I had a small POC with SD-WAN on PA-410 units and Panorama in management mode.
Once it was done, configuration was deleted, and it acted just as a regular firewall, so I have decided later to remove it at all from Panorama. Just as a regular step removed IP, disabled policy and objects and device and network templates.
Now as I need to test something else I have installed fresh Panorama instance (only difference that it is now in Panorama mode).
Unfortunately FW is not able anymore to connect to Panorama.
Both PA and Panorama OS are 10.1.5-h1 (it was same lastly no change).
What I did so far tried to reinstall Panorama, modify its IP, use same IP as previous instance.
License is active on Panorama, certificates are also ok on both FW and Panorama.
FW can reach Panorama.
For isolating issue there is a top rule on FW that allows ANY > Panorama (no zone) and same in reverse.
Also from logs it states that (on both ends):
lcs agent on serialxxx-log-collection connected
Connectivity on port 3978 works, I can see established sessions.
On Panorama it keeps to be not connected, from FW:
> show panorama-status
Connected : no
Any ideas what I am missing?
... View more