After a reboot, the firewall in "Not Ready" state, commit does not work

After a reboot, the firewall in "Not Ready" state, commit does not work

44134
Created On 10/16/20 02:21 AM - Last Modified 08/19/22 03:46 AM


Symptom


  • After the reboot, the firewall remains in "Not ready" state.
  • The autocommit jobs fail with the message
 Management server failed to send phase 1 to client cord
 Commit failed
 Failed to commit policy to device
from WebUI, we can see the firewall is in "Not Ready" state
  • The commit force will fail with the error
admin@Lab32-13-PA-3020> configure
admin@Lab32-13-PA-3020# commit force 
Server error : Commit job was not queued. All daemons are not available.
  • The process cdb is stopped.
admin@Lab32-13-PA-3020> show system software status 

Slot 0, Role mp
----------------------------------------

Type     Name                 State    Info
Group    all                  running  
....
Group    third_party          running  
Process  authd                running  (pid: 3485) 
Process  cdb                  stopped  (pid: -1) - Exit Code: 100  
... 
Process  websrvr              running  (pid: 3459



Environment


  • Palo Alto PA-3000, 3200, 5000, 52000 or 7000 series firewalls
  • Supported PAN-OS.


Cause


The panlogs partition is full.
admin@Lab32-13-PA-3020> show system disk-space 

Filesystem      Size  Used Avail Use% Mounted on
/dev/root       3.8G  3.0G  643M  83% /
none            1.9G   64K  1.9G   1% /dev
/dev/sda5       7.6G  4.9G  2.3G  69% /opt/pancfg
/dev/sda6       3.8G  2.8G  842M  77% /opt/panrepo
tmpfs           1.9G  247M  1.6G  14% /dev/shm
/dev/sda8        90G   89G     0 100% /opt/panlogs
tmpfs            12M     0   12M   0% /opt/pancfg/mgmt/lcaas/ssl/private


 


Resolution


  1. Verify if the copy of logs are available on an external system (Panorama for instance).
  2. If they are available and there is no need to take the backup of logs,  then logs can be cleared by following the KB article - How to Clear Logs on a Palo Alto Networks Device
  3. If you do not have a copy of logs on an external system, you will need to contact the Support.

Note: Once the issue resolved, it is suggested to reduce the quota of the traffic and the threat logs by 1 or 2% each.


Actions
  • Print
  • Copy Link

    https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u000000HBCTCA4&lang=en_US&refURL=http%3A%2F%2Fknowledgebase.paloaltonetworks.com%2FKCSArticleDetail

Choose Language