<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>article Firewall Unable to Register to Cortex Data Lake in Prisma Access Articles</title>
    <link>https://live.paloaltonetworks.com/t5/prisma-access-articles/firewall-unable-to-register-to-cortex-data-lake/ta-p/282908</link>
    <description>&lt;DIV class="lia-message-template-symptoms-zone"&gt;
&lt;H2&gt;Symptoms&lt;/H2&gt;
&lt;P&gt;A firewall is unable to register to Cortex Data Lake (CDL) for log forwarding. You might see red lights under the logging status or the firewall fails to connect to the CDL.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;/DIV&gt;
&lt;DIV class="lia-message-template-diagnosis-zone"&gt;
&lt;H2&gt;Diagnosis&lt;/H2&gt;
&lt;OL&gt;
&lt;LI&gt;Make sure FQDN refresh is enabled on the firewall&lt;/LI&gt;
&lt;LI&gt;Able to resolve CDL FQDN&lt;/LI&gt;
&lt;LI&gt;Traffic from the firewall to CDL is not being decrypted&lt;/LI&gt;
&lt;LI&gt;The URLs and ports below are whitelisted for Prisma Access communication. &lt;BR /&gt;&lt;STRONG&gt;NOTE:&lt;/STRONG&gt; &lt;EM&gt;More information can be found at&amp;nbsp;&lt;A title="Set Up Prisma Access | TechDocs | Palo Alto Networks" href="https://docs.paloaltonetworks.com/prisma/prisma-access/prisma-access-panorama-admin/prepare-the-prisma-access-infrastructure/get-started-with-prisma-access-overview" target="_self"&gt;Set Up Prisma Access&lt;/A&gt;.&lt;/EM&gt;
&lt;UL&gt;
&lt;LI class="li"&gt;
&lt;DIV class="p"&gt;Port 444 (for Cortex Data Lake)&lt;/DIV&gt;
&lt;/LI&gt;
&lt;LI class="li"&gt;
&lt;DIV class="p"&gt;api.lc.prod.us.cs.paloaltonetworks.com (for Cortex Data Lake)&lt;/DIV&gt;
&lt;/LI&gt;
&lt;LI class="li"&gt;
&lt;DIV class="p"&gt;api.gpcloudservice.com (for Prisma Access)&lt;/DIV&gt;
&lt;/LI&gt;
&lt;LI class="li"&gt;
&lt;DIV class="p"&gt;api.paloaltonetworks.com (for Prisma Access)&lt;/DIV&gt;
&lt;/LI&gt;
&lt;LI class="li"&gt;
&lt;DIV class="p"&gt;apitrusted.paloaltonetworks.com (for Prisma Access)&lt;/DIV&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;/DIV&gt;
&lt;DIV class="lia-message-template-solution-zone"&gt;
&lt;H2&gt;Solution&lt;/H2&gt;
&lt;P&gt;Try following these steps on the firewall's CLI.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Troubleshooting
&lt;OL&gt;
&lt;LI&gt;&lt;FONT face="courier new,courier"&gt;delete license key &amp;lt;logging_service_key&amp;gt;&lt;/FONT&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;FONT face="courier new,courier"&gt;request logging-service-forwarding certificate delete&lt;/FONT&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;FONT face="courier new,courier"&gt;request logging-service-forwarding certificate fetch&lt;/FONT&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Verification
&lt;OL&gt;
&lt;LI&gt;&lt;FONT face="courier new,courier"&gt;show logging-status&lt;/FONT&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;FONT face="courier new,courier"&gt;debug log-receiver rawlog_fwd_trial stats global show&lt;/FONT&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;FONT face="courier new,courier"&gt;request logging-service-forwarding status&lt;/FONT&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;FONT face="courier new,courier"&gt;request license info&lt;/FONT&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;FONT face="courier new,courier"&gt;show system state | match lcaas&lt;/FONT&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;FONT face="courier new,courier"&gt;show system state | match cust&lt;/FONT&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;FONT face="courier new,courier"&gt;request logging-service-forwarding customerinfo show&lt;/FONT&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;FONT face="courier new,courier"&gt;request logging-service-forwarding certificate info&lt;/FONT&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;FONT face="courier new,courier"&gt;show netstat numeric-hosts yes numeric-ports yes | match 3978&lt;/FONT&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If it does not help, please &lt;A title="Prisma Access Discussions | LIVEcommunity | Palo Alto Networks" href="https://live.paloaltonetworks.com/t5/Prisma-Access-Discussions/bd-p/Prisma_Access_Discussions" target="_self"&gt;Start a Topic in the Prisma Access Discussions&lt;/A&gt; area for community help. You may also&amp;nbsp;open a &lt;A title="Customer Support | Palo Alto Networks " href="https://support.paloaltonetworks.com" target="_self"&gt;TAC Case&lt;/A&gt; for further assistance, and be sure to reference the error and the steps provided. You can reference this document if needed.&lt;/P&gt;
&lt;/DIV&gt;</description>
    <pubDate>Thu, 15 Aug 2019 21:54:18 GMT</pubDate>
    <dc:creator>Sai_Tumuluri</dc:creator>
    <dc:date>2019-08-15T21:54:18Z</dc:date>
    <item>
      <title>Firewall Unable to Register to Cortex Data Lake</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-access-articles/firewall-unable-to-register-to-cortex-data-lake/ta-p/282908</link>
      <description>&lt;P&gt;Is firewall unable to connected Cortex Data Lake (CDL)?&lt;/P&gt;</description>
      <pubDate>Thu, 15 Aug 2019 21:54:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-access-articles/firewall-unable-to-register-to-cortex-data-lake/ta-p/282908</guid>
      <dc:creator>Sai_Tumuluri</dc:creator>
      <dc:date>2019-08-15T21:54:18Z</dc:date>
    </item>
  </channel>
</rss>

