<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic After removal firewall from Panorama it cannot register anymore to other Panorama instances in Panorama Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/panorama-discussions/after-removal-firewall-from-panorama-it-cannot-register-anymore/m-p/541319#M1534</link>
    <description>&lt;P&gt;I had a small POC with SD-WAN on PA-410 units and Panorama in management mode.&lt;/P&gt;
&lt;P&gt;Once it was done, configuration was deleted, and it acted just as a regular firewall, so I have decided later to remove it at all from Panorama. Just as a regular step removed IP, disabled policy and objects and device and network templates.&lt;/P&gt;
&lt;P&gt;Now as I need to test something else I have installed fresh Panorama instance (only difference that it is now in Panorama mode).&lt;/P&gt;
&lt;P&gt;Unfortunately FW is not able anymore to connect to Panorama.&lt;/P&gt;
&lt;P&gt;Both PA and Panorama OS are 10.1.5-h1 (it was same lastly no change).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What I did so far tried to reinstall Panorama, modify its IP, use same IP as previous instance.&lt;/P&gt;
&lt;P&gt;License is active on Panorama, certificates are also ok on both FW and Panorama.&lt;/P&gt;
&lt;P&gt;FW can reach Panorama.&lt;/P&gt;
&lt;P&gt;For isolating issue there is a top rule on FW that allows ANY &amp;gt; Panorama (no zone) and same in reverse.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Also from logs it states that (on both ends):&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV style="overflow-wrap: break-word !important; width: 392px;"&gt;lcs agent on serialxxx-log-collection connected&lt;/DIV&gt;
&lt;DIV style="overflow-wrap: break-word !important; width: 392px;"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV style="overflow-wrap: break-word !important; width: 392px;"&gt;Connectivity on port 3978 works, I can see established sessions.&lt;/DIV&gt;
&lt;DIV style="overflow-wrap: break-word !important; width: 392px;"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV style="overflow-wrap: break-word !important; width: 392px;"&gt;On Panorama it keeps to be not connected, from FW:&lt;/DIV&gt;
&lt;DIV style="overflow-wrap: break-word !important; width: 392px;"&gt;
&lt;P&gt;&amp;gt; show panorama-status&lt;/P&gt;
&lt;P&gt;Connected : no&lt;/P&gt;
&lt;/DIV&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Any ideas what I am missing?&lt;/P&gt;</description>
    <pubDate>Sat, 06 May 2023 14:45:43 GMT</pubDate>
    <dc:creator>MarcinJ</dc:creator>
    <dc:date>2023-05-06T14:45:43Z</dc:date>
    <item>
      <title>After removal firewall from Panorama it cannot register anymore to other Panorama instances</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/after-removal-firewall-from-panorama-it-cannot-register-anymore/m-p/541319#M1534</link>
      <description>&lt;P&gt;I had a small POC with SD-WAN on PA-410 units and Panorama in management mode.&lt;/P&gt;
&lt;P&gt;Once it was done, configuration was deleted, and it acted just as a regular firewall, so I have decided later to remove it at all from Panorama. Just as a regular step removed IP, disabled policy and objects and device and network templates.&lt;/P&gt;
&lt;P&gt;Now as I need to test something else I have installed fresh Panorama instance (only difference that it is now in Panorama mode).&lt;/P&gt;
&lt;P&gt;Unfortunately FW is not able anymore to connect to Panorama.&lt;/P&gt;
&lt;P&gt;Both PA and Panorama OS are 10.1.5-h1 (it was same lastly no change).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What I did so far tried to reinstall Panorama, modify its IP, use same IP as previous instance.&lt;/P&gt;
&lt;P&gt;License is active on Panorama, certificates are also ok on both FW and Panorama.&lt;/P&gt;
&lt;P&gt;FW can reach Panorama.&lt;/P&gt;
&lt;P&gt;For isolating issue there is a top rule on FW that allows ANY &amp;gt; Panorama (no zone) and same in reverse.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Also from logs it states that (on both ends):&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV style="overflow-wrap: break-word !important; width: 392px;"&gt;lcs agent on serialxxx-log-collection connected&lt;/DIV&gt;
&lt;DIV style="overflow-wrap: break-word !important; width: 392px;"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV style="overflow-wrap: break-word !important; width: 392px;"&gt;Connectivity on port 3978 works, I can see established sessions.&lt;/DIV&gt;
&lt;DIV style="overflow-wrap: break-word !important; width: 392px;"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV style="overflow-wrap: break-word !important; width: 392px;"&gt;On Panorama it keeps to be not connected, from FW:&lt;/DIV&gt;
&lt;DIV style="overflow-wrap: break-word !important; width: 392px;"&gt;
&lt;P&gt;&amp;gt; show panorama-status&lt;/P&gt;
&lt;P&gt;Connected : no&lt;/P&gt;
&lt;/DIV&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Any ideas what I am missing?&lt;/P&gt;</description>
      <pubDate>Sat, 06 May 2023 14:45:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/after-removal-firewall-from-panorama-it-cannot-register-anymore/m-p/541319#M1534</guid>
      <dc:creator>MarcinJ</dc:creator>
      <dc:date>2023-05-06T14:45:43Z</dc:date>
    </item>
    <item>
      <title>Re: After removal firewall from Panorama it cannot register anymore to other Panorama instances</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/after-removal-firewall-from-panorama-it-cannot-register-anymore/m-p/541320#M1535</link>
      <description>&lt;P&gt;Today again I followed that procedure, after Panorama reinstallation and it worked.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/panorama/10-1/panorama-admin/troubleshooting/recover-managed-device-connectivity-to-panorama" target="_self"&gt;Recover Managed Device Connectivity to Panorama&lt;/A&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 06 May 2023 15:52:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/after-removal-firewall-from-panorama-it-cannot-register-anymore/m-p/541320#M1535</guid>
      <dc:creator>MarcinJ</dc:creator>
      <dc:date>2023-05-06T15:52:59Z</dc:date>
    </item>
    <item>
      <title>Re: After removal firewall from Panorama it cannot register anymore to other Panorama instances</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/after-removal-firewall-from-panorama-it-cannot-register-anymore/m-p/564850#M1997</link>
      <description>&lt;P&gt;When you followed that procedure, how did it go? Did you run into any hiccups or service interruption? Thanks.&lt;/P&gt;</description>
      <pubDate>Wed, 08 Nov 2023 17:52:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/after-removal-firewall-from-panorama-it-cannot-register-anymore/m-p/564850#M1997</guid>
      <dc:creator>cbrentano-mozilla</dc:creator>
      <dc:date>2023-11-08T17:52:44Z</dc:date>
    </item>
  </channel>
</rss>

