Defender not included in the collection based on Account ID with Error log "Failed to fetch cloud metadata: fetch from IMDSv1 failed"

Defender not included in the collection based on Account ID with Error log "Failed to fetch cloud metadata: fetch from IMDSv1 failed"

7730
Created On 12/07/22 08:35 AM - Last Modified 03/28/23 06:52 AM


Symptom


  • Collection defined based on Account ID as below:
collections.png
  • However, cannot find the Defender tagged with the expected Collection Label:

host.PNG


Environment


  • Prisma Cloud Compute Self-hosted version 22.06 and below


Cause


  • Defender uses IMDSv1 API provided by AWS to determine AWS Account ID of the current running host.
  • This API requires the connection from defender to 169.254.169.254.
  • If the Defender cannot reach this IP, it will fail to retrieve the account ID, with the following Error in Defender Logs: 
ERRO 2022-09-07T11:04:27.872 defender.go:239 Failed to fetch cloud metadata: fetch from IMDSv1 failed: Get "http://169.254.169.254/latest/dynamic/instance-identity/document": dial tcp 169.254.169.254:80: connect: network is unreachable

 


Resolution


  • Ensure Defender connectivity to IP 169.254.169.254 on port 80
  • If the Defender is configured with Proxy at Manage > System > Proxy
    • Ensure the Proxy can access IP 169.254.169.254 with port 80 , or
    • Add IP 169.254.169.254 into "No proxy" list to make defender connect directly when making IMDSv1 API
Screen Shot 2022-12-07 at 4.22.00 PM.png
  • If the Defender is not configured with Proxy, then review the settings on your Firewall, Security Group and Routing Table to troubleshoot network problem between the host and 169.254.169.254 on port 80.
 
curl -vvv --noproxy '*'  http://169.254.169.254/latest/dynamic/instance-identity/document
Expected output:

output.png

  • After fixing the network issue between the Defender and 169.254.169.254, restart the Defender so that it will call IMDSv1 API to fetch the cloud metadata again.


Additional Information


  • By design, Defender will only fetch cloud metadata once every time it starts.
  • It will not retry when it fails to fetch cloud metadata.


Actions
  • Print
  • Copy Link

    https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u000000sa4CCAQ&refURL=http%3A%2F%2Fknowledgebase.paloaltonetworks.com%2FKCSArticleDetail

Choose Language