<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SD-WAN: ION2000 issue with getting registered with the portal in Prisma SD-WAN Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/prisma-sd-wan-discussions/sd-wan-ion2000-issue-with-getting-registered-with-the-portal/m-p/457643#M10</link>
    <description>&lt;P&gt;Hi Pavel,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please see requested output below.&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;Ajit&lt;/P&gt;
&lt;P&gt;==&lt;/P&gt;
&lt;P&gt;ion toolkit# dump interface config controller &lt;BR /&gt;Interface : controller &lt;BR /&gt;Description : &lt;BR /&gt;ID : 10 &lt;BR /&gt;Type : port&lt;BR /&gt;Admin State : up&lt;BR /&gt;Alarms : enabled&lt;BR /&gt;NetworkContextID: &lt;BR /&gt;Scope : &lt;BR /&gt;MTU : 1500&lt;BR /&gt;IP : dhcp&lt;/P&gt;
&lt;P&gt;ion toolkit# dump controller status&lt;BR /&gt;Controller Connection : Partially Connected&lt;BR /&gt;Number of Active Connections : 1&lt;BR /&gt;--------------------------------------------------------------------------------&lt;BR /&gt;tcp 0 0 10.0.0.65:56041 52.8.25.40:443 ESTABLISHED&lt;BR /&gt;--------------------------------------------------------------------------------&lt;BR /&gt;ion toolkit#&lt;/P&gt;</description>
    <pubDate>Sat, 08 Jan 2022 23:40:41 GMT</pubDate>
    <dc:creator>AjitKumar</dc:creator>
    <dc:date>2022-01-08T23:40:41Z</dc:date>
    <item>
      <title>SD-WAN: ION2000 issue with getting registered with the portal</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-sd-wan-discussions/sd-wan-ion2000-issue-with-getting-registered-with-the-portal/m-p/457243#M8</link>
      <description>&lt;P&gt;I have a brand new ION2000 that is connected to Internet however it does not show up under unclaimed devices on the SD-WAN port.&lt;/P&gt;
&lt;P&gt;Can you please help.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;Ajit Kumar&lt;/P&gt;
&lt;P&gt;NBC Universal&lt;/P&gt;
&lt;P&gt;Sr Network Engineer&lt;/P&gt;</description>
      <pubDate>Thu, 06 Jan 2022 15:19:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-sd-wan-discussions/sd-wan-ion2000-issue-with-getting-registered-with-the-portal/m-p/457243#M8</guid>
      <dc:creator>AjitKumar</dc:creator>
      <dc:date>2022-01-06T15:19:06Z</dc:date>
    </item>
    <item>
      <title>Re: SD-WAN: ION2000 issue with getting registered with the portal</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-sd-wan-discussions/sd-wan-ion2000-issue-with-getting-registered-with-the-portal/m-p/457376#M9</link>
      <description>&lt;P&gt;Thank you for the post&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/73105"&gt;@AjitKumar&lt;/a&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;ION appliance will register to portal via "controller 1" interface. Could you make sure that this interface is up, has configured DNS and can go to internet (only TCP 443 is enough for registration). Could you run below 2 commands to confirm status?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;dump interface config interface=controller1&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;dump controller status&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Kind Regards&lt;/P&gt;
&lt;P&gt;Pavel&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 06 Jan 2022 21:37:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-sd-wan-discussions/sd-wan-ion2000-issue-with-getting-registered-with-the-portal/m-p/457376#M9</guid>
      <dc:creator>PavelK</dc:creator>
      <dc:date>2022-01-06T21:37:51Z</dc:date>
    </item>
    <item>
      <title>Re: SD-WAN: ION2000 issue with getting registered with the portal</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-sd-wan-discussions/sd-wan-ion2000-issue-with-getting-registered-with-the-portal/m-p/457643#M10</link>
      <description>&lt;P&gt;Hi Pavel,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please see requested output below.&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;Ajit&lt;/P&gt;
&lt;P&gt;==&lt;/P&gt;
&lt;P&gt;ion toolkit# dump interface config controller &lt;BR /&gt;Interface : controller &lt;BR /&gt;Description : &lt;BR /&gt;ID : 10 &lt;BR /&gt;Type : port&lt;BR /&gt;Admin State : up&lt;BR /&gt;Alarms : enabled&lt;BR /&gt;NetworkContextID: &lt;BR /&gt;Scope : &lt;BR /&gt;MTU : 1500&lt;BR /&gt;IP : dhcp&lt;/P&gt;
&lt;P&gt;ion toolkit# dump controller status&lt;BR /&gt;Controller Connection : Partially Connected&lt;BR /&gt;Number of Active Connections : 1&lt;BR /&gt;--------------------------------------------------------------------------------&lt;BR /&gt;tcp 0 0 10.0.0.65:56041 52.8.25.40:443 ESTABLISHED&lt;BR /&gt;--------------------------------------------------------------------------------&lt;BR /&gt;ion toolkit#&lt;/P&gt;</description>
      <pubDate>Sat, 08 Jan 2022 23:40:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-sd-wan-discussions/sd-wan-ion2000-issue-with-getting-registered-with-the-portal/m-p/457643#M10</guid>
      <dc:creator>AjitKumar</dc:creator>
      <dc:date>2022-01-08T23:40:41Z</dc:date>
    </item>
    <item>
      <title>Re: SD-WAN: ION2000 issue with getting registered with the portal</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-sd-wan-discussions/sd-wan-ion2000-issue-with-getting-registered-with-the-portal/m-p/457655#M11</link>
      <description>&lt;P&gt;Thank you for reply&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/73105"&gt;@AjitKumar&lt;/a&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;From the output of: "dump interface config controller" it looks like that ION is connected to portal.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Could you run below debug to to confirm that all test are passed:&lt;/P&gt;
&lt;DIV&gt;&lt;STRONG&gt;debug controller reachability controller1&lt;/STRONG&gt;&lt;/DIV&gt;
&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV&gt;Kind Regards&lt;/DIV&gt;
&lt;DIV&gt;Pavel&lt;/DIV&gt;
&lt;P&gt;&lt;LI-WRAPPER&gt;&lt;/LI-WRAPPER&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 09 Jan 2022 07:05:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-sd-wan-discussions/sd-wan-ion2000-issue-with-getting-registered-with-the-portal/m-p/457655#M11</guid>
      <dc:creator>PavelK</dc:creator>
      <dc:date>2022-01-09T07:05:41Z</dc:date>
    </item>
    <item>
      <title>Re: SD-WAN: ION2000 issue with getting registered with the portal</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-sd-wan-discussions/sd-wan-ion2000-issue-with-getting-registered-with-the-portal/m-p/457706#M12</link>
      <description>&lt;P&gt;Hi Paval,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please see below the output as per your request:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;ion toolkit# debug controller reachability controller &lt;BR /&gt;TPM-tcsd running fine&lt;BR /&gt;cic/mic id not in keys-list&lt;BR /&gt;ion toolkit#&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;Ajit&lt;/P&gt;</description>
      <pubDate>Mon, 10 Jan 2022 00:42:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-sd-wan-discussions/sd-wan-ion2000-issue-with-getting-registered-with-the-portal/m-p/457706#M12</guid>
      <dc:creator>AjitKumar</dc:creator>
      <dc:date>2022-01-10T00:42:22Z</dc:date>
    </item>
    <item>
      <title>Re: SD-WAN: ION2000 issue with getting registered with the portal</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-sd-wan-discussions/sd-wan-ion2000-issue-with-getting-registered-with-the-portal/m-p/457776#M13</link>
      <description>&lt;P&gt;Thank you for reply&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/73105"&gt;@AjitKumar&lt;/a&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Based on debug output you provided, it looks like that the MIC (Manufacturer Installed Certificate) is missing/invalid. During the initial registration, the CloudGenix controller validates the ION's MIC, which is stored in the TPM. This is however failing. This is likely reason why you can't see this ION under unclaimed devices in portal. At this point, I would reach Palo Alto support. I do not believe this is something you can fix by your self.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Kind Regards&lt;/P&gt;
&lt;P&gt;Pavel&lt;/P&gt;</description>
      <pubDate>Mon, 10 Jan 2022 13:43:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-sd-wan-discussions/sd-wan-ion2000-issue-with-getting-registered-with-the-portal/m-p/457776#M13</guid>
      <dc:creator>PavelK</dc:creator>
      <dc:date>2022-01-10T13:43:37Z</dc:date>
    </item>
  </channel>
</rss>

