<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: TS agent SSL error in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/ts-agent-ssl-error/m-p/485115#M104493</link>
    <description>&lt;P&gt;Hi Pavel,&lt;/P&gt;&lt;P&gt;We are not using a SSL decryption at all, and we use URL filtering but a very specific rules that are not about traffic from FW to terminal server.&lt;/P&gt;&lt;P&gt;Also we are using default service routing (so using management interface)&lt;/P&gt;</description>
    <pubDate>Thu, 05 May 2022 08:09:02 GMT</pubDate>
    <dc:creator>MMerlier</dc:creator>
    <dc:date>2022-05-05T08:09:02Z</dc:date>
    <item>
      <title>TS agent SSL error</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ts-agent-ssl-error/m-p/484804#M104457</link>
      <description>&lt;P&gt;Hello,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I've been trying to add a new TS agent on my firewalls. As there is no redistribution for user-{ip+port} mapping, I want to map the TS agent to 2 FWs. Backend FW is connected correctly, Frontend FW is in error.&lt;/P&gt;&lt;P&gt;I can capture the following between FW and TS agent :&lt;/P&gt;&lt;P&gt;- FW to TS : SYN&lt;/P&gt;&lt;P&gt;- TS to FW : SYN/ACK&amp;nbsp;&lt;/P&gt;&lt;P&gt;- FW to TS : ACK&lt;/P&gt;&lt;P&gt;- FW to TS : RST&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I've got the following error:&lt;/P&gt;&lt;P&gt;show user ts-agent state&lt;/P&gt;&lt;P&gt;not-conn:idle(Error: Failed to Connect to 1.1.1.1(source: 2.2.2.2), SSL error: error:00000000:lib(0):func(0):reason(0)(5) )&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also on TS agent side I've got the following error:&lt;/P&gt;&lt;P&gt;05/04/22 12:33:57[Info 1571]: Client thread 2 with IP 2.2.2.2 is started.&lt;BR /&gt;05/04/22 12:33:57[Error 1946]: SSL 2 accept error: 5-10054!&lt;BR /&gt;05/04/22 12:33:57[Info 1659]: Connection 2.2.2.2/39560 closed.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The thing is that there is no certificate configured for any user ID agent.&lt;/P&gt;&lt;P&gt;I tried to restart user-id process on the FW with no success.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Does someone have an idea ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 04 May 2022 12:25:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ts-agent-ssl-error/m-p/484804#M104457</guid>
      <dc:creator>MMerlier</dc:creator>
      <dc:date>2022-05-04T12:25:05Z</dc:date>
    </item>
    <item>
      <title>Re: TS agent SSL error</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ts-agent-ssl-error/m-p/484868#M104462</link>
      <description>&lt;P&gt;Thank you for the post&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/96479"&gt;@MMerlier&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;is there any URL Filtering / SSL inspection between Firewall and TS Agent? There might be an issue similar what is described in this KB:&amp;nbsp;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClKSCA0" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClKSCA0&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Kind Regards&lt;/P&gt;&lt;P&gt;Pavel&lt;/P&gt;</description>
      <pubDate>Wed, 04 May 2022 13:32:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ts-agent-ssl-error/m-p/484868#M104462</guid>
      <dc:creator>PavelK</dc:creator>
      <dc:date>2022-05-04T13:32:11Z</dc:date>
    </item>
    <item>
      <title>Re: TS agent SSL error</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ts-agent-ssl-error/m-p/485115#M104493</link>
      <description>&lt;P&gt;Hi Pavel,&lt;/P&gt;&lt;P&gt;We are not using a SSL decryption at all, and we use URL filtering but a very specific rules that are not about traffic from FW to terminal server.&lt;/P&gt;&lt;P&gt;Also we are using default service routing (so using management interface)&lt;/P&gt;</description>
      <pubDate>Thu, 05 May 2022 08:09:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ts-agent-ssl-error/m-p/485115#M104493</guid>
      <dc:creator>MMerlier</dc:creator>
      <dc:date>2022-05-05T08:09:02Z</dc:date>
    </item>
    <item>
      <title>Re: TS agent SSL error</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ts-agent-ssl-error/m-p/534341#M109973</link>
      <description>&lt;P&gt;Did you ever get to the root cause of this? I am having the same issue which just started today and no recent changes. Getting the same error with firewalls sending their user id data to panorama.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 14 Mar 2023 11:50:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ts-agent-ssl-error/m-p/534341#M109973</guid>
      <dc:creator>MikeGeo</dc:creator>
      <dc:date>2023-03-14T11:50:04Z</dc:date>
    </item>
    <item>
      <title>Re: TS agent SSL error</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ts-agent-ssl-error/m-p/584149#M116704</link>
      <description>&lt;P&gt;Did you manage to find a solution on this issue?&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 18 Apr 2024 05:17:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ts-agent-ssl-error/m-p/584149#M116704</guid>
      <dc:creator>rcandeloza</dc:creator>
      <dc:date>2024-04-18T05:17:20Z</dc:date>
    </item>
  </channel>
</rss>

