Panorama and Firewall frequent disconnection

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

Panorama and Firewall frequent disconnection

Hi Team,

 

I'm facing issue where firewall and Panorama keeping disconnected every minute. It is getting connected and disconnecting.

 

This happens within a minute, I have checked the reachability is fine between panoraman and firewall and port is open.

 

I'm seeing in system logs TLS session disconnected not sure but again it is connecting.

 

PAN OS 8.1.8

M-100 series appliance

 

This happens will all my managed devices with Panorama, Also important I have some firewall in same network of Panorama which is also having issue.

 

Any help in this issue will be greatful 

 

Firewall issue.JPGPanorama issue.JPG

10 REPLIES 10

L0 Member

Hello,

 

Which model of firewall are you using and what version of PAN-OS are you running on it?

 

Just curious.

 

L7 Applicator

Hi @Venkatesan_radhakrishnan 

 

When did this problem start? Maybe at 1st of september? Do you habe more firewalls but it happens only with one device? Is the cpu load higher than normal on your panorama since this problem startet?

Just in case it is the problem I am aware of try to do a search query in the system logs where you display all logs starting from 08/01/2019 00:00:00 untill 08/31/2019 23:59:59. This query maybe won't show any results but if it is the same problem I had it will take - depending on the amount of logs you normally have per second - something between some minutes and a few hours and evrything will be normal again.

 

Regards,

Remo

HI 

 

Problem is happening for last 2 months its not with only one firewall, all connected firewalls are disconnected and connecting again.

 

CPU load is normal not much high.

 

Regards

Venky

So did it may be start at 1st August?

If you did not already do so, I recommend to open also a TAC case (in addition to asking the community)

L1 Bithead

any resolution to this issue. We are also having same issue on Panorama running 8.1.9 version

L0 Member

I had the same issues with PanOS 8.1.10.

Issue started occurring some hours after upgrade to 8.1.10, and resolved itself without measures taken after a few days.

Multiple hardware types (PA-200 up to PA-5050) were involved, even when the firewall and Panorama were in the same data center.

 

TAC mentioned that it might be related to the upgrade. In case this problem occurs again, this packet captures between firewalls and Panorama should be set up and the ms-log should be viewed.

 

Hope this information will help progress similar cases.

 

We have M100 and Firewalls  running same version 8.1.9  no issues.

We have 5050,5220,3220,3020,850, firewalls no issues.

 

Try to downgrade the PAN OS to 8.1.9 see if this helps.

MP

Help the community: Like helpful comments and mark solutions.

Is there any solution for this issue?, is happening to us using version 8.1.18, migrated to 9.0.12 and right now we are in version 9.1.6 and we have the same issue.

I'm also experiencing the same issue. Version 9.0.9 on a PA-220.
I've check routing and switching and all look good, so I'm starting to look inwards to the PA


D.

@DuvallDav 

 

I am using PA 220 with PAN OS 9.1.10 and having no issues.

I will recommend you using PAN OS 9.1.10

 

Regards

MP

Help the community: Like helpful comments and mark solutions.
  • 12579 Views
  • 10 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!