<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Panorama shows FW as disconnected after App and Threats Update in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/panorama-shows-fw-as-disconnected-after-app-and-threats-update/m-p/156210#M51275</link>
    <description>&lt;P&gt;We have the same problem.&amp;nbsp; A couple of our firewalls are connected, but we have some that are disconnected.&amp;nbsp; We tried to reboot one of the disconnected firewalls, and it is still disconnected.&amp;nbsp; We do have a case open with Palo Alto, but they haven't helped yet.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Did you find a fix for this?&amp;nbsp; I'm concerned about trying to reboot Panorma again and lose the firewalls that are stil connected.&lt;/P&gt;</description>
    <pubDate>Thu, 11 May 2017 13:20:14 GMT</pubDate>
    <dc:creator>dfeddersen</dc:creator>
    <dc:date>2017-05-11T13:20:14Z</dc:date>
    <item>
      <title>Panorama shows FW as disconnected after App and Threats Update</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/panorama-shows-fw-as-disconnected-after-app-and-threats-update/m-p/154840#M50972</link>
      <description>&lt;P&gt;So I got the mail today about the certificate which is about to expire.&lt;/P&gt;&lt;P&gt;I installed App protection 694-4000 on the Panorama as described .&lt;/P&gt;&lt;P&gt;After the reboot I no longer have communication between my 2 PA-2050 boxes and Panorama. The log is no longer updated and it shows the 2 boxes "Device State" as Disconnected.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I currently run 7.0.10 on all devices.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I also installed 694-4000 on the firewall boxes and rebooted them, but it didn't change anything. Reverting to a previous versioun of app definition did not help (which seems clear as the new certificate gets probably not rolled back)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Even a Rollback of the config on the Panorama did not help.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Anyone has an idea what could be wrong?&lt;/P&gt;</description>
      <pubDate>Tue, 02 May 2017 13:58:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/panorama-shows-fw-as-disconnected-after-app-and-threats-update/m-p/154840#M50972</guid>
      <dc:creator>saint-paul</dc:creator>
      <dc:date>2017-05-02T13:58:04Z</dc:date>
    </item>
    <item>
      <title>Re: Panorama shows FW as disconnected after App and Threats Update</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/panorama-shows-fw-as-disconnected-after-app-and-threats-update/m-p/156175#M51265</link>
      <description>&lt;P&gt;Exactly the same problem after content update 694-4000 has been installed&lt;/P&gt;&lt;P&gt;In my case&amp;nbsp;we have 2 PA-5050 boxes, and Panorama,&amp;nbsp;running on&amp;nbsp;software version 7.1.5&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is it possible that the firewalls are not trusting the renewed CA certificate on Panorama?&lt;/P&gt;</description>
      <pubDate>Thu, 11 May 2017 08:05:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/panorama-shows-fw-as-disconnected-after-app-and-threats-update/m-p/156175#M51265</guid>
      <dc:creator>BBogdanovic</dc:creator>
      <dc:date>2017-05-11T08:05:29Z</dc:date>
    </item>
    <item>
      <title>Re: Panorama shows FW as disconnected after App and Threats Update</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/panorama-shows-fw-as-disconnected-after-app-and-threats-update/m-p/156210#M51275</link>
      <description>&lt;P&gt;We have the same problem.&amp;nbsp; A couple of our firewalls are connected, but we have some that are disconnected.&amp;nbsp; We tried to reboot one of the disconnected firewalls, and it is still disconnected.&amp;nbsp; We do have a case open with Palo Alto, but they haven't helped yet.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Did you find a fix for this?&amp;nbsp; I'm concerned about trying to reboot Panorma again and lose the firewalls that are stil connected.&lt;/P&gt;</description>
      <pubDate>Thu, 11 May 2017 13:20:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/panorama-shows-fw-as-disconnected-after-app-and-threats-update/m-p/156210#M51275</guid>
      <dc:creator>dfeddersen</dc:creator>
      <dc:date>2017-05-11T13:20:14Z</dc:date>
    </item>
    <item>
      <title>Re: Panorama shows FW as disconnected after App and Threats Update</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/panorama-shows-fw-as-disconnected-after-app-and-threats-update/m-p/156332#M51321</link>
      <description>&lt;P&gt;We've found the problem. The certificate is indeed the culprit.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;With assistance from Palo Alto we've deleted the pem certiticates (of both the firewalls)&amp;nbsp;from Panorama.&lt;/P&gt;&lt;P&gt;And once a new one was generated (or imported - not sure about this, and i forgot to ask)&amp;nbsp;the firewalls succesfully connected to Panorama again.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The thing is that you need Root access&amp;nbsp;on Panorama from the&amp;nbsp;CLI, which we don't have, so you will need to contact support and they will need to delete the certs.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;</description>
      <pubDate>Fri, 12 May 2017 05:42:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/panorama-shows-fw-as-disconnected-after-app-and-threats-update/m-p/156332#M51321</guid>
      <dc:creator>BBogdanovic</dc:creator>
      <dc:date>2017-05-12T05:42:42Z</dc:date>
    </item>
    <item>
      <title>Re: Panorama shows FW as disconnected after App and Threats Update</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/panorama-shows-fw-as-disconnected-after-app-and-threats-update/m-p/156355#M51325</link>
      <description>&lt;P&gt;Steps support did in order to resolve the issue:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;- You have reported that after the Panorama Certificate update, few of the managed devices are shown as disconnected&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;- From the Panorama CLI the devices are shown as connected&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;- In order to restore the connectivity, we entered the root shell and deleted the certificates of the affected device&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;- After that, we restarted the management server process and confirmed that all devices are shown as connected&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 12 May 2017 09:38:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/panorama-shows-fw-as-disconnected-after-app-and-threats-update/m-p/156355#M51325</guid>
      <dc:creator>TranceforLife</dc:creator>
      <dc:date>2017-05-12T09:38:45Z</dc:date>
    </item>
    <item>
      <title>Re: Panorama shows FW as disconnected after App and Threats Update</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/panorama-shows-fw-as-disconnected-after-app-and-threats-update/m-p/158431#M51839</link>
      <description>&lt;P&gt;I installed App protection 702-4044 today, rebooted panorama and restarted the management process on the firewalls as described in the Paloalto newsletter I got today.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This also solved the problem&lt;/P&gt;</description>
      <pubDate>Fri, 26 May 2017 08:43:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/panorama-shows-fw-as-disconnected-after-app-and-threats-update/m-p/158431#M51839</guid>
      <dc:creator>saint-paul</dc:creator>
      <dc:date>2017-05-26T08:43:08Z</dc:date>
    </item>
  </channel>
</rss>

