Troubleshooting Panorama Connectivity

Troubleshooting Panorama Connectivity

111604
Created On 09/25/18 19:38 PM - Last Modified 11/22/21 22:29 PM


Environment
  • Palo Alto Firewalls.
  • Panorama.
  • PAN-OS 7.1 and above.


Resolution

Details

Here are some checks that should be made when Panorama is out of sync with one of many managed firewalls, or simply cannot connect to a firewall.

  1. Check IP connectivity between the devices.
  2. Make sure port 3978 is open and available from the device to Panorama.
  3. Make sure that a certificate has been generated or installed on Panorama.
  4. Confirm the serial number configured in Panorama (case sensitive).
  5. If a permitted IP list is configured for the management interface, make sure that Panorama IP is allowed in the list. By default, it will allow all IPs if a list is not specified.
  6. Make sure Panorama is on a version greater than or equal to that of the managed devices. Panorama can manage devices running supported PAN-OS versions of the same or a lower release.
  7. Check MTU settings on the managed device,  as the value may need to be reduced. If a device on the path is fragmenting packets, communication from Managed Device to Panorama will not succeed. Check the MTU settings on intermediate router as well.
  8. Verify that there is not a large time difference between the clock (Date/Time) on Panorama and the clock (Date/Time) on the managed device.

 

 



Attachments
Actions
  • Print
  • Copy Link

    https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClaWCAS&refURL=http%3A%2F%2Fknowledgebase.paloaltonetworks.com%2FKCSArticleDetail

Attachments
Choose Language