200153 - Target Firewall Not Connected (User-ID)
Agent error code #200153 means Knocknoc sent an IP-tag registration through Panorama for a specific firewall serial number, and Panorama could not reach that firewall to pass the request on.
This is the User-ID equivalent of #200000, which covers the same problem on the External Dynamic List refresh path. If a knoc uses both, expect both codes.
Common causes include:
- The firewall has lost its management connection to Panorama
- The serial number configured on the knoc does not match a device Panorama manages
- The serial number is correct but the device was rebooting or upgrading
- The vsys named on the knoc does not exist on that firewall, which Panorama reports the same way
Steps to Resolve
Check the Device Connection in Panorama
- Open Panorama > Managed Devices > Summary
- Find the serial number from the agent log line, which records it as
serial - Confirm the device shows as Connected
A device that shows as disconnected is a Panorama-to-firewall problem, not a Knocknoc one. Check network reachability on TCP 3978 between the firewall and Panorama.
Verify the Serial Number on the Knoc
- In the Knocknoc admin portal, open the knoc and read the serial numbers configured on it
- Compare them against Panorama > Managed Devices, or against Dashboard > General Information on the firewall itself
- Correct any mismatch, including stale serials left behind after a hardware replacement or RMA
A knoc listing several serials fails only for the ones that cannot be reached, so a partial failure points at one specific device rather than at Panorama.
Verify the vsys
If the firewall runs in multi-vsys mode, confirm the vsys named on the knoc exists on that device. A vsys that exists on some managed firewalls but not others produces this error only for the ones missing it.