Palo Alto Networks Certified Network Security Engineer (PCNSE)TroubleshootHard

A network security administrator is troubleshooting Panorama. When attempting to push a configuration to a managed firewall, the task fails with an error indicating 'connection refused'. The Panorama server can ping the firewall's management interface, and there are no network firewalls between them. What is the most likely cause for the 'connection refused' error during a Panorama push?

  1. AThe firewall's management interface is configured with an incorrect IP address.
  2. BThe firewall's management interface is not configured to allow Panorama access.
  3. CThe firewall has run out of disk space on its management plane.
  4. DThe Panorama server's IP address is not listed in the firewall's 'Permitted IP Addresses' list for management access.
Show answer & explanation

Correct answer: D. The Panorama server's IP address is not listed in the firewall's 'Permitted IP Addresses' list for management access.

A 'connection refused' error, despite successful ping, often indicates that the target device (firewall) is actively rejecting the connection attempt from the source (Panorama). For Palo Alto Networks firewalls, this is commonly caused by the Panorama server's IP address not being explicitly permitted in the firewall's Management Interface Profile or the 'Permitted IP Addresses' list under Device > Setup > Management, preventing the firewall from accepting the Panorama connection.

Why the other options are wrong

  • A. An incorrect IP address would result in ping failure or no route to host, not a 'connection refused' error.
  • B. While the management interface needs to be configured, the 'connection refused' implies the firewall is reachable but rejecting the connection, pointing to a specific access control mechanism.
  • C. Running out of disk space might cause commit failures or system instability, but typically not a 'connection refused' error on a management connection.

Firewall Management Access Control

Palo Alto Networks firewalls restrict management access to specific IP addresses defined in the Management Interface Profile or 'Permitted IP Addresses' list under Device > Setup > Management.

  • Prevents unauthorized management access.
  • If source IP is not permitted, connections are refused.
  • Crucial for Panorama to connect to managed firewalls.

Memory trick: Permitted IPs must open the door for Panorama's call.

More Troubleshoot questions