<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Issue using ZTP and a PA-440 in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/issue-using-ztp-and-a-pa-440/m-p/538118#M110513</link>
    <description>&lt;P&gt;sorry to hear your ZTP might need manual intervention. I have seen this before on 10.1.3.&lt;/P&gt;
&lt;P&gt;The fix was to manually set auth key via cli on the FW as the GUI did not accept the auth key from panorama.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;&lt;SPAN&gt;generate the auth keys from panorama when adding FW's&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;use the auth keys from Panorama on the firewall CLI -&amp;nbsp; &amp;nbsp;request authkey set &amp;lt;auth key&amp;gt;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&lt;SPAN&gt;2nd step is only possible on the firewall CLI is this is a bug on version 10.1.3.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;see this knowledge article which you might need to reset communication between FW &amp;lt;&amp;gt; Panorama&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u000000wlJpCAI&amp;amp;lang=en_US%E2%80%A9" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u000000wlJpCAI&amp;amp;lang=en_US%E2%80%A9&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 10 Apr 2023 12:28:25 GMT</pubDate>
    <dc:creator>Y-alwaysMe</dc:creator>
    <dc:date>2023-04-10T12:28:25Z</dc:date>
    <item>
      <title>Issue using ZTP and a PA-440</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/issue-using-ztp-and-a-pa-440/m-p/516256#M107199</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;We are trying to deploy a PA-440 by ZTP. Everything works fine until the connection to Panorama.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;PA-440 receives the Panorama IP adresses from the CSP. It autocommits the configuration.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;After that, the PA-440 is able to connect to Panorama (port TCP 3978) : Handshake TCP is OK, but the connection is closed immediately. Probably because of a problem during the SSL part (certificate issue...).&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We tried in 10.1.3 (the sw version out the box) and in 10.1.6-h6. Panorama is in 10.1.6-h6.&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;In the logs (ms.log on PA-440), we can find these messages :&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;2022-09-26 06:00:39.288 -0700 COMM: connection established. sock=28 remote ip=10.253.0.106 port=3978 local port=44874&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;2022-09-26 06:00:39.288 -0700 cms agent: Pre. send buffer limit=46080. s=28&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;2022-09-26 06:00:39.288 -0700 cms agent: Post. send buffer limit=425984. s=28&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;2022-09-26 06:00:39.288 -0700 Error: cs_load_certs_ex(cs_common.c:654): keyfile not exists&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;2022-09-26 06:00:39.288 -0700 Error: pan_cmsa_tcp_channel_setup(src_panos/cms_agent.c:864): cms agent: cs_load_certs_ex failed&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;2022-09-26 06:00:39.288 -0700 cmsa: client will use default context&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;2022-09-26 06:00:39.288 -0700 Warning: pan_cmsa_tcp_channel_setup(src_panos/cms_agent.c:960): client will not use SNI&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;2022-09-26 06:00:39.306 -0700 COMM: connection established. sock=29 remote ip=10.253.0.107 port=3978 local port=54792&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;2022-09-26 06:00:39.306 -0700 cms agent: Pre. send buffer limit=46080. s=29&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;2022-09-26 06:00:39.306 -0700 cms agent: Post. send buffer limit=425984. s=29&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;2022-09-26 06:00:39.306 -0700 Error: cs_load_certs_ex(cs_common.c:654): keyfile not exists&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;2022-09-26 06:00:39.306 -0700 Error: pan_cmsa_tcp_channel_setup(src_panos/cms_agent.c:864): cms agent: cs_load_certs_ex failed&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;2022-09-26 06:00:39.306 -0700 cmsa: client will use default context&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;2022-09-26 06:00:39.306 -0700 Warning: pan_cmsa_tcp_channel_setup(src_panos/cms_agent.c:960): client will not use SNI&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;2022-09-26 06:00:39.326 -0700 Error: pan_cmsa_tcp_channel_setup(src_panos/cms_agent.c:1180): panorama agent: SSL connect error. sock=28 err=1&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;2022-09-26 06:00:39.342 -0700 Error: pan_cmsa_tcp_channel_setup(src_panos/cms_agent.c:1180): panorama agent: SSL connect error. sock=29 err=1&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Does anyone already have the same issue ? Can someone help me ?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Thanks in advance.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Sébastien&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 28 Sep 2022 16:27:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/issue-using-ztp-and-a-pa-440/m-p/516256#M107199</guid>
      <dc:creator>lemoines</dc:creator>
      <dc:date>2022-09-28T16:27:16Z</dc:date>
    </item>
    <item>
      <title>Re: Issue using ZTP and a PA-440</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/issue-using-ztp-and-a-pa-440/m-p/538118#M110513</link>
      <description>&lt;P&gt;sorry to hear your ZTP might need manual intervention. I have seen this before on 10.1.3.&lt;/P&gt;
&lt;P&gt;The fix was to manually set auth key via cli on the FW as the GUI did not accept the auth key from panorama.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;&lt;SPAN&gt;generate the auth keys from panorama when adding FW's&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;use the auth keys from Panorama on the firewall CLI -&amp;nbsp; &amp;nbsp;request authkey set &amp;lt;auth key&amp;gt;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&lt;SPAN&gt;2nd step is only possible on the firewall CLI is this is a bug on version 10.1.3.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;see this knowledge article which you might need to reset communication between FW &amp;lt;&amp;gt; Panorama&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u000000wlJpCAI&amp;amp;lang=en_US%E2%80%A9" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u000000wlJpCAI&amp;amp;lang=en_US%E2%80%A9&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 10 Apr 2023 12:28:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/issue-using-ztp-and-a-pa-440/m-p/538118#M110513</guid>
      <dc:creator>Y-alwaysMe</dc:creator>
      <dc:date>2023-04-10T12:28:25Z</dc:date>
    </item>
  </channel>
</rss>

