<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Reason: TCP channel setup failed, reverting configuration issue. in Panorama Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/panorama-discussions/reason-tcp-channel-setup-failed-reverting-configuration-issue/m-p/545107#M1567</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Since recently we have a few firewalls that we are unable to push because the firewall is checking connectivity to panorama and this is failing.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Inside panorama the device is listed as connected and from the firewall's session table I can see there is an existing session to panorama.&lt;/P&gt;
&lt;P&gt;2023-06-07 16:38:38.410 +0200 ACR: Performing panorama connectivity check (attempt 5 of 5)&lt;BR /&gt;2023-06-07 16:38:38.410 +0200 [Secure conn] Secure channel for Firewall to panorama communication not enabled for secure conn.&lt;BR /&gt;2023-06-07 16:38:56.329 +0200 client dagger reported op command was SUCCESSFUL&lt;BR /&gt;2023-06-07 16:38:57.459 +0200 client dagger reported op command was SUCCESSFUL&lt;BR /&gt;2023-06-07 16:38:58.807 +0200 Error: pan_comm_get_iplist(cs_conn.c:4711): connmgr: panorama: addr info address: panorama.domain.net error: System error&lt;BR /&gt;2023-06-07 16:38:58.808 +0200 Error: pan_cmsa_tcp_channel_setup(src_panos/cms_agent.c:1124): ACR: Failed to establish TCP connection&lt;BR /&gt;2023-06-07 16:38:58.808 +0200 ACR: Panorama connectivity check failed for panorama.ontex.net. Reason: TCP channel setup failed, reverting configuration&lt;BR /&gt;2023-06-07 16:38:58.808 +0200 ACR: Post-commit connectivity check failed, beginning to revert config.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I already tried increasing timers and amount of retries.&amp;nbsp; &amp;nbsp;I also verified the firewall is able to reach panorama and is connected.&lt;/P&gt;
&lt;P&gt;DNS is working.&lt;/P&gt;
&lt;P&gt;Session table is showing me 2 active sessions to panorama.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;show session all filter destination 10.255.125.50&lt;/P&gt;
&lt;P&gt;--------------------------------------------------------------------------------&lt;BR /&gt;ID Application State Type Flag Src[Sport]/Zone/Proto (translated IP[Port])&lt;BR /&gt;Vsys Dst[Dport]/Zone (translated IP[Port])&lt;BR /&gt;--------------------------------------------------------------------------------&lt;BR /&gt;6501 panorama ACTIVE FLOW 10.163.66.253[33607]/management/6 (10.163.66.253[33607])&lt;BR /&gt;vsys1 10.255.125.50[3978]/VPN (10.255.125.50[3978])&lt;BR /&gt;7007 panorama ACTIVE FLOW 10.163.66.252[45224]/management/6 (10.163.66.252[45224])&lt;BR /&gt;vsys1 10.255.125.50[3978]/VPN (10.255.125.50[3978])&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;anybody else experiencing this?&amp;nbsp; &amp;nbsp; can i use global counter for management traffic?&lt;/P&gt;
&lt;P&gt;Only one of the firewalls in the cluster is having this issue, only active one.&amp;nbsp; Restarting mangement plane did not help.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 07 Jun 2023 14:56:37 GMT</pubDate>
    <dc:creator>zGomez</dc:creator>
    <dc:date>2023-06-07T14:56:37Z</dc:date>
    <item>
      <title>Reason: TCP channel setup failed, reverting configuration issue.</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/reason-tcp-channel-setup-failed-reverting-configuration-issue/m-p/545107#M1567</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Since recently we have a few firewalls that we are unable to push because the firewall is checking connectivity to panorama and this is failing.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Inside panorama the device is listed as connected and from the firewall's session table I can see there is an existing session to panorama.&lt;/P&gt;
&lt;P&gt;2023-06-07 16:38:38.410 +0200 ACR: Performing panorama connectivity check (attempt 5 of 5)&lt;BR /&gt;2023-06-07 16:38:38.410 +0200 [Secure conn] Secure channel for Firewall to panorama communication not enabled for secure conn.&lt;BR /&gt;2023-06-07 16:38:56.329 +0200 client dagger reported op command was SUCCESSFUL&lt;BR /&gt;2023-06-07 16:38:57.459 +0200 client dagger reported op command was SUCCESSFUL&lt;BR /&gt;2023-06-07 16:38:58.807 +0200 Error: pan_comm_get_iplist(cs_conn.c:4711): connmgr: panorama: addr info address: panorama.domain.net error: System error&lt;BR /&gt;2023-06-07 16:38:58.808 +0200 Error: pan_cmsa_tcp_channel_setup(src_panos/cms_agent.c:1124): ACR: Failed to establish TCP connection&lt;BR /&gt;2023-06-07 16:38:58.808 +0200 ACR: Panorama connectivity check failed for panorama.ontex.net. Reason: TCP channel setup failed, reverting configuration&lt;BR /&gt;2023-06-07 16:38:58.808 +0200 ACR: Post-commit connectivity check failed, beginning to revert config.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I already tried increasing timers and amount of retries.&amp;nbsp; &amp;nbsp;I also verified the firewall is able to reach panorama and is connected.&lt;/P&gt;
&lt;P&gt;DNS is working.&lt;/P&gt;
&lt;P&gt;Session table is showing me 2 active sessions to panorama.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;show session all filter destination 10.255.125.50&lt;/P&gt;
&lt;P&gt;--------------------------------------------------------------------------------&lt;BR /&gt;ID Application State Type Flag Src[Sport]/Zone/Proto (translated IP[Port])&lt;BR /&gt;Vsys Dst[Dport]/Zone (translated IP[Port])&lt;BR /&gt;--------------------------------------------------------------------------------&lt;BR /&gt;6501 panorama ACTIVE FLOW 10.163.66.253[33607]/management/6 (10.163.66.253[33607])&lt;BR /&gt;vsys1 10.255.125.50[3978]/VPN (10.255.125.50[3978])&lt;BR /&gt;7007 panorama ACTIVE FLOW 10.163.66.252[45224]/management/6 (10.163.66.252[45224])&lt;BR /&gt;vsys1 10.255.125.50[3978]/VPN (10.255.125.50[3978])&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;anybody else experiencing this?&amp;nbsp; &amp;nbsp; can i use global counter for management traffic?&lt;/P&gt;
&lt;P&gt;Only one of the firewalls in the cluster is having this issue, only active one.&amp;nbsp; Restarting mangement plane did not help.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 07 Jun 2023 14:56:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/reason-tcp-channel-setup-failed-reverting-configuration-issue/m-p/545107#M1567</guid>
      <dc:creator>zGomez</dc:creator>
      <dc:date>2023-06-07T14:56:37Z</dc:date>
    </item>
    <item>
      <title>Re: Reason: TCP channel setup failed, reverting configuration issue.</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/reason-tcp-channel-setup-failed-reverting-configuration-issue/m-p/545201#M1570</link>
      <description>&lt;P&gt;If you change Panorama from DNS name to IP it still fails?&lt;/P&gt;</description>
      <pubDate>Thu, 08 Jun 2023 00:55:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/reason-tcp-channel-setup-failed-reverting-configuration-issue/m-p/545201#M1570</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2023-06-08T00:55:23Z</dc:date>
    </item>
    <item>
      <title>Re: Reason: TCP channel setup failed, reverting configuration issue.</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/reason-tcp-channel-setup-failed-reverting-configuration-issue/m-p/545758#M1579</link>
      <description>&lt;P data-unlink="true"&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/211799"&gt;@zGomez&lt;/a&gt;&amp;nbsp;Have you found a solution yet ?&lt;BR /&gt;I have a &lt;A href="https://live.paloaltonetworks.com/t5/panorama-discussions/push-to-devices-failed/td-p/545747" target="_blank" rel="noopener"&gt;similar problem&lt;/A&gt;, but unfortunately no solution yet.&lt;/P&gt;</description>
      <pubDate>Tue, 13 Jun 2023 13:11:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/reason-tcp-channel-setup-failed-reverting-configuration-issue/m-p/545758#M1579</guid>
      <dc:creator>Jeroen_Proost</dc:creator>
      <dc:date>2023-06-13T13:11:43Z</dc:date>
    </item>
    <item>
      <title>Re: Reason: TCP channel setup failed, reverting configuration issue.</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/reason-tcp-channel-setup-failed-reverting-configuration-issue/m-p/545774#M1580</link>
      <description>&lt;P&gt;Hi Jeroen,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For met the issue was resolved by checking the primary and secondary dns used under setup, services.&amp;nbsp; The primary dns in use here was an old dns that was no longer responding.&amp;nbsp; when issuing a dns lookup from the cli of palo alto i always had a response from the mgt interface.&amp;nbsp; So i am guessing the panorama check never switches to the seconcary if first is not responding.&lt;/P&gt;
&lt;P&gt;Dns resolving was something i checked right away fromt he cli but since this was responding i did not immediatly check the services dns config.&lt;/P&gt;
&lt;P&gt;I tried first as Raido suggest the ip and then it worked so this made me look at dns settings.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 13 Jun 2023 14:18:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/reason-tcp-channel-setup-failed-reverting-configuration-issue/m-p/545774#M1580</guid>
      <dc:creator>zGomez</dc:creator>
      <dc:date>2023-06-13T14:18:08Z</dc:date>
    </item>
    <item>
      <title>Re: Reason: TCP channel setup failed, reverting configuration issue.</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/reason-tcp-channel-setup-failed-reverting-configuration-issue/m-p/552080#M1685</link>
      <description>&lt;P&gt;I started having this same issue while attempting to add a second vpn tunnel to a 220.&amp;nbsp; The moment I start seeing that message in the firewall system logs, it appears to drop offline in Panorama.&amp;nbsp; Weird thing is that I can still https and ssh to it...&amp;nbsp; About the only way&amp;nbsp; I've been able to recover is to restart the management-server and eventually it reconnects.&lt;/P&gt;</description>
      <pubDate>Tue, 01 Aug 2023 14:40:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/reason-tcp-channel-setup-failed-reverting-configuration-issue/m-p/552080#M1685</guid>
      <dc:creator>bwsaloum</dc:creator>
      <dc:date>2023-08-01T14:40:35Z</dc:date>
    </item>
    <item>
      <title>Re: Reason: TCP channel setup failed, reverting configuration issue.</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/reason-tcp-channel-setup-failed-reverting-configuration-issue/m-p/552246#M1692</link>
      <description>&lt;P&gt;I too, am experiencing this issue and Panorama has always been referenced by IP and not DNS name.&lt;/P&gt;
&lt;P&gt;I am trying to enable ECMP on a HA pair PA5260s&lt;/P&gt;</description>
      <pubDate>Wed, 02 Aug 2023 19:16:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/reason-tcp-channel-setup-failed-reverting-configuration-issue/m-p/552246#M1692</guid>
      <dc:creator>ChuckW</dc:creator>
      <dc:date>2023-08-02T19:16:07Z</dc:date>
    </item>
    <item>
      <title>Re: Reason: TCP channel setup failed, reverting configuration issue.</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/reason-tcp-channel-setup-failed-reverting-configuration-issue/m-p/560322#M1902</link>
      <description>&lt;P&gt;Hi,&lt;BR /&gt;I observe the same, which version are you running ? I'm on&amp;nbsp;10.1.10-h2&lt;/P&gt;</description>
      <pubDate>Tue, 03 Oct 2023 05:37:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/reason-tcp-channel-setup-failed-reverting-configuration-issue/m-p/560322#M1902</guid>
      <dc:creator>karldormeTVH</dc:creator>
      <dc:date>2023-10-03T05:37:18Z</dc:date>
    </item>
    <item>
      <title>Re: Reason: TCP channel setup failed, reverting configuration issue.</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/reason-tcp-channel-setup-failed-reverting-configuration-issue/m-p/567763#M2025</link>
      <description>&lt;P&gt;I have had the same issue with a virtual firewall managed by Panorama. I do not use the hostname, but connect using IP address. Initially, PANW TAC suggested adding the IP address of Panorama on the managed firewall under Device &amp;gt; Setup &amp;gt; Interfaces &amp;gt; Management &amp;gt; Permitted IP Addresses. The issue was resolved for a while just after making this change, however it has re-appeared. I *think* my issue is to do with the server infrastructure that this virtual firewalls sits on, but have no concrete proof, so I have logged a TAC case again.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Versions running:&lt;BR /&gt;Panorama: 10.2.3-h2&lt;/P&gt;
&lt;P&gt;Managed firewall: 10.1.6&lt;/P&gt;</description>
      <pubDate>Thu, 30 Nov 2023 12:54:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/reason-tcp-channel-setup-failed-reverting-configuration-issue/m-p/567763#M2025</guid>
      <dc:creator>AtulK</dc:creator>
      <dc:date>2023-11-30T12:54:11Z</dc:date>
    </item>
    <item>
      <title>Re: Reason: TCP channel setup failed, reverting configuration issue.</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/reason-tcp-channel-setup-failed-reverting-configuration-issue/m-p/567771#M2027</link>
      <description>&lt;P&gt;The solution in my case was not only to factory reset the PA440, but also delete every remaining default configuration in it. After that, there was no problem pushing config to the PA440's.&lt;/P&gt;</description>
      <pubDate>Thu, 30 Nov 2023 13:33:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/reason-tcp-channel-setup-failed-reverting-configuration-issue/m-p/567771#M2027</guid>
      <dc:creator>Jeroen_Proost</dc:creator>
      <dc:date>2023-11-30T13:33:17Z</dc:date>
    </item>
    <item>
      <title>Re: Reason: TCP channel setup failed, reverting configuration issue.</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/reason-tcp-channel-setup-failed-reverting-configuration-issue/m-p/570285#M2048</link>
      <description>&lt;P&gt;Updating the DNS (as you noted) correct this issue for me.&amp;nbsp; Thank you for the post.&lt;/P&gt;</description>
      <pubDate>Tue, 19 Dec 2023 00:25:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/reason-tcp-channel-setup-failed-reverting-configuration-issue/m-p/570285#M2048</guid>
      <dc:creator>J-Miller</dc:creator>
      <dc:date>2023-12-19T00:25:12Z</dc:date>
    </item>
    <item>
      <title>Re: Reason: TCP channel setup failed, reverting configuration issue.</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/reason-tcp-channel-setup-failed-reverting-configuration-issue/m-p/570322#M2050</link>
      <description>&lt;P&gt;Just adding further to this for folks who might have issues in the future. My issue was resolved by increasing the "number of attempts for Panorama connectivity" from 1 (default) to 5. As I understand it, this solution does not address the underlying cause for this issue, which I *think* could be the bandwidth limitation since Panorama resides in Azure and the firewall is in a DC.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I followed this article to make changes:&lt;BR /&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-new-features/panorama-features/automatic-panorama-connection-recovery" target="_blank"&gt;https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-new-features/panorama-features/automatic-panorama-connection-recovery&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 19 Dec 2023 09:19:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/reason-tcp-channel-setup-failed-reverting-configuration-issue/m-p/570322#M2050</guid>
      <dc:creator>AtulK</dc:creator>
      <dc:date>2023-12-19T09:19:12Z</dc:date>
    </item>
    <item>
      <title>Re: Reason: TCP channel setup failed, reverting configuration issue.</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/reason-tcp-channel-setup-failed-reverting-configuration-issue/m-p/571503#M2062</link>
      <description>&lt;P&gt;Not sure if you located answer to your issue but in my case (same error) i had to install certificate on my firewall and after that no error...&lt;/P&gt;
&lt;P&gt;So far...&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Cheers&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 03 Jan 2024 00:21:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/reason-tcp-channel-setup-failed-reverting-configuration-issue/m-p/571503#M2062</guid>
      <dc:creator>D_Milojevic</dc:creator>
      <dc:date>2024-01-03T00:21:31Z</dc:date>
    </item>
    <item>
      <title>Re: Reason: TCP channel setup failed, reverting configuration issue.</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/reason-tcp-channel-setup-failed-reverting-configuration-issue/m-p/577073#M2153</link>
      <description>&lt;P&gt;Came across the same issue, but the only X-factors were updated to permitted IP's for the MGT interfaces.&amp;nbsp; Had to Add the firewall IP addresses to the Permitted IP's for the MGT interfaces on Panorama.&lt;/P&gt;</description>
      <pubDate>Tue, 13 Feb 2024 01:07:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/reason-tcp-channel-setup-failed-reverting-configuration-issue/m-p/577073#M2153</guid>
      <dc:creator>Ernesto-James</dc:creator>
      <dc:date>2024-02-13T01:07:59Z</dc:date>
    </item>
    <item>
      <title>Re: Reason: TCP channel setup failed, reverting configuration issue.</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/reason-tcp-channel-setup-failed-reverting-configuration-issue/m-p/598800#M2486</link>
      <description>&lt;P&gt;&amp;nbsp;This broke my connection to the GUI of those firewalls that I added the permit IP address. Not advised&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 25 Sep 2024 21:37:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/reason-tcp-channel-setup-failed-reverting-configuration-issue/m-p/598800#M2486</guid>
      <dc:creator>jmatanane</dc:creator>
      <dc:date>2024-09-25T21:37:07Z</dc:date>
    </item>
    <item>
      <title>Re: Reason: TCP channel setup failed, reverting configuration issue.</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/reason-tcp-channel-setup-failed-reverting-configuration-issue/m-p/1229978#M2890</link>
      <description>&lt;P&gt;I was experiencing the same issue. I'm running 11.1.8 on Panorama and PA-450. I increased teh retry like you suggested, and that did the trick.&lt;BR /&gt;Thank you.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 25 May 2025 06:09:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/reason-tcp-channel-setup-failed-reverting-configuration-issue/m-p/1229978#M2890</guid>
      <dc:creator>jtravlos</dc:creator>
      <dc:date>2025-05-25T06:09:05Z</dc:date>
    </item>
  </channel>
</rss>

