<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: unable to connect to Panorama error &amp;quot;TSL-SESSION-DISCONNECTED&amp;quot; in Panorama Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/panorama-discussions/unable-to-connect-to-panorama-error-quot-tsl-session/m-p/440145#M470</link>
    <description>&lt;P&gt;Thank you for posting the issue&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/179734"&gt;@SubaMuthuram&lt;/a&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Would it be possible to take packet capture from management interface to get more visibility into TLS Handshake? You can use filter: tcpdump filter "port 3978" (&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000CleECAS)" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000CleECAS)&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;On Panorama side, the output from: "show devices all" should for functional registration with predefined certificate return:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Certificate Status:&lt;BR /&gt;Certificate subject Name: &amp;lt;Firewall Serial Number&amp;gt;&lt;BR /&gt;Certificate expiry at: &amp;lt;Predefined Certificate Expiration Day&amp;gt;&lt;BR /&gt;Connected at: &amp;lt;Last Connected Time&amp;gt;&lt;BR /&gt;Custom certificate Used: no&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Could you please confirm what are you seeing on your side?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you and Regards&lt;/P&gt;
&lt;P&gt;Pavel Kucera&lt;/P&gt;</description>
    <pubDate>Mon, 11 Oct 2021 21:58:28 GMT</pubDate>
    <dc:creator>PavelK</dc:creator>
    <dc:date>2021-10-11T21:58:28Z</dc:date>
    <item>
      <title>unable to connect to Panorama error "TSL-SESSION-DISCONNECTED"</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/unable-to-connect-to-panorama-error-quot-tsl-session/m-p/439626#M464</link>
      <description>&lt;P&gt;Hi Team,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I am unable to add my gateway to Panorama, It is showing system logs&amp;nbsp;&lt;SPAN&gt;TSL-SESSION-DISCONNECTED in panorama, &lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;It is connecting and disconnecting every minute. When I supply command show devices in panorama, The predefined certificates not taking, The certificate CN name showing empty.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Please help me.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 08 Oct 2021 08:17:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/unable-to-connect-to-panorama-error-quot-tsl-session/m-p/439626#M464</guid>
      <dc:creator>SubaMuthuram</dc:creator>
      <dc:date>2021-10-08T08:17:29Z</dc:date>
    </item>
    <item>
      <title>Re: unable to connect to Panorama error "TSL-SESSION-DISCONNECTED"</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/unable-to-connect-to-panorama-error-quot-tsl-session/m-p/440145#M470</link>
      <description>&lt;P&gt;Thank you for posting the issue&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/179734"&gt;@SubaMuthuram&lt;/a&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Would it be possible to take packet capture from management interface to get more visibility into TLS Handshake? You can use filter: tcpdump filter "port 3978" (&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000CleECAS)" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000CleECAS)&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;On Panorama side, the output from: "show devices all" should for functional registration with predefined certificate return:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Certificate Status:&lt;BR /&gt;Certificate subject Name: &amp;lt;Firewall Serial Number&amp;gt;&lt;BR /&gt;Certificate expiry at: &amp;lt;Predefined Certificate Expiration Day&amp;gt;&lt;BR /&gt;Connected at: &amp;lt;Last Connected Time&amp;gt;&lt;BR /&gt;Custom certificate Used: no&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Could you please confirm what are you seeing on your side?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you and Regards&lt;/P&gt;
&lt;P&gt;Pavel Kucera&lt;/P&gt;</description>
      <pubDate>Mon, 11 Oct 2021 21:58:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/unable-to-connect-to-panorama-error-quot-tsl-session/m-p/440145#M470</guid>
      <dc:creator>PavelK</dc:creator>
      <dc:date>2021-10-11T21:58:28Z</dc:date>
    </item>
    <item>
      <title>Re: unable to connect to Panorama error "TSL-SESSION-DISCONNECTED"</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/unable-to-connect-to-panorama-error-quot-tsl-session/m-p/440167#M471</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/192693"&gt;@PavelK&lt;/a&gt;&amp;nbsp;, thanks for the deatails, The Frewall model is PA-220-ZTP, Is there any diffrent procedur add ZTP firewalls to Panorama.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The predefined certificate status is not showing in Panorama, Also in the firewall show panorama-certificate comment showing empty.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Oct 2021 01:27:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/unable-to-connect-to-panorama-error-quot-tsl-session/m-p/440167#M471</guid>
      <dc:creator>SubaMuthuram</dc:creator>
      <dc:date>2021-10-12T01:27:42Z</dc:date>
    </item>
    <item>
      <title>Re: unable to connect to Panorama error "TSL-SESSION-DISCONNECTED"</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/unable-to-connect-to-panorama-error-quot-tsl-session/m-p/440171#M472</link>
      <description>&lt;P&gt;Thank you for quick reply&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/179734"&gt;@SubaMuthuram&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I see. For ZTP, there is different procedure:&amp;nbsp;&lt;A href="https://docs.paloaltonetworks.com/panorama/10-0/panorama-admin/manage-firewalls/set-up-zero-touch-provisioning/add-ztp-firewalls-to-panorama/add-a-ztp-firewall-to-panorama.html#id182211ac-a31c-4122-a11f-19450ec9ca4e" target="_blank"&gt;https://docs.paloaltonetworks.com/panorama/10-0/panorama-admin/manage-firewalls/set-up-zero-touch-provisioning/add-ztp-firewalls-to-panorama/add-a-ztp-firewall-to-panorama.html#id182211ac-a31c-4122-a11f-19450ec9ca4e&lt;/A&gt;&amp;nbsp;Have you followed this manual?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Kind Regards&lt;/P&gt;
&lt;P&gt;Pavel&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Oct 2021 02:06:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/unable-to-connect-to-panorama-error-quot-tsl-session/m-p/440171#M472</guid>
      <dc:creator>PavelK</dc:creator>
      <dc:date>2021-10-12T02:06:17Z</dc:date>
    </item>
    <item>
      <title>Re: unable to connect to Panorama error "TSL-SESSION-DISCONNECTED"</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/unable-to-connect-to-panorama-error-quot-tsl-session/m-p/557657#M1842</link>
      <description>&lt;P&gt;Hi PavelK,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="AkashThangavel_0-1694584327460.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/53663i53600C02C549F4F0/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="AkashThangavel_0-1694584327460.png" alt="AkashThangavel_0-1694584327460.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Connection is not established between the Panorama and PA-445 device.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="AkashThangavel_1-1694584389867.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/53664i682D3EA4001F42F6/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="AkashThangavel_1-1694584389867.png" alt="AkashThangavel_1-1694584389867.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;admin@Panorama&amp;gt; tcpdump filter "port 3978"&lt;BR /&gt;Press Ctrl-C to stop capturing&lt;/P&gt;
&lt;P&gt;dropped privs to tcpdump&lt;BR /&gt;tcpdump: listening on eth0, link-type EN10MB (Ethernet), capture size 262144 bytes&lt;BR /&gt;^C171 packets captured&lt;BR /&gt;173 packets received by filter&lt;BR /&gt;0 packets dropped by kernel&lt;BR /&gt;admin@Panorama&amp;gt; view-pcap mgmt-pcap mgmt.pcap&lt;BR /&gt;reading from file /opt/pan/.debug/mgmtpcap/mgmt.pcap, link-type EN10MB (Ethernet)&lt;BR /&gt;11:13:50.460705 IP 192.168.0.234.35266 &amp;gt; 192.168.0.209.pan-panorama: Flags [P.], seq 2147872072:2147872113, ack 1423784632, win 1424, options [nop,nop,TS val 816080192 ecr 1424438131], length 41&lt;BR /&gt;11:13:50.461558 IP 192.168.0.209.pan-panorama &amp;gt; 192.168.0.234.35266: Flags [P.], seq 1:42, ack 41, win 2561, options [nop,nop,TS val 1424444132 ecr 816080192], length 41&lt;BR /&gt;11:13:50.462033 IP 192.168.0.234.35266 &amp;gt; 192.168.0.209.pan-panorama: Flags [.], ack 42, win 1424, options [nop,nop,TS val 816080193 ecr 1424444132], length 0&lt;BR /&gt;11:13:50.736827 IP 192.168.0.234.35402 &amp;gt; 192.168.0.209.pan-panorama: Flags [P.], seq 1434786217:1434786286, ack 3262034349, win 387, options [nop,nop,TS val 816080468 ecr 1424438407], length 69&lt;BR /&gt;11:13:50.737330 IP 192.168.0.209.pan-panorama &amp;gt; 192.168.0.234.35402: Flags [P.], seq 1:70, ack 69, win 252, options [nop,nop,TS val 1424444407 ecr 816080468], length 69&lt;BR /&gt;11:13:50.737790 IP 192.168.0.234.35402 &amp;gt; 192.168.0.209.pan-panorama: Flags [.], ack 70, win 387, options [nop,nop,TS val 816080469 ecr 1424444407], length 0&lt;BR /&gt;11:13:50.863234 IP 192.168.0.235.54942 &amp;gt; 192.168.0.209.pan-panorama: Flags [P.], seq 309000155:309000189, ack 2612794819, win 410, options [nop,nop,TS val 1522304549 ecr 3195316293], length 34&lt;BR /&gt;11:13:50.863830 IP 192.168.0.209.pan-panorama &amp;gt; 192.168.0.235.54942: Flags [P.], seq 1:35, ack 34, win 243, options [nop,nop,TS val 3195322293 ecr 1522304549], length 34&lt;BR /&gt;11:13:50.864256 IP 192.168.0.235.54942 &amp;gt; 192.168.0.209.pan-panorama: Flags [.], ack 35, win 410, options [nop,nop,TS val 1522304550 ecr 3195322293], length 0&lt;BR /&gt;11:13:56.460708 IP 192.168.0.234.35266 &amp;gt; 192.168.0.209.pan-panorama: Flags [P.], seq 41:82, ack 42, win 1424, options [nop,nop,TS val 816086192 ecr 1424444132], length 41&lt;BR /&gt;11:13:56.461296 IP 192.168.0.209.pan-panorama &amp;gt; 192.168.0.234.35266: Flags [P.], seq 42:83, ack 82, win 2561, options [nop,nop,TS val 1424450131 ecr 816086192], length 41&lt;BR /&gt;11:13:56.461770 IP 192.168.0.234.35266 &amp;gt; 192.168.0.209.pan-panorama: Flags [.], ack 83, win 1424, options [nop,nop,TS val 816086193 ecr 1424450131], length 0&lt;BR /&gt;11:13:56.736761 IP 192.168.0.234.35402 &amp;gt; 192.168.0.209.pan-panorama: Flags [P.], seq 69:138, ack 70, win 387, options [nop,nop,TS val 816086468 ecr 1424444407], length 69&lt;BR /&gt;11:13:56.737334 IP 192.168.0.209.pan-panorama &amp;gt; 192.168.0.234.35402: Flags [P.], seq 70:139, ack 138, win 252, options [nop,nop,TS val 1424450407 ecr 816086468], length 69&lt;BR /&gt;11:13:56.737795 IP 192.168.0.234.35402 &amp;gt; 192.168.0.209.pan-panorama: Flags [.], ack 139, win 387, options [nop,nop,TS val 816086469 ecr 1424450407], length 0&lt;BR /&gt;11:13:56.863315 IP 192.168.0.235.54942 &amp;gt; 192.168.0.209.pan-panorama: Flags [P.], seq 34:68, ack 35, win 410, options [nop,nop,TS val 1522310549 ecr 3195322293], length 34&lt;BR /&gt;11:13:56.863799 IP 192.168.0.209.pan-panorama &amp;gt; 192.168.0.235.54942: Flags [P.], seq 35:69, ack 68, win 243, options [nop,nop,TS val 3195328293 ecr 1522310549], length 34&lt;BR /&gt;11:13:56.864331 IP 192.168.0.235.54942 &amp;gt; 192.168.0.209.pan-panorama: Flags [.], ack 69, win 410, options [nop,nop,TS val 1522310550 ecr 3195328293], length 0&lt;BR /&gt;11:14:02.460794 IP 192.168.0.234.35266 &amp;gt; 192.168.0.209.pan-panorama: Flags [P.], seq 82:123, ack 83, win 1424, options [nop,nop,TS val 816092192 ecr 1424450131], length 41&lt;BR /&gt;11:14:02.461931 IP 192.168.0.209.pan-panorama &amp;gt; 192.168.0.234.35266: Flags [P.], seq 83:124, ack 123, win 2561, options [nop,nop,TS val 1424456132 ecr 816092192], length 41&lt;BR /&gt;11:14:02.462591 IP 192.168.0.234.35266 &amp;gt; 192.168.0.209.pan-panorama: Flags [.], ack 124, win 1424, options [nop,nop,TS val 816092194 ecr 1424456132], length 0&lt;BR /&gt;11:14:02.736781 IP 192.168.0.234.35402 &amp;gt; 192.168.0.209.pan-panorama: Flags [P.], seq 138:207, ack 139, win 387, options [nop,nop,TS val 816092468 ecr 1424450407], length 69&lt;BR /&gt;11:14:02.737180 IP 192.168.0.209.pan-panorama &amp;gt; 192.168.0.234.35402: Flags [P.], seq 139:208, ack 207, win 252, options [nop,nop,TS val 1424456407 ecr 816092468], length 69&lt;BR /&gt;11:14:02.737602 IP 192.168.0.234.35402 &amp;gt; 192.168.0.209.pan-panorama: Flags [.], ack 208, win 387, options [nop,nop,TS val 816092469 ecr 1424456407], length 0&lt;BR /&gt;11:14:02.863588 IP 192.168.0.235.54942 &amp;gt; 192.168.0.209.pan-panorama: Flags [P.], seq 68:102, ack 69, win 410, options [nop,nop,TS val 1522316549 ecr 3195328293], length 34&lt;BR /&gt;11:14:02.864166 IP 192.168.0.209.pan-panorama &amp;gt; 192.168.0.235.54942: Flags [P.], seq 69:103, ack 102, win 243, options [nop,nop,TS val 3195334293 ecr 1522316549], length 34&lt;BR /&gt;11:14:02.864638 IP 192.168.0.235.54942 &amp;gt; 192.168.0.209.pan-panorama: Flags [.], ack 103, win 410, options [nop,nop,TS val 1522316551 ecr 3195334293], length 0&lt;BR /&gt;11:14:08.460730 IP 192.168.0.234.35266 &amp;gt; 192.168.0.209.pan-panorama: Flags [P.], seq 123:164, ack 124, win 1424, options [nop,nop,TS val 816098192 ecr 1424456132], length 41&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;regards,&lt;/P&gt;
&lt;P&gt;Akash Thangavel&lt;/P&gt;
&lt;P&gt;Network Security Engineer&lt;/P&gt;</description>
      <pubDate>Wed, 13 Sep 2023 05:56:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/unable-to-connect-to-panorama-error-quot-tsl-session/m-p/557657#M1842</guid>
      <dc:creator>AkashThangavel</dc:creator>
      <dc:date>2023-09-13T05:56:19Z</dc:date>
    </item>
  </channel>
</rss>

