Managed Devices Unable to Establish Connections to Panorama after Configuring Permitted IP Addresses

Managed Devices Unable to Establish Connections to Panorama after Configuring Permitted IP Addresses

84650
Created On 09/26/18 13:48 PM - Last Modified 07/07/22 04:28 AM


Symptom


  • Firewalls unable to connect to Panorama after Configuring "Permitted IP Addresses" (GUI: Panorama > Setup > Interfaces....)
  • Existing Firewalls display as "not connected" (GUI: Panorama > Managed Devices)

 

 



Environment


  • Any Panorama with Managed Firewalls.
  • Supported PAN-OS.
  • Permitted IP Addresses setting


Cause


  • The Management Interface on Panorama was configured with Permitted IP Addresses.
  • The "permitted IP Address" list did not include the IP addresses of the firewall’s interface from where it is configured to connect to Panorama.
GUI: Panorama > Setup > Interfaces > Management > Management Interface Settings > Permitted IP Addresses

Secondary+box+-+Mgmt+Access+list.jpg

 



Resolution


  1. Go to GUI:  Panorama > Setup > Interfaces > Management > Management Interface Settings.
  2. Under "Permitted IP Settings", add all the management IP of Firewalls.
  3. Alternatively one can add the network range of managed Firewalls as well.
  4. Commit the configuration.
Note:
  • When the "Permitted IP Addresses"  on Panorama is not configured (blank), then any managed firewall can connect to Panorama.
  • If any IP is configured in the settings, then only the configured IP addresses can connect to Panorama.
  • The behavior of "permitted IP address" settings on the Firewall is same as that of Panorama
  • In case of HA(High Availability) configuration, both the active and passive Firewall's management IP must be added to Panorama.

If the issue is not resolved after correcting the configuration, one can do a Packet capture using tcpdump command on Panorama CLI.
> tcpdump filter "port 3978"     >>>> wait for some time and use ctrl+c to stop
> view-pcap mgmt-pcap mgmt.pcap

The display show SYN packets received from devices on port 3978, but no SYN-ACK is sent from Panorama.



Additional Information


Is there a Separate Connection for Forwarding Logs to Panorama?

Troubleshooting Panorama Connectivity

 



Actions
  • Print
  • Copy Link

    https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000Clp2CAC&refURL=http%3A%2F%2Fknowledgebase.paloaltonetworks.com%2FKCSArticleDetail

Choose Language