Step 1: Review the incident details and record the affected ION, site, disconnection time, software version, and the WAN interface expected to provide internet and controller connectivity.
Step 2: Because the ION is disconnected from the controller, the Remote CLI Toolkit will not be available, and configuration changes made in SCM will not be pushed to the device. Connect directly to the ION through SSH from the local network or through the console port.
Step 3: Check the ION and controller-connection status:
dump overview
dump controller status
Confirm that the device is disconnected and review the reported state of the controller sessions.
Step 4: Verify the configuration and operational state of the controller-facing WAN interface:
dump interface config <WAN-interface-number>
dump interface status <WAN-interface-number>
Confirm that the interface is Admin Up, operationally up, has a valid IP address, and has the expected default gateway and DNS configuration.
Step 5: Verify Layer 3 internet reachability through the affected WAN interface:
ping <WAN-interface-number> 8.8.8.8
If the test fails, investigate the local interface, IP addressing, default gateway, routing, upstream router, ISP connectivity, cabling, or modem.
Step 6: Verify DNS resolution and reachability using the controller locator hostname:
nslookup locator.cgnx.net
ping <WAN-interface-number> locator.cgnx.net
Confirm that locator.cgnx.net resolves to an IP address. If the public-IP ping succeeds but the hostname test fails, investigate the configured DNS servers and DNS reachability.
Step 7: Verify Layer 4 TCP connectivity to the controller locator service over port 443:
tcpping <WAN-interface-number> locator.cgnx.net:443
If DNS resolution works but the TCP test fails, confirm that upstream firewalls, proxies, security policies, and the ISP allow outbound TCP port 443 to the Palo Alto Networks controller services.
Step 8: Verify the complete controller connection, including Layer 7 and certificate validation:
debug controller reachability <WAN-interface-number>
Review each test result to identify a DNS, routing, TCP 443, TLS, certificate-validation, or controller-service failure. Confirm that the ION system time is correct if certificate validation fails.
Step 9: Correct the identified network, DNS, routing, firewall, or time-synchronization issue locally. After connectivity is restored, run:
dump controller status
Confirm that Controller Connection shows Connected and that the controller sessions are established. Verify that the ION returns online in SCM and that the incident clears.
Step 10: If Layer 3, DNS, and TCP 443 connectivity succeed but the ION remains disconnected, collect the incident details and all command outputs and contact Palo Alto Networks Support. After controller connectivity is restored, collect a support bundle if requested:
For Release 6.4.1 or later:
dump-support all file=controller-disconnected
For earlier supported releases:
dump-support outputs file=controller-disconnected
Do not restart processes or reboot the ION unless instructed by Palo Alto Networks Support. |