- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
03-03-2025 11:01 AM
Hello Team,
We are having an issue connecting palo-alto VM firewalls in AWS to the panorama hosted in AWS as well.
connectivity is successful between the firewall and panorama and we are using management port for this traffic.
we ran below command
show netstat all yes numeric-hosts yes numeric-ports yes | match IP
and found the state established on 3978.
when we read ms.log file, we see as below
SC3: failed to get SNI -0700 Warning: sc3_get_current_sc3(sc3_utils.c:182): SC3: failed to get CCN
as per this seems like secure connection issue, but we performed sc3 reset procedure multiple times and also completely removed and re-added the firewall to panorama, but still not connecting.
Below is the complete error or ms.log file message we are seeing
has any body faced similar issue before where firewall is connecting to panorama in aws after performing all the required steps ?Here is ms/log file message
03-30-2025 02:38 PM
Hello @Jagdeep1
- Could you confirm you followed this procedure: recover-managed-device-connectivity-to-panorama for recovery?
- Could you provide screen shot of logs what happens after log line with "device_registered no"?
- Could you confirm what PAN-OS is running on FW and Panorama?
Kind Regards
Pavel
10-03-2025 04:00 AM
Hello Everyone,
I am also facing similar problem where our VM firewall's are unable to join to on prem Panorama, it suddenly started after sudden reboot of these devices hosted on kvm, any resolution was found to your problem ?
10-03-2025 07:14 AM
Had to Re-deploy the panorama. It solved the issue. Not sure what was wrong with initial instance.
 
					
				
				
			
		
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!

