How we can verify that SC3 registration process is completed?

How we can verify that SC3 registration process is completed?

6066
Created On 04/16/24 02:14 AM - Last Modified 10/31/24 21:07 PM


Question


When sc3 registration process is initiated, how to verify if the sc3 registration process is completed?



Environment


  • Panorama
  • Firewall
  • PAN-OS 10.1 and above


Answer


  1. Once Authkey is configured on the firewall, The Firewall send CSR to Panorama and get Panorama signed certificate. 
  2. To verify if the SC3 registration process is completed, Check if the firewall has the Panorama Signed Certificate.
  3. The Certificate subject Name field displayed on Panorama should match with firewall cert CN (cfg.ms.cc).
  4. The CLI command on Firewall and Panorama are listed below with certificate name highlighted.
Firewall > show system state filter cfg.ms*

cfg.ms.ca: 6d49b9fe-3e9a-49e7-bd12-0e6b0dd0ada7
cfg.ms.cc: 2dd89c4a-54b2-40cb-888e-5b9524c4bc4b

Panorama > show devices connected

Serial                   Hostname        IPv4            IPv6                             Connected
--------------------------------------------------------------------------
012001061717             Lab32-188-PA-820 10.194.32.188   unknown                                yes
Wildfire Real-time Stream Disabled  VPN Disable Mode: no
  Operational Mode: normal
  HA Cluster State: cluster-unknown
  Certificate Status: 
  Certificate subject Name: 2dd89c4a-54b2-40cb-888e-5b9524c4bc4b
  Certificate expiry at: 2024/07/01 08:12:14
  Connected at: 2024/04/02 17:12:45
  Custom certificate Used: no
  Virtual Systems:
    vsys1(vsys1) shared policy md5sum:()
           shared policy version:
  Last masterkey push status: Unknown
  Last masterkey push timestamp:  none
  Express mode: no
 Device cert present : None
 Device cert expiry date : N/A

Total Connected Devices: 1


Actions
  • Print
  • Copy Link

    https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u0000008XnLCAU&lang=en_US&refURL=http%3A%2F%2Fknowledgebase.paloaltonetworks.com%2FKCSArticleDetail

Choose Language