After a reboot, the firewall in "Not Ready" state, commit does not work
44134
Created On 10/16/20 02:21 AM - Last Modified 08/19/22 03:46 AM
Symptom
- After the reboot, the firewall remains in "Not ready" state.
- The autocommit jobs fail with the message
Management server failed to send phase 1 to client cord
Commit failed
Failed to commit policy to device
- The commit force will fail with the error
admin@Lab32-13-PA-3020> configure
admin@Lab32-13-PA-3020# commit force
Server error : Commit job was not queued. All daemons are not available.
- The process cdb is stopped.
admin@Lab32-13-PA-3020> show system software status
Slot 0, Role mp
----------------------------------------
Type Name State Info
Group all running
....
Group third_party running
Process authd running (pid: 3485)
Process cdb stopped (pid: -1) - Exit Code: 100
...
Process websrvr running (pid: 3459
Environment
- Palo Alto PA-3000, 3200, 5000, 52000 or 7000 series firewalls
- Supported PAN-OS.
Cause
The panlogs partition is full.
admin@Lab32-13-PA-3020> show system disk-space
Filesystem Size Used Avail Use% Mounted on
/dev/root 3.8G 3.0G 643M 83% /
none 1.9G 64K 1.9G 1% /dev
/dev/sda5 7.6G 4.9G 2.3G 69% /opt/pancfg
/dev/sda6 3.8G 2.8G 842M 77% /opt/panrepo
tmpfs 1.9G 247M 1.6G 14% /dev/shm
/dev/sda8 90G 89G 0 100% /opt/panlogs
tmpfs 12M 0 12M 0% /opt/pancfg/mgmt/lcaas/ssl/private
Resolution
- Verify if the copy of logs are available on an external system (Panorama for instance).
- If they are available and there is no need to take the backup of logs, then logs can be cleared by following the KB article - How to Clear Logs on a Palo Alto Networks Device
- If you do not have a copy of logs on an external system, you will need to contact the Support.
Note: Once the issue resolved, it is suggested to reduce the quota of the traffic and the threat logs by 1 or 2% each.