;The log is constantly cycling this&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;2022-10-14 11:44:47.330 +0000 CMSA: Source bind sock to 10.201.25.13
2022-10-14 11:44:47.330 +0000 COMM: Source bind sock 18 to 10.201.25.13 before connect to remote ip [10.201.25.12] &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/45675"&gt;@port&lt;/a&gt; 3978
2022-10-14 11:44:47.331 +0000 COMM: connection established. sock=18 remote ip=10.201.25.12 port=3978 local port=45361
2022-10-14 11:44:47.331 +0000 cms agent: Pre. send buffer limit=87040. s=18
2022-10-14 11:44:47.331 +0000 cms agent: Post. send buffer limit=425984. s=18
2022-10-14 11:44:47.331 +0000 Warning:  pan_cmsa_tcp_channel_setup(src_panos/cms_agent.c:905): SC3A: client will use sni:'a83fdd6a-3842-4806-962b-4af693a2744d' and ccn:'353cea78-6757-45ac-9073-8fa13c4e2090'
2022-10-14 11:44:47.331 +0000 SC3: CA: 'a83fdd6a-3842-4806-962b-4af693a2744d', CC/CSR: '353cea78-6757-45ac-9073-8fa13c4e2090'
2022-10-14 11:44:47.335 +0000 CMSA: Source bind sock to 10.201.25.13
2022-10-14 11:44:47.335 +0000 COMM: Source bind sock 19 to 10.201.25.13 before connect to remote ip [10.201.24.12] &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/45675"&gt;@port&lt;/a&gt; 3978
2022-10-14 11:44:47.336 +0000 SC3: context initialized using SNI: a83fdd6a-3842-4806-962b-4af693a2744d
2022-10-14 11:44:47.336 +0000 cmsa: client will use SNI: a83fdd6a-3842-4806-962b-4af693a2744d
2022-10-14 11:44:47.336 +0000 COMM: connection established. sock=19 remote ip=10.201.24.12 port=3978 local port=39935
2022-10-14 11:44:47.336 +0000 cms agent: Pre. send buffer limit=87040. s=19
2022-10-14 11:44:47.336 +0000 cms agent: Post. send buffer limit=425984. s=19
2022-10-14 11:44:47.336 +0000 Warning:  pan_cmsa_tcp_channel_setup(src_panos/cms_agent.c:905): SC3A: client will use sni:'a83fdd6a-3842-4806-962b-4af693a2744d' and ccn:'353cea78-6757-45ac-9073-8fa13c4e2090'
2022-10-14 11:44:47.336 +0000 Error:  pan_cmsa_tcp_channel_setup(src_panos/cms_agent.c:1208): panorama agent: SSL connect error. sock=18 err=1
2022-10-14 11:44:47.337 +0000 SC3: CA: 'a83fdd6a-3842-4806-962b-4af693a2744d', CC/CSR: '353cea78-6757-45ac-9073-8fa13c4e2090'
2022-10-14 11:44:47.341 +0000 SC3: context initialized using SNI: a83fdd6a-3842-4806-962b-4af693a2744d
2022-10-14 11:44:47.341 +0000 cmsa: client will use SNI: a83fdd6a-3842-4806-962b-4af693a2744d
2022-10-14 11:44:47.342 +0000 Error:  pan_cmsa_tcp_channel_setup(src_panos/cms_agent.c:1208): panorama agent: SSL connect error. sock=19 err=1&lt;/LI-CODE&gt;
&lt;P&gt;Repeated the process multiple times, but same failure every time. Both sides are running 10.1.6-h6&lt;/P&gt;</description>
      <pubDate>Fri, 14 Oct 2022 11:56:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/cannot-connect-log-collector-to-panorama/m-p/517941#M1153</guid>
      <dc:creator>alan-griffiths</dc:creator>
      <dc:date>2022-10-14T11:56:30Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot connect Log Collector to Panorama</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/cannot-connect-log-collector-to-panorama/m-p/518020#M1154</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/232309"&gt;@alan-griffiths&lt;/a&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;thanks for the post.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;1.) Could you make sure that log collector has the same time and time zone as Panorama?&lt;/P&gt;
&lt;P&gt;2.) Could you make sure that log collector has set DNS server?&lt;/P&gt;
&lt;P&gt;3.) Could you make sure that&amp;nbsp;log collector has device management license applied?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Kind Regards&lt;/P&gt;
&lt;P&gt;Pavel&lt;/P&gt;</description>
      <pubDate>Sun, 16 Oct 2022 21:42:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/cannot-connect-log-collector-to-panorama/m-p/518020#M1154</guid>
      <dc:creator>PavelK</dc:creator>
      <dc:date>2022-10-16T21:42:57Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot connect Log Collector to Panorama</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/cannot-connect-log-collector-to-panorama/m-p/518527#M1164</link>
      <description>&lt;P&gt;hi&amp;nbsp;&lt;A id="link_7" class="lia-link-navigation lia-page-link lia-user-name-link" href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/232309" target="_self" aria-label="View Profile of alan-griffiths"&gt;&lt;SPAN class=""&gt;Alan-Griffiths&lt;/SPAN&gt;&lt;/A&gt;：&lt;/P&gt;
&lt;P&gt;your panorama ha state display&amp;nbsp; disconnected，so i think you should recovery ha state then check log collector connect stats.&lt;/P&gt;</description>
      <pubDate>Thu, 20 Oct 2022 15:07:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/cannot-connect-log-collector-to-panorama/m-p/518527#M1164</guid>
      <dc:creator>Felixcao</dc:creator>
      <dc:date>2022-10-20T15:07:12Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot connect Log Collector to Panorama</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/cannot-connect-log-collector-to-panorama/m-p/518898#M1167</link>
      <description>&lt;P&gt;Hi, sorry for late reply, was on leave last week. I have validated 1) and 2), but what is the command to check 3)?&lt;/P&gt;</description>
      <pubDate>Mon, 24 Oct 2022 11:28:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/cannot-connect-log-collector-to-panorama/m-p/518898#M1167</guid>
      <dc:creator>alan-griffiths</dc:creator>
      <dc:date>2022-10-24T11:28:00Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot connect Log Collector to Panorama</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/cannot-connect-log-collector-to-panorama/m-p/518905#M1168</link>
      <description>&lt;P&gt;Thank you for reply&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/232309"&gt;@alan-griffiths&lt;/a&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;you can check it from cli by:&amp;nbsp;&lt;STRONG&gt;request license info&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;This license: "Device Management License" should be listed under Feature.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Kind Regards&lt;/P&gt;
&lt;P&gt;Pavel&lt;/P&gt;</description>
      <pubDate>Mon, 24 Oct 2022 12:30:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/cannot-connect-log-collector-to-panorama/m-p/518905#M1168</guid>
      <dc:creator>PavelK</dc:creator>
      <dc:date>2022-10-24T12:30:32Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot connect Log Collector to Panorama</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/cannot-connect-log-collector-to-panorama/m-p/518910#M1169</link>
      <description>&lt;P&gt;Confirmed device mgt license is present.&lt;/P&gt;</description>
      <pubDate>Mon, 24 Oct 2022 13:52:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/cannot-connect-log-collector-to-panorama/m-p/518910#M1169</guid>
      <dc:creator>alan-griffiths</dc:creator>
      <dc:date>2022-10-24T13:52:17Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot connect Log Collector to Panorama</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/cannot-connect-log-collector-to-panorama/m-p/518980#M1170</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/232309"&gt;@alan-griffiths&lt;/a&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;thank you for reply.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Could you confirm the PAN-OS version of both Panorama as well as Log Collector?&lt;/P&gt;
&lt;P&gt;Could you confirm that&amp;nbsp;Log Collector's certificate is not expired? Navigate to:&amp;nbsp;https://&amp;lt;Log Collector IP&amp;gt;:3978&lt;/P&gt;
&lt;P&gt;Could you confirm what logs on Panorama side says?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Kind Regards&lt;/P&gt;
&lt;P&gt;Pavel&lt;/P&gt;</description>
      <pubDate>Tue, 25 Oct 2022 02:03:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/cannot-connect-log-collector-to-panorama/m-p/518980#M1170</guid>
      <dc:creator>PavelK</dc:creator>
      <dc:date>2022-10-25T02:03:28Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot connect Log Collector to Panorama</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/cannot-connect-log-collector-to-panorama/m-p/519006#M1171</link>
      <description>&lt;P&gt;Both Panorama and LC are running 10.1.6-h6.&lt;/P&gt;
&lt;P&gt;Confirmed LC cert is still valid.&lt;/P&gt;
&lt;P&gt;Panorama log is filled with these&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;2022-10-25 09:34:50.101 +0000 Error:  sni_ssl_servername_cb(src_cms/cms_server.c:654): Unknown SNI: 'ae25c29c-0b84-4ff3-8b7e-5a2877411c8a'.
139678775854848:error:1408A0E2:SSL routines:SSL3_GET_CLIENT_HELLO:clienthello tlsext:s3_srvr.c:1181:
2022-10-25 09:34:52.147 +0000 Error:  sni_ssl_servername_cb(src_cms/cms_server.c:654): Unknown SNI: 'a83fdd6a-3842-4806-962b-4af693a2744d'.
139678809425664:error:1408A0E2:SSL routines:SSL3_GET_CLIENT_HELLO:clienthello tlsext:s3_srvr.c:1181:
2022-10-25 09:35:00.456 +0000 Error:  sni_ssl_servername_cb(src_cms/cms_server.c:654): Unknown SNI: 'ae25c29c-0b84-4ff3-8b7e-5a2877411c8a'.
139678792640256:error:1408A0E2:SSL routines:SSL3_GET_CLIENT_HELLO:clienthello tlsext:s3_srvr.c:1181:
2022-10-25 09:35:02.500 +0000 Error:  sni_ssl_servername_cb(src_cms/cms_server.c:654): Unknown SNI: 'a83fdd6a-3842-4806-962b-4af693a2744d'.
139678733891328:error:1408A0E2:SSL routines:SSL3_GET_CLIENT_HELLO:clienthello tlsext:s3_srvr.c:1181:
2022-10-25 09:35:10.811 +0000 Error:  sni_ssl_servername_cb(src_cms/cms_server.c:654): Unknown SNI: 'ae25c29c-0b84-4ff3-8b7e-5a2877411c8a'.
139678826211072:error:1408A0E2:SSL routines:SSL3_GET_CLIENT_HELLO:clienthello tlsext:s3_srvr.c:1181:
2022-10-25 09:35:12.847 +0000 Error:  sni_ssl_servername_cb(src_cms/cms_server.c:654): Unknown SNI: 'a83fdd6a-3842-4806-962b-4af693a2744d'.
139678775854848:error:1408A0E2:SSL routines:SSL3_GET_CLIENT_HELLO:clienthello tlsext:s3_srvr.c:1181:
2022-10-25 09:35:21.164 +0000 Error:  sni_ssl_servername_cb(src_cms/cms_server.c:654): Unknown SNI: 'ae25c29c-0b84-4ff3-8b7e-5a2877411c8a'.
139678826211072:error:1408A0E2:SSL routines:SSL3_GET_CLIENT_HELLO:clienthello tlsext:s3_srvr.c:1181:
2022-10-25 09:35:23.202 +0000 Error:  sni_ssl_servername_cb(src_cms/cms_server.c:654): Unknown SNI: 'a83fdd6a-3842-4806-962b-4af693a2744d'.
&lt;/LI-CODE&gt;</description>
      <pubDate>Tue, 25 Oct 2022 09:37:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/cannot-connect-log-collector-to-panorama/m-p/519006#M1171</guid>
      <dc:creator>alan-griffiths</dc:creator>
      <dc:date>2022-10-25T09:37:18Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot connect Log Collector to Panorama</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/cannot-connect-log-collector-to-panorama/m-p/519751#M1181</link>
      <description>&lt;P&gt;I opened a support ticket for this exact issue. This KB article solved the issue for me:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/panorama/10-1/panorama-admin/troubleshooting/recover-managed-device-connectivity-to-panorama" target="_blank"&gt;https://docs.paloaltonetworks.com/panorama/10-1/panorama-admin/troubleshooting/recover-managed-device-connectivity-to-panorama&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;I skipped over step 2.2 because there was no managed device to reset.&lt;/P&gt;
&lt;P&gt;Good luck.&lt;/P&gt;</description>
      <pubDate>Mon, 31 Oct 2022 20:54:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/cannot-connect-log-collector-to-panorama/m-p/519751#M1181</guid>
      <dc:creator>nvieira</dc:creator>
      <dc:date>2022-10-31T20:54:23Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot connect Log Collector to Panorama</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/cannot-connect-log-collector-to-panorama/m-p/519824#M1182</link>
      <description>&lt;P&gt;Ah, you're about 6 hours too late. I'd just opened a ticket and got the same info. The Palo documentation is baffling. There are two separate pages detailing how to configure dedicated log collector. One page includes a step to reset the sc3 the other one doesn't.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This is the page support told me to use &lt;A href="https://docs.paloaltonetworks.com/panorama/10-1/panorama-admin/manage-log-collection/log-collection-deployments/deploy-panorama-with-dedicated-log-collectors" target="_blank"&gt;https://docs.paloaltonetworks.com/panorama/10-1/panorama-admin/manage-log-collection/log-collection-deployments/deploy-panorama-with-dedicated-log-collectors&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 01 Nov 2022 10:11:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/cannot-connect-log-collector-to-panorama/m-p/519824#M1182</guid>
      <dc:creator>alan-griffiths</dc:creator>
      <dc:date>2022-11-01T10:11:11Z</dc:date>
    </item>
  </channel>
</rss>

