Failed to establish SSL connection to Panorama Server

cancel
Showing results for 
Search instead for 
Did you mean: 

Failed to establish SSL connection to Panorama Server

L1 Bithead

I upgraded a PA200 from 7.0.5 to 7.1.3 on friday.

After the upgrade, the box show a MGT CPU load average on >80% and is not able to connect to Panorama anymore.

 

The box is rebooted twice adter upgrade to try to fix this. Anyone know a fix?

1 ACCEPTED SOLUTION

Accepted Solutions

L4 Transporter

Is the traffic passing through the dataplane? If that's the case maybe you're the next document can help you out.

https://live.paloaltonetworks.com/t5/PAN-OS-7-1-Articles/PAN-OS-7-1-Policy-behavior-change-applicati...

View solution in original post

4 REPLIES 4

L4 Transporter

Is the traffic passing through the dataplane? If that's the case maybe you're the next document can help you out.

https://live.paloaltonetworks.com/t5/PAN-OS-7-1-Articles/PAN-OS-7-1-Policy-behavior-change-applicati...

View solution in original post

L6 Presenter

Hi,

 

Did you try to access cli and check what process is running high:

 

> show system resources follow

 

Cheers,

Myky

EDIT: Wait.. Let me read the post from glastra1 first! :)

 

I did remove application-default from the interface after some trouble yesterday, that have probably fixed it then..

 

Weird, as application is "any".. It should have let Panorama thought?

panorama uses ssl on a non standard port, the application is also dependent on ssl (this means ssl needs to be allowed also)

 

there could have been a condition where, because there is app-default configured and also a very short security policy, appid was a little too fast and tagged panorama traffic as ssl on a non-default port and rejected it

 

if this persists you should reach out to TAC to have the AppID verified, but this will probably solve itself once you have a slightly larger security policy

Tom Piens
PANgurus
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!