Syslog over TLS defaults to the management port, ignoring the service port setting

Syslog over TLS defaults to the management port, ignoring the service port setting

1485
Created On 07/22/25 09:49 AM - Last Modified 08/06/25 21:50 PM


Symptom


  • Syslog over TLS configured to use data port using service route.
  • This works correctly till PAN-OS upgrade to PAN-OS 11.1 or 11.2.
  • After upgrade, the port defaults to management port instead of using the data port configured in the service route.
  • No issues observed with Syslog over TCP or UDP.
  • Netstat confirms connections are initiated from the firewall’s management IP.
Firewall> show netstat all yes numeric-ports yes numeric-hosts yes programs yes | match "Your-Syslog-Server-IP"
tcp        0      1 FW-Mgmt-IP:41488     Your-Syslog-Server-IP:6514     SYN_SENT    13259/logrcvr
  • The following are seen in the logrcvr.log (less mp-log logrcvr.log)
Error: pan_comm_get_tcp_conn_gen(comm_utils.c:875): COMM: cannot connect. remote ip="Your-Syslog-Server-IP" port=6514 err=Connection timed out(110) sock=23  
Error: pan_syslog_server_connect(cs_conn.c:12875): Failed to connect to server
Error: _pan_syslog(pan_syslog.c:1638): Failed to init socket


Environment


  • Palo Alto Firewalls
  • PAN-OS 11.1 / 11.2
  • Syslog over TLS
  • Service-port configured to use data-port


Cause


PAN-OS is not honoring the service-port configuration for Syslog over TLS, causing it to default to the management interface.



Resolution


  1. The issue will be fixed under PAN-279415 in PAN-OS 11.1.11 and 11.2.8
  2. Upgrade to the above versions when released will resolve the issue.

Workaround:

  1. Use the management port for Syslog over TLS, or
  2. Switch to Syslog over TCP or UDP, which are not affected by this issue.


Actions
  • Print
  • Copy Link

    https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA1Ki000000blgIKAQ&lang=en_US&refURL=http%3A%2F%2Fknowledgebase.paloaltonetworks.com%2FKCSArticleDetail