Error message: pan_ssl_conn_open failed seen when connecting User ID agent to Windows 2019 Server
29696
Created On 04/27/20 21:24 PM - Last Modified 03/13/21 03:51 AM
Symptom
- User-ID Agent Version 8.1.11-2 installed on on a Windows Server 2019.
- UID agent on the firewall displays as ‘not connected’ ( GUI:Device>User Identification>User-ID Agents).
- When attempting the connection from the FW to the user id agent on the Windows Server, Firewall useridd.log displays the following error message:
pan_ssl_conn_open (pan_ssl_utils.c:696) : pan_tcp_sock_open () to 10.36.192.104 port 5007 failed;
errno=115
Environment
- All PA Series Firewall
- PAN-OS 8.1,9.0,9.1
Cause
User-ID Agent Version 8.1.11 is not supported on Windows Server 2019.
Resolution
Upgrade and Use the User ID Agent version 9.0.2 or greater to connect to WindowsServer2019. Details of the same can be found here