<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Management server failed to send phase 1 to client sslvpn in Panorama Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/panorama-discussions/management-server-failed-to-send-phase-1-to-client-sslvpn/m-p/555637#M1796</link>
    <description>&lt;P&gt;Below logs from firewall might help to identify the issue.&lt;/P&gt;
&lt;P&gt;2023-08-28 00:59:43.454 -0700 [Cache] Load /opt/pancfg/mgmt/content//cache/80101//tdb.cache.ser-1 success&lt;BR /&gt;load cache is successful &lt;BR /&gt;2023-08-28 00:59:43.512 -0700 Get tdb_only from last committed config&lt;BR /&gt;2023-08-28 00:59:43.512 -0700 No Any content change&lt;BR /&gt;2023-08-28 00:59:43.512 -0700 TDB compilation done, return 0&lt;BR /&gt;2023-08-28 01:00:05.601 -0700 Use stored file_type_hash table as tdb-&amp;gt;dlp_file_type_hash is invalid &lt;BR /&gt;2023-08-28 01:00:05.603 -0700 Error: pan_profile_compile_memory(pan_profile_comp.c:7341): Stored file_type_hash table is also in valid entry &lt;BR /&gt;2023-08-28 01:00:06.404 -0700 Config commit phase1 abort&lt;BR /&gt;2023-08-28 01:00:06.404 -0700 tdb compile flag is still up, abort thread wait 1 second&lt;BR /&gt;2023-08-28 01:00:06.416 -0700 Error: cfgagent_modify_callback(pan_cfgagent.c:84): Modify string (sw.mgmt.runtime.clients.device.err) error: USER (1)&lt;BR /&gt;2023-08-28 01:00:07.404 -0700 tdb compile flag is still up, abort thread wait 1 second&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 29 Aug 2023 08:17:03 GMT</pubDate>
    <dc:creator>Ankit1Singh</dc:creator>
    <dc:date>2023-08-29T08:17:03Z</dc:date>
    <item>
      <title>Management server failed to send phase 1 to client sslvpn</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/management-server-failed-to-send-phase-1-to-client-sslvpn/m-p/555531#M1786</link>
      <description>&lt;P&gt;Hi All, Commit is getting failed on only Active unit while pushing it from Panorama.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Commit Failed from Panorama&lt;/P&gt;
&lt;P&gt;Error :&amp;nbsp;Management server failed to send phase 1 to client sslvpn&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Commit is failing only on Active unit while commit is successful on passive unit.&lt;/P&gt;
&lt;P&gt;Device Details:&lt;/P&gt;
&lt;P&gt;Panorama : M-500 PAN-OS : 9.1.8&lt;/P&gt;
&lt;P&gt;Firewall : PA-5060 PAN-OS : 8.1.18&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;From Firewall :&amp;nbsp;&lt;/P&gt;
&lt;P&gt;adm(active)&amp;gt; show management-clients&lt;/P&gt;
&lt;P&gt;Client PRI State Progress&lt;BR /&gt;-------------------------------------------------------------------------&lt;BR /&gt;routed 30 init 0 &lt;BR /&gt;ha_agent 25 init 0 &lt;BR /&gt;device 20 init 0 &lt;BR /&gt;ikemgr 10 init 0 &lt;BR /&gt;keymgr 10 init 0 (op cmds only)&lt;BR /&gt;logrcvr 10 init 0 &lt;BR /&gt;dhcpd 10 init 0 &lt;BR /&gt;varrcvr 10 init 0 &lt;BR /&gt;sslvpn 10 init 0 &lt;BR /&gt;rasmgr 10 init 0 &lt;BR /&gt;useridd 10 init 0 &lt;BR /&gt;satd 10 init 0 &lt;BR /&gt;websrvr 10 init 0 &lt;BR /&gt;sslmgr 10 init 0 &lt;BR /&gt;authd 10 init 0 &lt;BR /&gt;pppoed 10 init 0 &lt;BR /&gt;dnsproxyd 10 init 0 &lt;BR /&gt;cryptod 10 init 0 &lt;BR /&gt;dagger 10 init 0 (op cmds only)&lt;BR /&gt;l2ctrld 10 init 0 &lt;BR /&gt;cord 10 init 0&lt;/P&gt;
&lt;P&gt;Overall status: init. Progress: 0&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;From Panorama:&lt;/P&gt;
&lt;P&gt;adm&amp;gt; show management-clients&lt;/P&gt;
&lt;P&gt;Client PRI State Progress&lt;BR /&gt;-------------------------------------------------------------------------&lt;BR /&gt;ha_agent 25 P2-ok 100 &lt;BR /&gt;sslmgr 10 P2-ok 100 &lt;BR /&gt;authd 10 P2-ok 100 &lt;BR /&gt;cryptod 10 P2-ok 100 &lt;BR /&gt;dagger 10 init 0 (op cmds only)&lt;BR /&gt;cord 10 P2-ok 100 &lt;BR /&gt;logd 10 init 0 (op cmds only)&lt;BR /&gt;reportd 10 init 0 (op cmds only)&lt;BR /&gt;useridd 10 P2-ok 100&lt;/P&gt;
&lt;P&gt;Overall status: P2-ok. Progress: 0&lt;/P&gt;</description>
      <pubDate>Mon, 28 Aug 2023 14:59:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/management-server-failed-to-send-phase-1-to-client-sslvpn/m-p/555531#M1786</guid>
      <dc:creator>Ankit1Singh</dc:creator>
      <dc:date>2023-08-28T14:59:08Z</dc:date>
    </item>
    <item>
      <title>Re: Management server failed to send phase 1 to client sslvpn</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/management-server-failed-to-send-phase-1-to-client-sslvpn/m-p/555587#M1792</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/290696"&gt;@Ankit1Singh&lt;/a&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;to drill down root cause could you check logs from CLI:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV data-pm-slice="1 1 []" data-en-clipboard="true"&gt;&lt;STRONG&gt;&lt;SPAN&gt;Panorama&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN&gt;: tail follow yes mp-log configd.log&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;STRONG&gt;&lt;SPAN&gt;FW&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN&gt;: tail follow yes mp-log devsrv.log&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN&gt;Typically logs from these files can reveal more details than the error displayed in GUI. Also, both Panoramas as well as Firewall have outdated PAN-OS. If there is a chance, I would recommend to upgrade both.&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN&gt;Kind Regards&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN&gt;Pavel&lt;/SPAN&gt;&lt;/DIV&gt;</description>
      <pubDate>Mon, 28 Aug 2023 23:48:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/management-server-failed-to-send-phase-1-to-client-sslvpn/m-p/555587#M1792</guid>
      <dc:creator>PavelK</dc:creator>
      <dc:date>2023-08-28T23:48:33Z</dc:date>
    </item>
    <item>
      <title>Re: Management server failed to send phase 1 to client sslvpn</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/management-server-failed-to-send-phase-1-to-client-sslvpn/m-p/555595#M1793</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/290696"&gt;@Ankit1Singh&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Could you run the CLI command "show system software status | match sslvpn" and confirm the process is running?&amp;nbsp; If not, you can restart the process with the CLI command "debug software restart process sslvpn".&amp;nbsp; Then commit again.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;</description>
      <pubDate>Tue, 29 Aug 2023 00:23:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/management-server-failed-to-send-phase-1-to-client-sslvpn/m-p/555595#M1793</guid>
      <dc:creator>TomYoung</dc:creator>
      <dc:date>2023-08-29T00:23:04Z</dc:date>
    </item>
    <item>
      <title>Re: Management server failed to send phase 1 to client sslvpn</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/management-server-failed-to-send-phase-1-to-client-sslvpn/m-p/555629#M1795</link>
      <description>&lt;P&gt;Thank you TomYoung for the reply.&lt;/P&gt;
&lt;P&gt;Command need to run or Panorama or the managed firewall?&lt;/P&gt;
&lt;P&gt;Also restarting sslvpn process cause any traffic impact?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 29 Aug 2023 08:09:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/management-server-failed-to-send-phase-1-to-client-sslvpn/m-p/555629#M1795</guid>
      <dc:creator>Ankit1Singh</dc:creator>
      <dc:date>2023-08-29T08:09:34Z</dc:date>
    </item>
    <item>
      <title>Re: Management server failed to send phase 1 to client sslvpn</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/management-server-failed-to-send-phase-1-to-client-sslvpn/m-p/555637#M1796</link>
      <description>&lt;P&gt;Below logs from firewall might help to identify the issue.&lt;/P&gt;
&lt;P&gt;2023-08-28 00:59:43.454 -0700 [Cache] Load /opt/pancfg/mgmt/content//cache/80101//tdb.cache.ser-1 success&lt;BR /&gt;load cache is successful &lt;BR /&gt;2023-08-28 00:59:43.512 -0700 Get tdb_only from last committed config&lt;BR /&gt;2023-08-28 00:59:43.512 -0700 No Any content change&lt;BR /&gt;2023-08-28 00:59:43.512 -0700 TDB compilation done, return 0&lt;BR /&gt;2023-08-28 01:00:05.601 -0700 Use stored file_type_hash table as tdb-&amp;gt;dlp_file_type_hash is invalid &lt;BR /&gt;2023-08-28 01:00:05.603 -0700 Error: pan_profile_compile_memory(pan_profile_comp.c:7341): Stored file_type_hash table is also in valid entry &lt;BR /&gt;2023-08-28 01:00:06.404 -0700 Config commit phase1 abort&lt;BR /&gt;2023-08-28 01:00:06.404 -0700 tdb compile flag is still up, abort thread wait 1 second&lt;BR /&gt;2023-08-28 01:00:06.416 -0700 Error: cfgagent_modify_callback(pan_cfgagent.c:84): Modify string (sw.mgmt.runtime.clients.device.err) error: USER (1)&lt;BR /&gt;2023-08-28 01:00:07.404 -0700 tdb compile flag is still up, abort thread wait 1 second&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 29 Aug 2023 08:17:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/management-server-failed-to-send-phase-1-to-client-sslvpn/m-p/555637#M1796</guid>
      <dc:creator>Ankit1Singh</dc:creator>
      <dc:date>2023-08-29T08:17:03Z</dc:date>
    </item>
    <item>
      <title>Re: Management server failed to send phase 1 to client sslvpn</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/management-server-failed-to-send-phase-1-to-client-sslvpn/m-p/555671#M1797</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/290696"&gt;@Ankit1Singh&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please run the commands on the managed NGFW.&amp;nbsp; The commit is failing there.&amp;nbsp; As long as you have not reverted the configuration, the Panorama pushed configuration is still part of the candidate configuration.&amp;nbsp; You can still try to commit it.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;</description>
      <pubDate>Tue, 29 Aug 2023 11:47:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/management-server-failed-to-send-phase-1-to-client-sslvpn/m-p/555671#M1797</guid>
      <dc:creator>TomYoung</dc:creator>
      <dc:date>2023-08-29T11:47:45Z</dc:date>
    </item>
    <item>
      <title>Re: Management server failed to send phase 1 to client sslvpn</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/management-server-failed-to-send-phase-1-to-client-sslvpn/m-p/555717#M1799</link>
      <description>&lt;P&gt;I tried with the mgmt-server restart but still it is failing with the same error.&lt;/P&gt;
&lt;P&gt;-------&lt;SPAN&gt;debug software restart process management-server---------&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;I believe restarting mgmt-server will restart all the process including sslvpn.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;debug software restart process sslvpn ---- will hit be helpful&amp;nbsp;now?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;If I run this command will it impact live traffic?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Thank you for your reply!!!!&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 29 Aug 2023 13:55:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/management-server-failed-to-send-phase-1-to-client-sslvpn/m-p/555717#M1799</guid>
      <dc:creator>Ankit1Singh</dc:creator>
      <dc:date>2023-08-29T13:55:02Z</dc:date>
    </item>
  </channel>
</rss>

