Local Log collector Runtime Status showing "Disconnected"

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Local Log collector Runtime Status showing "Disconnected"

L2 Linker

Hi Mates,

 

I want to know why Runtime status is disconnected.

Error - Log collector XXXX failed to connect to XXXXX-inter-lc in the ring

 

We are using Panorama as a "panorama" and "log-collectors"

Setup is " Active/Passive.

Issue : Managed Log collected Runtime status is showing disconnected and Configuration status is "in-sync" and Health Status is "Green"

 

Active Panorama MS.log

Set SSL SNI as 8.0.0
Error: pan_lcsa_tcp_channel_setup(src_panos/lcs_agent.XXXX): inter-logger-agent # 0/0: SSL connect retry. sslerr=2

 

Passive Panorama ms.log

Error: sni_ssl_servername_cb(src_cms/cms_server.XXXX): PANOS_SNI got, but no custom context configured.

 

Thanks in advance.

3 REPLIES 3

Cyber Elite
Cyber Elite

Hello @Ankit1Singh

 

could you please provide more details?

Was this working before or is it a new setup?

What version of Panorama and PAN-OS are you running?

 

Kind Regards

Pavel 

Help the community: Like helpful comments and mark solutions.

Thanks .

PAN-OS 11.1.2-h2

It was working previously.

The issue started after reboot. And we did mgmt-srver restart but status is still same.

Cyber Elite
Cyber Elite

Hello @Ankit1Singh

 

thank you for reply.

 

The error looks like related SSL handshake. I went through release notes and could not find any known issue corresponding with this error. Since it was functional before, I can't think of anything resulting this error. Are you using custom certificate or default one?

 

At this point I would either try to take a packet capture to see what SSL is possibly causing the issue or open a TAC ticket.

 

Kind Regards

Pavel

Help the community: Like helpful comments and mark solutions.
  • 739 Views
  • 3 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!