<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Panorama connectivity check failed for xxxx.  Reason: TCP channel setup failed, reverting configuration in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/panorama-connectivity-check-failed-for-xxxx-reason-tcp-channel/m-p/558846#M113357</link>
    <description>&lt;P&gt;- We ran into an issue where the commits from Panorama were failing with error:&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;SPAN class="ui-provider bcx bcy bcz bda bdb bdc bdd bde bdf bdg bdh bdi bdj bdk bdl bdm bdn bdo bdp bdq bdr bds bdt bdu bdv bdw bdx bdy bdz bea beb bec bed bee bef"&gt;• . Performing panorama connectivity check (attempt 1 of 1)&lt;BR /&gt;• . &lt;STRONG&gt;Panorama connectivity check failed&lt;/STRONG&gt; for xxxx. &lt;STRONG&gt;Reason: TCP channel setup failed, reverting configuration&lt;/STRONG&gt;&lt;BR /&gt;• . Configuration reverted successfully&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;- We checked&amp;nbsp;&lt;SPAN&gt;No validation errors while the commit failed&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;- run show panorama-status on the managed firewall&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;gt; show panorama-status&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Panorama Server 1 :&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://panorama01.rush-enterprises.com/" target="_blank" rel="noopener"&gt;xxxx&lt;/A&gt;&lt;BR /&gt;&lt;SPAN&gt;Connected : yes&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;HA state : Unknown&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;- Check if Pings between the Firewalls and Panorama are working&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;gt; ping host x.x.x.x&amp;nbsp; - 100 success&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;- Check if Netstat output on the Firewalls show connnections are Established to the Panorama on port 3978.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;gt; show netstat all yes numeric-hosts yes numeric-ports yes&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;tcp&amp;nbsp; x.x.x.x:3978 ESTABLISHED&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;- Connectivity looks fine, tried restarting the management server process&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;gt; debug software restart process management-server&lt;/SPAN&gt;&lt;BR /&gt;- We tried to add the ip address instead of the hostname - but it would still fail&lt;BR /&gt;&lt;SPAN&gt;- We tried to push the Device-group for the other cluster as well and it fails with the same reason&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;- We see show system resources – pointing at 3 zombie processes in the panorama&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;- We see system files are present&amp;nbsp;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;- Analyzing the TSF uploaded – we see&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;2 (2023-09-19 11:07:19) – Critical System(java) - An Out of Memory condition occured and restarted the process&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Sep 19 11:04:43 CMS init: Id "s0" respawning too fast: disabled for 5 minutes&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Sep 19 11:07:18 CMS klogd: conn12 invoked oom-killer: gfp_mask=0x201da, order=0, oom_score_adj=0&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Sep 19 11:07:19 CMS klogd: Out of memory: Kill process 3399 (java) score 504 or sacrifice child&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Sep 19 11:07:19 CMS klogd: Killed process 3399 (java) total-vm:686690928kB, anon-rss:8422608kB, file-rss:0kB&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;We also see&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;2 (2023-09-13 23:31:25)- Critical System (nodejs ) – Process Restarts - nodejs restarted unexpectedly however no known issue was identified, and we see the java core files which explains the restarts.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;- Reboot didn't make a change, we still saw the OOM errors&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;- Lastly also upgraded the Pano to : 10.1.10-h2 but the issue persists&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 20 Sep 2023 17:29:36 GMT</pubDate>
    <dc:creator>Param_Upadhyay</dc:creator>
    <dc:date>2023-09-20T17:29:36Z</dc:date>
    <item>
      <title>Panorama connectivity check failed for xxxx.  Reason: TCP channel setup failed, reverting configuration</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/panorama-connectivity-check-failed-for-xxxx-reason-tcp-channel/m-p/558846#M113357</link>
      <description>&lt;P&gt;- We ran into an issue where the commits from Panorama were failing with error:&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;SPAN class="ui-provider bcx bcy bcz bda bdb bdc bdd bde bdf bdg bdh bdi bdj bdk bdl bdm bdn bdo bdp bdq bdr bds bdt bdu bdv bdw bdx bdy bdz bea beb bec bed bee bef"&gt;• . Performing panorama connectivity check (attempt 1 of 1)&lt;BR /&gt;• . &lt;STRONG&gt;Panorama connectivity check failed&lt;/STRONG&gt; for xxxx. &lt;STRONG&gt;Reason: TCP channel setup failed, reverting configuration&lt;/STRONG&gt;&lt;BR /&gt;• . Configuration reverted successfully&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;- We checked&amp;nbsp;&lt;SPAN&gt;No validation errors while the commit failed&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;- run show panorama-status on the managed firewall&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;gt; show panorama-status&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Panorama Server 1 :&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://panorama01.rush-enterprises.com/" target="_blank" rel="noopener"&gt;xxxx&lt;/A&gt;&lt;BR /&gt;&lt;SPAN&gt;Connected : yes&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;HA state : Unknown&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;- Check if Pings between the Firewalls and Panorama are working&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;gt; ping host x.x.x.x&amp;nbsp; - 100 success&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;- Check if Netstat output on the Firewalls show connnections are Established to the Panorama on port 3978.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;gt; show netstat all yes numeric-hosts yes numeric-ports yes&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;tcp&amp;nbsp; x.x.x.x:3978 ESTABLISHED&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;- Connectivity looks fine, tried restarting the management server process&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;gt; debug software restart process management-server&lt;/SPAN&gt;&lt;BR /&gt;- We tried to add the ip address instead of the hostname - but it would still fail&lt;BR /&gt;&lt;SPAN&gt;- We tried to push the Device-group for the other cluster as well and it fails with the same reason&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;- We see show system resources – pointing at 3 zombie processes in the panorama&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;- We see system files are present&amp;nbsp;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;- Analyzing the TSF uploaded – we see&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;2 (2023-09-19 11:07:19) – Critical System(java) - An Out of Memory condition occured and restarted the process&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Sep 19 11:04:43 CMS init: Id "s0" respawning too fast: disabled for 5 minutes&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Sep 19 11:07:18 CMS klogd: conn12 invoked oom-killer: gfp_mask=0x201da, order=0, oom_score_adj=0&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Sep 19 11:07:19 CMS klogd: Out of memory: Kill process 3399 (java) score 504 or sacrifice child&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Sep 19 11:07:19 CMS klogd: Killed process 3399 (java) total-vm:686690928kB, anon-rss:8422608kB, file-rss:0kB&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;We also see&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;2 (2023-09-13 23:31:25)- Critical System (nodejs ) – Process Restarts - nodejs restarted unexpectedly however no known issue was identified, and we see the java core files which explains the restarts.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;- Reboot didn't make a change, we still saw the OOM errors&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;- Lastly also upgraded the Pano to : 10.1.10-h2 but the issue persists&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 20 Sep 2023 17:29:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/panorama-connectivity-check-failed-for-xxxx-reason-tcp-channel/m-p/558846#M113357</guid>
      <dc:creator>Param_Upadhyay</dc:creator>
      <dc:date>2023-09-20T17:29:36Z</dc:date>
    </item>
    <item>
      <title>Re: Panorama connectivity check failed for xxxx.  Reason: TCP channel setup failed, reverting configuration</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/panorama-connectivity-check-failed-for-xxxx-reason-tcp-channel/m-p/558847#M113358</link>
      <description>&lt;P&gt;We raised a TAC case and they stated there is an internal investigation still going on this.&lt;/P&gt;
&lt;P&gt;Resolution- increase the&amp;nbsp;&lt;STRONG&gt;&lt;SPAN&gt;Number of attempts to check for Panorama connectivity &lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN&gt;to &lt;STRONG&gt;5&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;DIV&gt;
&lt;P&gt;.&lt;/P&gt;
&lt;/DIV&gt;
&lt;P&gt;&lt;LI-WRAPPER&gt;&lt;/LI-WRAPPER&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 20 Sep 2023 17:32:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/panorama-connectivity-check-failed-for-xxxx-reason-tcp-channel/m-p/558847#M113358</guid>
      <dc:creator>Param_Upadhyay</dc:creator>
      <dc:date>2023-09-20T17:32:18Z</dc:date>
    </item>
  </channel>
</rss>

