<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: No valid AceMlc2 config: SC 1 (AceMlc2): Config not valid in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/no-valid-acemlc2-config-sc-1-acemlc2-config-not-valid/m-p/598994#M119138</link>
    <description>&lt;P&gt;Hello I had the same problem on the passive PA in my cluster&lt;BR /&gt;licenses ok,&amp;nbsp;&amp;nbsp; "debug software restart process ctd-agent" or firewall restart does not change anything. &lt;BR /&gt;but when I suspended the active one,&amp;nbsp; magic, the problem disappear,&amp;nbsp; confirming that my configuration (network, service route configuration and other) was correct.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;have a nice day&lt;/P&gt;</description>
    <pubDate>Fri, 27 Sep 2024 15:47:15 GMT</pubDate>
    <dc:creator>JoseRegueiro</dc:creator>
    <dc:date>2024-09-27T15:47:15Z</dc:date>
    <item>
      <title>No valid AceMlc2 config: SC 1 (AceMlc2): Config not valid</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/no-valid-acemlc2-config-sc-1-acemlc2-config-not-valid/m-p/598952#M119132</link>
      <description>&lt;P&gt;Hello all,&lt;/P&gt;
&lt;P&gt;I need some help troubleshooting these low severity logs that keep popping up.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This is happening on a PA-3220 which is running 10.2.9.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The output of show ctd-agent status security-client is:&lt;/P&gt;
&lt;P&gt;[snip]&lt;/P&gt;
&lt;P&gt;Security Client AceMlc2(1)&lt;BR /&gt;Current cloud server: ace.hawkeye.services-edge.paloaltonetworks.com:443&lt;BR /&gt;Cloud connection: disconnected&lt;BR /&gt;Config:&lt;BR /&gt;Number of gRPC connections: 2, Number of workers: 6&lt;BR /&gt;Debug level: 2, Insecure connection: false, Cert valid: true, Key valid: true, CA count: 385&lt;BR /&gt;Maximum number of workers: 10&lt;BR /&gt;Maximum number of sessions a worker should process before reconnect: 1024&lt;BR /&gt;Maximum number of messages per worker: 0&lt;BR /&gt;Skip cert verify: false&lt;BR /&gt;Grpc Connection Status:&lt;BR /&gt;State Invalid Config (8), last err SC 1 (AceMlc2): Config not valid&lt;BR /&gt;Pool state: Invalid Config (7)&lt;BR /&gt;last update: 2024-09-27 11:11:24.801152042 +0200 CEST m=+4233846.308952506&lt;BR /&gt;last connection retry: 2024-09-27 11:11:24.801135605 +0200 CEST m=+4233846.308936058&lt;BR /&gt;last pool close: 2024-08-09 11:09:08.896545095 +0200 CEST m=+112.772251674&lt;BR /&gt;isProxy: false&lt;/P&gt;
&lt;P&gt;[/snip]&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I did not find any useful documentation on how to understand what's not working and how should I fix it.&lt;/P&gt;
&lt;P&gt;So far i got that it's about cloud features of Vulnerability Protection but it seems it's not enabled on the software version I am using.&lt;/P&gt;
&lt;P&gt;Any other hint or suggestion is appreciated.&lt;/P&gt;</description>
      <pubDate>Fri, 27 Sep 2024 09:42:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/no-valid-acemlc2-config-sc-1-acemlc2-config-not-valid/m-p/598952#M119132</guid>
      <dc:creator>paolopoz</dc:creator>
      <dc:date>2024-09-27T09:42:20Z</dc:date>
    </item>
    <item>
      <title>Re: No valid AceMlc2 config: SC 1 (AceMlc2): Config not valid</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/no-valid-acemlc2-config-sc-1-acemlc2-config-not-valid/m-p/598994#M119138</link>
      <description>&lt;P&gt;Hello I had the same problem on the passive PA in my cluster&lt;BR /&gt;licenses ok,&amp;nbsp;&amp;nbsp; "debug software restart process ctd-agent" or firewall restart does not change anything. &lt;BR /&gt;but when I suspended the active one,&amp;nbsp; magic, the problem disappear,&amp;nbsp; confirming that my configuration (network, service route configuration and other) was correct.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;have a nice day&lt;/P&gt;</description>
      <pubDate>Fri, 27 Sep 2024 15:47:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/no-valid-acemlc2-config-sc-1-acemlc2-config-not-valid/m-p/598994#M119138</guid>
      <dc:creator>JoseRegueiro</dc:creator>
      <dc:date>2024-09-27T15:47:15Z</dc:date>
    </item>
    <item>
      <title>Re: No valid AceMlc2 config: SC 1 (AceMlc2): Config not valid</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/no-valid-acemlc2-config-sc-1-acemlc2-config-not-valid/m-p/598999#M119139</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/563164049"&gt;@paolopoz&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;If you're looking at a passive firewall that doesn't have an internet connection through the management interface and relies upon a service route this is kind of expected, which is why it's a low severity alert.&lt;/P&gt;</description>
      <pubDate>Fri, 27 Sep 2024 16:06:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/no-valid-acemlc2-config-sc-1-acemlc2-config-not-valid/m-p/598999#M119139</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2024-09-27T16:06:20Z</dc:date>
    </item>
    <item>
      <title>Re: No valid AceMlc2 config: SC 1 (AceMlc2): Config not valid</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/no-valid-acemlc2-config-sc-1-acemlc2-config-not-valid/m-p/599178#M119171</link>
      <description>&lt;P&gt;Thanks &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt; but this is happening on the active firewall.&lt;/P&gt;
&lt;P&gt;All services are running as intended.&lt;/P&gt;
&lt;P&gt;The firewall has access to internet.&lt;/P&gt;</description>
      <pubDate>Tue, 01 Oct 2024 14:01:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/no-valid-acemlc2-config-sc-1-acemlc2-config-not-valid/m-p/599178#M119171</guid>
      <dc:creator>paolopoz</dc:creator>
      <dc:date>2024-10-01T14:01:33Z</dc:date>
    </item>
    <item>
      <title>Re: No valid AceMlc2 config: SC 1 (AceMlc2): Config not valid</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/no-valid-acemlc2-config-sc-1-acemlc2-config-not-valid/m-p/998235#M122535</link>
      <description>&lt;P&gt;I had to open a case to PA to fix this.&lt;/P&gt;
&lt;P&gt;The error was caused by an active but unlicensed feature.&lt;/P&gt;
&lt;P&gt;They disabled the service:&lt;/P&gt;
&lt;P&gt;&lt;FONT face="courier new,courier"&gt;set system setting ctd feature-forward mica disable&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;Then rebooted it:&lt;/P&gt;
&lt;P&gt;&lt;FONT face="courier new,courier"&gt;debug software restart process ctd-agent&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;Hope this help others.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 13 Dec 2024 10:47:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/no-valid-acemlc2-config-sc-1-acemlc2-config-not-valid/m-p/998235#M122535</guid>
      <dc:creator>paolopoz</dc:creator>
      <dc:date>2024-12-13T10:47:51Z</dc:date>
    </item>
  </channel>
</rss>

