初始配置后,Panorama 无法连接 Strata Logging Service。

初始配置后,Panorama 无法连接 Strata Logging Service。

6697
Created On 10/10/24 09:03 AM - Last Modified 01/07/25 01:32 AM


Symptom


  • 为 Strata Logging Service 配置的 Panorama。
  • When checking the status "request plugins cloud_services logging-service status", the following error message is displayed.
    > request plugins cloud_services logging-service status
    fail
    Exception 'customer-id'
  • In lcaas_agent.log (更少 mp-log lcaas_agent.log), response code 401 can be seen.
    16:13:39,693 lcaas_agent INFO URL=https://lic.lc.prod.us.cs.paloaltonetworks.com:444/Platform/CustomerInfo/
    16:13:39,693 lcaas_agent INFO CERT=/opt/pancfg/mgmt/ssl/private/device.crt
    16:13:40,397 lcaas_agent INFO response from orchestrator=b'{"code":401,"message":"Got error. No provisioned tenant id found for serial number in cert subject: ClientCert.Subject(commonName=000702042476, orgUnit=null, serialNumber=null, oid=OID.1.3.6.1.4.1.25461.4.22.1)","timeStamp":"2024-10-08T07:13:40.311Z"}'
    16:13:40,398 lcaas_agent INFO Resp from cloud service : b'{"code":401,"message":"Got error. No provisioned tenant id found for serial number in cert subject: ClientCert.Subject(commonName=000702042476, orgUnit=null, serialNumber=null, oid=OID.1.3.6.1.4.1.25461.4.22.1)","timeStamp":"2024-10-08T07:13:40.311Z"}'
    16:13:40,398 lcaas_agent ERROR Customer is not provisioned in CSP
  • 许可证和设备证书没有问题。
  • From a packet capture on a management interface, you do not observe any traffic from port 444.
    > tcpdump snaplen 0 filter "tcp port (3978 or 80 or 443 or 444) or udp port 53"


Environment


  • 全景
  • 支持的 PAN OS
  • Strata 日志服务 (以前称为 Cortex 数据湖)


Cause


Panorama 尚未加入 Strata Logging Service 租户。

Resolution


按照为 Strata Logging Service 配置 Panorama中的步骤安装 Panorama。



Actions
  • Print
  • Copy Link

    https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u000000HEGTCA4&lang=zh_CN&refURL=http%3A%2F%2Fknowledgebase.paloaltonetworks.com%2FKCSArticleDetail

Choose Language