A critical error has been detected (Entry reason: System startup error).

A critical error has been detected (Entry reason: System startup error).

12804
Created On 06/16/23 18:55 PM - Last Modified 06/16/23 22:25 PM


Symptom


  • After a license is installed on a VM-Series Firewall it reboots (Palo Alto Networks, Inc., 2023).
  • However, the Firewall boots into maintenance mode and the “Entry reason” is “System startup error”; 
  • When you attempt to access the CLI (via the console, for instance) you come across the following error:
 

 
  • On the GUI you come across the following error:
 



 



Environment


  • VM-Series Firewall or Panorama just after a license has been installed on it.
  • Console access enabled.

 


Cause


  • This particular combination of symptoms listed below can occur because the VM doesn’t meet the System Requirements for the license or model (e.g. VM-300) that you’re attempting to install on it 
    • License installed on the VM, followed by
    • The VM booting into maintenance mode
    • Maintenance entry reason “System startup error”
  • PAN-OS detects that the VM doesn’t meet the requirements stipulated by the license installed on the VM, and boots into maintenance mode.
 


Resolution


There are two ways to resolve this, but both involve matching the resources allocated to the VM, with the correct license type:
  1. Increase resources allocated to the VM:
    • For VMs on a public cloud, this will typically involve shutting the VM down, resizing it to another VM type, and then starting the VM.
    • For example, on AWS-hosted Firewall or Panorama VMs, you stop the instance, change the instance type, and start the instance (Amazon Web Services, 2023).
  2. Deactivate the currently-active license, factory-reset the Firewall, and install the correct license:
    • You can deactivate the license using the Customer Support Portal (Palo Alto Networks, Inc., 2023).
    • Factory-resetting the Firewall is possible via maintenance mode itself (Palo Alto Networks, Inc., 2018).
    • Install the license again.


Additional Information


 

References

Amazon Web Services. (2023, 06 16). Change the instance type. AWS Documentation. https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/ec2-instance-resize.html

Palo Alto Networks, Inc. (2018, 09 25). How to perform a factory reset on a Palo Alto Networks device. Palo Alto Networks Knowledge Base. https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000CldXCAS

Palo Alto Networks, Inc. (2023, 01 27). VM-Series Models on AWS EC2 Instances. Palo Alto Networks TechDocs. https://docs.paloaltonetworks.com/vm-series/10-1/vm-series-performance-capacity/vm-series-performance-capacity/vm-series-on-aws-models-and-instances

Palo Alto Networks, Inc. (2023, 03 17). VM-Series System Requirements. Palo Alto Networks TechDocs. https://docs.paloaltonetworks.com/vm-series/10-1/vm-series-deployment/license-the-vm-series-firewall/vm-series-models/vm-series-system-requirements

Palo Alto Networks, Inc. (2023, 05 17). Activate the License for the VM-Series Firewall (Standalone Version). Palo Alto Networks TechDocs. https://docs.paloaltonetworks.com/vm-series/10-1/vm-series-deployment/license-the-vm-series-firewall/vm-series-models/activate-the-license/activate-the-license-for-the-vm-series-firewall-standalone-version

Palo Alto Networks, Inc. (2023, 05 17). Deactivate VM. Palo Alto Networks TechDocs. https://docs.paloaltonetworks.com/vm-series/10-1/vm-series-deployment/license-the-vm-series-firewall/vm-series-models/deactivate-the-licenses/deactivate-vm



Actions
  • Print
  • Copy Link

    https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u000000kI73CAE&refURL=http%3A%2F%2Fknowledgebase.paloaltonetworks.com%2FKCSArticleDetail

Choose Language