Panorama OTP verification failed due to the error "Generic communication error occured. Please enable debugging for detailed info [get-panorama-cert.py:262] <class 'TypeError'> ("'error' object is not iterable",)"

Panorama OTP verification failed due to the error "Generic communication error occured. Please enable debugging for detailed info [get-panorama-cert.py:262] <class 'TypeError'> ("'error' object is not iterable",)"

419
Created On 05/12/25 07:46 AM - Last Modified 11/07/25 20:58 PM


Symptom


Panorama OTP verification failed due to the following error.

admin@Panorama> request plugins cloud_services panorama-certificate fetch debug yes otp <OTP>

Generic communication error occured. Please enable debugging for detailed info  [get-panorama-cert.py:262] <class 'TypeError'> ("'error' object is not iterable",) 
=========== DEBUG BEGINS ===========

=========== DEBUG ENDS ===========
Failure

 



Environment


  • Panorama Managed Prisma Access
  • Panorama
  • Cloud Services Plugin


Cause


This issue can be caused by several reasons, including:

  1. Required ports and FQDNs are not allowed by security appliances on the path between Panorama and Prisma Access.
  2. PMTUD is not working correctly on Panorama due to the following factors.
    1. Customer environment uses Palo Alto Networks firewalls as security appliances with SYN cookies enabled in Flood Protection.
    2. ICMP fragmentation needed message not to reach the management interface because permitted IP list is configured on management interface of Panorama.


Resolution


  1. Allow required ports and FQDNs in security appliances.

    1. Disable SYN cookies on the firewall
    2. Add the IP of the intermediate devices that sent ICMP Fragmentation needed message to permitted IP list.


Additional Information




Actions
  • Print
  • Copy Link

    https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA1Ki000000blQeKAI&lang=en_US&refURL=http%3A%2F%2Fknowledgebase.paloaltonetworks.com%2FKCSArticleDetail