No GUI Access to PA-VM deployed in AWS China

No GUI Access to PA-VM deployed in AWS China

8121
Created On 02/13/19 22:57 PM - Last Modified 12/06/22 13:34 PM


Symptom


  • PA-VM deployment successful in AWS-China
  • Ping and SSH to EIP works fine (NOTE: provided you have Security Groups and NACL configured to allow it ),But Unable to access the GUI. GUI is not displayed.

 

  • Note: AWS China is not a Region like the other we see on AWS console. You have to login to a different AWS console.


Environment


  • AWS China - Beijing 
  • PA VM - 8.0.4 ( On AWS)


Cause


  • The root cause of this issue is not a corrupt AMI or configuration of either AWS or PA-VM
  • The root cause is the "Chinese laws and regulations". 

 



Resolution


  1. To host a website in mainland China you are required to obtain an ICP (Internet Content Provider) Recordal or License.
  2.  Access to  PA-VM is nothing but accessing the public IP (EIP or Public IP of the Management interface)
  •  NOTE: You can obtain an AWS China account without a ICP Recordal/License and use it for anything other than website hosting ports 80, 8080 and 443 as it will be blocked until you provide the required documents.

Reference link: https://www.amazonaws.cn/en/about-aws/china/faqs/#new%20step

  •  Also NOTE: The following error logs of the Instance screen shot or the Instance system logs can be ignored:

"cannot get hvm parameter CONSOLE_EVTCHN (18)" 



Actions
  • Print
  • Copy Link

    https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000CmpbCAC&lang=en_US%E2%80%A9&refURL=http%3A%2F%2Fknowledgebase.paloaltonetworks.com%2FKCSArticleDetail&refURL=http%3A%2F%2Fknowledgebase.paloaltonetworks.com%2FKCSArticleDetail

Choose Language