Description

While enrolling an SRX device as a collector to JATP Core, the "Failed to communicate with JATP server when retrieving registration status" error may be encountered.

This article gives the reason for the enrollment to fail and details what must be done to succeed with the enrollment.

 

Symptoms

The following error is output while enrolling an SRX device as a collector to JATP Core:

root@SRX-A> op url "https://10.10.10.10:443/cyadmin/cgi-bin/srx_enrollment?operation=enroll&api_key=XXXX&config=.slax"
You're about to operate on an HA pair.
Platform is supported by JATP: SRX345.
Version JUNOS Software Release [18.3R1.9] is valid for bootstrapping.
Going to enroll HA pair for SRX345: HostA-HostB with hostname SRX-A::SRX-B.
Clear CA profile aamw-ca...
Clear CA profile aamw-cloud-ca...
Clear CA profile aamw-secintel-ca...
Start downloading Application Signature DB update...
Configure CA...
Request aamw-secintel-ca CA...
Load aamw-secintel-ca CA...
Retrieve CA profile aamw-ca...
CA certificate ready: aamw-ca...
CA certificate ready: aamw-secintel-ca...
Clear local certificate aamw-srx-cert with CA server...
Clear key pair: aamw-srx-cert...
Generate key pair: aamw-srx-cert...
Enroll local certificate aamw-srx-cert with CA server #1...
Configure advanced-anti-malware services...
Configuration added successfully for advanced-anti-malware services.
Checking configuration on SRX...
SSL profile:                          [OK]
SecIntel CA:                          [OK]
Client cert found:                    [OK]
SSL profile action:                   [OK]
URL for advanced-anti-malware:        [OK]
Profile for advanced-anti-malware:    [OK]
URL for security-intelligence:        [OK]
Profile for security-intelligence:    [OK]
All SRX configurations are correct for enrollment.
Communicate with JATP server...
error: [Error] Failed to communicate with JATP server when retrieving registration status.
Please make sure you are able to connect to JATP server. If this issue still remains, please contact JTAC for help.

 

Solution

SRX devices integrate with JATP only through an IP address. If there is a VPN/remote connection via an interface without an IP address assigned, for example st.0 of a VPN, the enrollment will fail.

 

To ensure that the enrollment of the SRX device as a collector to JATP Core is successful, assign an IP address to the SRX device interface that is reachable from the JATP Core and retry enrollment.

If the problem persists even after attempting the above solution, contact Support for troubleshooting further.