- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
Enhanced Security Measures in Place: To ensure a safer experience, we’ve implemented additional, temporary security measures for all users.
03-24-2023 04:19 AM
We have over 80+ firewalls in our environment, all of them of version 10.1.6.-h6 , we are using Kerberos profile in the user-id agent set-up and every server monitor status seems connected. Except for the firewall which is with PAN-OS version 10.2.3.-h4, even after using the same parameters.
getting below error:
Server monitor HOSTNAMEDP(vsys1): connection failed, HTTP code 401, (null)
Kindly suggest us on above condition.
03-29-2023 03:01 AM
Hi @Sujanya ,
That error is too general and requires additional debugging.
I'd make sure the clock is synced under the same NTP server everywhere.
Also enable debug logging:
debug user-id on debug
debug user-id set userid servermonitor
Also capture krb5 and http traffic at the time of the issue
1) kerberos traffic is between fw and kdc server on port 88.
2) http traffic is between fw and server monitor server on port 5985.
You might want to grab all this info + a tech support file and send it over to TAC for analysis.
Kind regards,
-Kiwi.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!