连接无法与系统日志服务器连接

连接无法与系统日志服务器连接

25302
Created On 09/01/20 21:07 PM - Last Modified 03/26/21 18:36 PM


Symptom


  • 在系统日志中,有失败的系统日志连接的消息
2020/03/24 11:40:11 high     syslog         syslog- 0  Syslog connection failed to server['AF_INET.10.230.240.173:1514.']
2020/03/24 11:40:11 high     syslog         syslog- 0  Syslog connection failed to server['AF_INET.10.230.240.173:1514.']
  • 插槽8上的syslog-ng日志 LPC 将显示"没有主机的路线"错误:
Mar 24 11:39:32 lp syslog-ng[3700]: Syslog connection failed; fd='27', server='AF_INET(10.230.240.173:1514)', error='No route to host (113)', time_reopen='5'
  • firewall通过 Panorama 配置推送或本地执行提交后,将重新建立 sslog 连接。 这也可以在系统日志中看到
2020/03/24 13:59:43 info     general        general 0  Commit job succeeded. Completion time=2020/03/24 13:59:43. JobId=272004. 
2020/03/24 14:00:11 high     syslog         syslog- 0  Syslog connection established to server['AF_INET.10.230.240.173:1514.']

 


Environment


  • PA-7050
  • PanOS 9.0.6
  • 使用日志处理卡进行Syslog转发 ( LPC )


Cause


  • PAN-112539 - 用于日志转发的数据飞机接口与第 8 槽中的日志处理卡之间的连接中断,导致系统日志连接也中断。


Resolution


  1. 该决议是升级到PanOS 9.0.10有一个修复PAN-112539

NOTE:
A 解决方法是 firewall 通过 Panorama 配置推送或本地执行提交。


Additional Information




Actions
  • Print
  • Copy Link

    https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u000000HAaZCAW&lang=zh_CN&refURL=http%3A%2F%2Fknowledgebase.paloaltonetworks.com%2FKCSArticleDetail

Choose Language