Palo Alto Networks Certified Network Security Engineer (PCNSE)TroubleshootMedium

A network administrator logs into Panorama and observes that the 'Managed Devices' tab shows a firewall in a 'Disconnected' state. The firewall itself is operational, passing traffic, and the management interface is reachable from Panorama. No recent configuration changes were made on either Panorama or the firewall. What is the most likely cause for the 'Disconnected' state in Panorama?

  1. AThe Panorama server's IP address is not configured as a Panorama server on the firewall.
  2. BThe firewall's management plane is overloaded, preventing connection.
  3. CThe Panorama management interface is down.
  4. DThe firewall's Device Group membership is incorrect.
Show answer & explanation

Correct answer: A. The Panorama server's IP address is not configured as a Panorama server on the firewall.

For a firewall to connect to Panorama, Panorama's IP address must be explicitly configured as a Panorama server on the firewall (Device > Setup > Management > Panorama Settings). If this setting is missing or incorrect, the firewall won't initiate or accept the connection from Panorama, leading to a 'Disconnected' state even if basic IP reachability exists.

Why the other options are wrong

  • B. An overloaded management plane might cause connection timeouts or sluggishness, but typically not a persistent 'Disconnected' state if the firewall is otherwise operational and reachable.
  • C. If Panorama's management interface were down, Panorama itself would likely be inaccessible, not just showing a single firewall as disconnected.
  • D. Incorrect Device Group membership affects configuration inheritance and pushes, but not the fundamental connection state between Panorama and the firewall.

Firewall Panorama Registration

For a Palo Alto Networks firewall to be managed by Panorama, the Panorama server's IP address must be explicitly configured on the firewall under its Panorama Settings.

  • Enables the firewall to initiate/accept connections from Panorama.
  • Crucial for Panorama to push configurations and retrieve logs.
  • Located at Device > Setup > Management > Panorama Settings on the firewall.

Memory trick: Tell the firewall where its Panorama home is.

More Troubleshoot questions