Solved

Palo Alto firewall config issue

  • 20 September 2022
  • 3 replies
  • 512 views

Badge +1

Hi All,

 

I have Palo Alto firewall, able to cvping ports but socket read is failing

 

11284 2cd4 09/20 15:34:32 OT:00008 ######## [Mediaagent] ERROR: cvfwd_iot_wait(): Socket READ failed. Got READ error on ON_DEMAND control tunnel from "client" to "mediaagent" via (x.x.x.x.x, y.y.y.y): The specified network name is no longer available.

icon

Best answer by Onno van den Berg 20 September 2022, 20:19

View original

3 replies

Userlevel 5
Badge +14

Hello @SGMak 

Thank you for your post. The error is suggesting that DNS cannot convert the Hostname of the remote machine that it is trying to connect to. Can you confirm DNS is working and there are no stale entries configured in the Hosts file?

It would also be good to confirm ports 8400 and 8403 are open at least one way between the two machines. If allowed one way we can configure a network tunnel so that we have the pipeline started in the direction that the ports.

 

Thank you,
Collin

Userlevel 7
Badge +23

Hi @SGMak , thanks for the post!  

Can you confirm with your Firewall team that the Palo Alto is allowing traffic for web browsing, http-proxy  Bi-Directionally between client and Commserve?

https://applipedia.paloaltonetworks.com/

Thanks!

Userlevel 7
Badge +19

Make sure to leverage a Commvault network topology configuratie to restricted the amount of TCP ports being used by default to a single TCP port which is 8403 by default. check name resolving and in case this is all working than I would loo into specific firewall features like deep packet inspection.

Reply