未能在任何新的 AWS 非默认地区,如香港,开普敦启动

未能在任何新的 AWS 非默认地区,如香港,开普敦启动

8972
Created On 03/12/21 17:39 PM - Last Modified 02/06/25 21:15 PM


Symptom


  • 无法检测部署在 N 。 弗吉尼亚地区和引导 AWS EC2 实例在非默认区域,如香港,开普敦。
  • 当 AWS S3 存储桶移动到同一区域(即香港)时,相同的部署场景是成功的。
mp        pan_vm_plugin.log                  2020-11-30 10:44:15   2020-11-30 10:44:15.781 -0800 vm_install_media INFO: : Platform Identified as AWS
mp        pan_vm_plugin.log                  2020-11-30 10:44:15   2020-11-30 10:44:15.840 -0800 vm_install_media INFO: : AWS cloud_setting called
mp        pan_vm_plugin.log                  2020-11-30 10:44:16   2020-11-30 10:44:16.974 -0800 vm_install_media INFO: : AWS bootstrap_attach called
mp        pan_vm_plugin.log                  2020-11-30 10:44:16   2020-11-30 10:44:16.974 -0800 vm_install_media INFO: : VM bootstrap: AWS
mp        pan_vm_plugin.log                  2020-11-30 10:44:16   2020-11-30 10:44:16.976 -0800 vm_install_media INFO: : AWS get_meta_data called http://169.254.169.254/latest/ user-data
mp        pan_vm_plugin.log                  2020-11-30 10:44:16   2020-11-30 10:44:16.977 -0800 vm_install_media INFO: : AWS get_meta_data succeedeed
mp        pan_vm_plugin.log                  2020-11-30 10:44:16   2020-11-30 10:44:16.977 -0800 vm_install_media INFO: : AWS get_meta_data called http://169.254.169.254/latest/ meta-data/iam/security-credentials
mp        pan_vm_plugin.log                  2020-11-30 10:44:16   2020-11-30 10:44:16.978 -0800 vm_install_media INFO: : AWS get_meta_data succeedeed
mp        pan_vm_plugin.log                  2020-11-30 10:45:17   2020-11-30 10:45:17.556 -0800 vm_install_media INFO: : AWS: unable to list bucket objects
mp        pan_vm_plugin.log                  2020-11-30 10:45:17   2020-11-30 10:45:17.781 -0800 vm_install_media INFO: : vm_mode: 4
mp        pan_vm_plugin.log                  2020-11-30 10:45:17   2020-11-30 10:45:17.866 -0800 vm_install_media INFO: : Platform Identified as AWS
mp        pan_vm_plugin.log                  2020-11-30 10:45:17   2020-11-30 10:45:17.925 -0800 vm_install_media INFO: : AWS cloud_setting called
mp        pan_vm_plugin.log                  2020-11-30 10:45:19   2020-11-30 10:45:19.059 -0800 vm_install_media INFO: : bootstrap_detach Unmount /mnt/install_media
mp        pan_vm_plugin.log                  2020-11-30 10:45:19   2020-11-30 10:45:19.063 -0800 vm_install_media INFO: : Detach failed for mount point /mnt/install_media
mp        pan_vm_plugin.log                  2020-11-30 10:45:19   2020-11-30 10:45:19.066 -0800 vm_install_media INFO: : clean up /tmp/.customdata
mp        pan_vm_plugin.log                  2020-11-30 10:47:24   2020-11-30 10:47:24.786 -0800 vm_license_check INFO: : vm_mode: 4
mp        pan_vm_plugin.log                  2020-11-30 10:47:24   2020-11-30 10:47:24.880 -0800 vm_license_check INFO: : Platform Identified as AWS
mp        pan_vm_plugin.log                  2020-11-30 10:47:24   2020-11-30 10:47:24.971 -0800 vm_license_check INFO: : AWS cloud_setting called
mp        pan_vm_plugin.log                  2020-11-30 10:47:25   2020-11-30 10:47:25.374 -0800 vm_host_init INFO: : vm_mode: 4
  • bts_details
--------------------------------------------------------------------------------
2020-11-30 10:44:15.640 -0800 INFO: Bootstrap log initialized
--------------------------------------------------------------------------------
2020-11-30 10:44:15.640 -0800 INFO: Running command: detect []
2020-11-30 10:44:15.640 -0800 DEBUG: /mnt/install_media: created
2020-11-30 10:45:17.623 -0800 INFO: Failed to mount install media: 1 [] [] 4098
2020-11-30 10:45:17.623 -0800 ERROR: btsErrorNoMedia: No Install media detected.(2)
2020-11-30 10:45:17.623 -0800 DEBUG: Syslogging: /usr/local/bin/pan_elog -u 12 -e 201326619 -s critical -m "No bootstrap media detected." -x
2020-11-30 10:45:17.726 -0800 DEBUG: Adding status: Media Detection Failed No bootstrap media detected.
2020-11-30 10:45:19.130 -0800 ERROR: btsErrorNoMedia: No Install media detected.(2)

 


Environment


  • 平台: VM- 系列 AWS
  • PAN-OS/插件版本:任何
  • 部署:现有


Cause


  • 由于 AWS ap-east-1等较新的区域的限制,我们目前的设计无法从不同区域访问S3存储桶。


Resolution


  • 如果 PA-VM 部署在任何新的非默认区域,如香港,开普敦,引导 AWS 将只工作,如果客户使用本地S3存储桶。 这基本上与 AWS 这些新区域限制与其他区域资源交互的默认行为 AWS 不一格。


Actions
  • Print
  • Copy Link

    https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u0000001UlrCAE&lang=zh_CN&refURL=http%3A%2F%2Fknowledgebase.paloaltonetworks.com%2FKCSArticleDetail

Choose Language