Reset Search
 

 

Article

KB43642 - ng-gateman process snapshots are generated when a PPS and its Palo Alto enfrocer attempt to reconcile

« Go Back

Information

 
Last Modified Date2/26/2018 11:51 PM
Synopsis
This article describes one possible cause for the creation of an ng-gateman snapshot. The ng-gateman process controls communications between the PPS and its Palo Alto enforcers.
Problem or Goal
When a PPS and its PAN firewall enforcer lose connection for any reason the PPS will reconnect to the PAN and begin reconciliation. When connectivity is lost it is important for the two devices to sync up and ensure new auth tables are added to the PAN and for old auth tables to be removed, this process is called reconciliation. We've observed issues with PAN OS 8.0.6 and 8.0.7 and reconciliation. The following message can be returned by the PAN firewall during reconciliation.

<response status="error"><msg><line><uid-response>
<version>2.0</version>
<payload>
<general>
<entry message="Not ready to process xmlapi data"/>
</general>
</payload>
</uid-response>
</line></msg></response>

 
Cause
Current releases of the PPS code are unable to understand the message and the PPS generates an ng-gateman core.
Solution
Changes have been incorporated into PPS 9.0R1 and later to prevent the cores.  Palo Alto reports the issue will be fixed on their end in PAN OS 8.0.9.
Related Links
Attachment 1 
Created ByBrian Pimentel

Feedback

 

Was this article helpful?


   

Feedback

Please tell us how we can make this article more useful.

Characters Remaining: 255