<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Pathfinder 16.02 not working with Proxy Settings in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/pathfinder-16-02-not-working-with-proxy-settings/m-p/287605#M20</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;it's not really a discussion but more a let's document two actual issue I went through.&lt;/P&gt;&lt;P&gt;In rare cases when you have to deploy Pathfinder in a not direct connection to the internet (no DNS, and no web), then this might be of interest to you.&lt;/P&gt;&lt;P&gt;In Pathfinder you can set the proxy settings.&amp;nbsp;In my case it is a non-authenticated proxy, so I just added proxy address and proxy port.&lt;/P&gt;&lt;P&gt;When doing a Connectivity check, all tests failed ! and no packets were sent to the proxy server.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Connectivity checks errors" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/21320i0E70FB0BCF9CA0A1/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="pathfinder.png" alt="Connectivity checks errors" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;Connectivity checks errors&lt;/span&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Looking into the logs we can see the cause.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="pathfinder_username.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/21321i158D1C274F25A9C8/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="pathfinder_username.png" alt="pathfinder_username.png" /&gt;&lt;/span&gt;BUG1 : This is due because the scripts implemented in 16.02 sends commands to curl but fails because the username = ''&lt;/P&gt;&lt;P&gt;Workaround &lt;STRONG&gt;: &lt;/STRONG&gt;enter any username and it works&lt;/P&gt;&lt;P&gt;All Connectivity tests are now working but I still cannot pair.&lt;/P&gt;&lt;P&gt;I get a message, please authorize in admin UI, but nothing appears in the pathfinder management UI, and then it fails miserably.&lt;/P&gt;&lt;P&gt;Looking at the logs (edited), we can see "internal IP address is invalid" because it's empty !&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="error_pathfinder_16.02.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/21323i2739E000AB9C2B35/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="error_pathfinder_16.02.png" alt="error_pathfinder_16.02.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The cause of this is a bit complex but basically it's related&amp;nbsp; to finding it's own ip based on the direct name resolution (dns) of your XDR Analyzer instance.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Workaround BUG2: find your instance name : example &amp;lt;xxxxxxxxxxxxcbaced8&amp;gt;.magnifier.eu.paloaltonetworks.com (replace with your own instance ID)&lt;/P&gt;&lt;P&gt;And create a 'A' DNS record for this entry which should resolve to&amp;nbsp;154.59.126.13.&lt;/P&gt;&lt;P&gt;Depending on your installation it can be hard to add another zone paloaltonetworks.com so another easier way is to use the DNSproxy feature of the PANOS with static entries&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="dns-proxy.png" style="width: 868px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/21325iEF79256D2799F688/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="dns-proxy.png" alt="dns-proxy.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 10 Sep 2019 12:34:26 GMT</pubDate>
    <dc:creator>Retired Member</dc:creator>
    <dc:date>2019-09-10T12:34:26Z</dc:date>
    <item>
      <title>Pathfinder 16.02 not working with Proxy Settings</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/pathfinder-16-02-not-working-with-proxy-settings/m-p/287605#M20</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;it's not really a discussion but more a let's document two actual issue I went through.&lt;/P&gt;&lt;P&gt;In rare cases when you have to deploy Pathfinder in a not direct connection to the internet (no DNS, and no web), then this might be of interest to you.&lt;/P&gt;&lt;P&gt;In Pathfinder you can set the proxy settings.&amp;nbsp;In my case it is a non-authenticated proxy, so I just added proxy address and proxy port.&lt;/P&gt;&lt;P&gt;When doing a Connectivity check, all tests failed ! and no packets were sent to the proxy server.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Connectivity checks errors" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/21320i0E70FB0BCF9CA0A1/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="pathfinder.png" alt="Connectivity checks errors" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;Connectivity checks errors&lt;/span&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Looking into the logs we can see the cause.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="pathfinder_username.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/21321i158D1C274F25A9C8/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="pathfinder_username.png" alt="pathfinder_username.png" /&gt;&lt;/span&gt;BUG1 : This is due because the scripts implemented in 16.02 sends commands to curl but fails because the username = ''&lt;/P&gt;&lt;P&gt;Workaround &lt;STRONG&gt;: &lt;/STRONG&gt;enter any username and it works&lt;/P&gt;&lt;P&gt;All Connectivity tests are now working but I still cannot pair.&lt;/P&gt;&lt;P&gt;I get a message, please authorize in admin UI, but nothing appears in the pathfinder management UI, and then it fails miserably.&lt;/P&gt;&lt;P&gt;Looking at the logs (edited), we can see "internal IP address is invalid" because it's empty !&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="error_pathfinder_16.02.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/21323i2739E000AB9C2B35/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="error_pathfinder_16.02.png" alt="error_pathfinder_16.02.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The cause of this is a bit complex but basically it's related&amp;nbsp; to finding it's own ip based on the direct name resolution (dns) of your XDR Analyzer instance.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Workaround BUG2: find your instance name : example &amp;lt;xxxxxxxxxxxxcbaced8&amp;gt;.magnifier.eu.paloaltonetworks.com (replace with your own instance ID)&lt;/P&gt;&lt;P&gt;And create a 'A' DNS record for this entry which should resolve to&amp;nbsp;154.59.126.13.&lt;/P&gt;&lt;P&gt;Depending on your installation it can be hard to add another zone paloaltonetworks.com so another easier way is to use the DNSproxy feature of the PANOS with static entries&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="dns-proxy.png" style="width: 868px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/21325iEF79256D2799F688/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="dns-proxy.png" alt="dns-proxy.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 10 Sep 2019 12:34:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/pathfinder-16-02-not-working-with-proxy-settings/m-p/287605#M20</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2019-09-10T12:34:26Z</dc:date>
    </item>
    <item>
      <title>Re: Pathfinder 16.02 not working with Proxy Settings</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/pathfinder-16-02-not-working-with-proxy-settings/m-p/288118#M21</link>
      <description>&lt;P&gt;Unfortunatly, the list goes on.&lt;/P&gt;&lt;P&gt;Bug No 3:&lt;/P&gt;&lt;P&gt;After pairing and being authorize in the portail UI, the service restart itself, and then you might get an error message of something like&lt;/P&gt;&lt;P&gt;Configuration file corrupted.&lt;/P&gt;&lt;P&gt;Looking at the logs in&amp;nbsp;&lt;SPAN&gt;the agent.log file. I saw an error :&lt;/SPAN&gt;&lt;SPAN&gt;InvalidURL: Failed to parse: myuser:p0&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;This is due to a wrong parsing a password which is encoded in base64 and containing a slash character. '/'&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;2 workarounds :&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;1) given a statistics of 344 characters with a probability of 1/64 to be a slash. This give a chance of 5:1. So if you try 10 times, you probably have a working installation.&lt;BR /&gt;2) second workaround. Edit /etc/conf/lc.conf and replace the slash character by another characters and restart the service.&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Regards&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Frank&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 12 Sep 2019 15:37:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/pathfinder-16-02-not-working-with-proxy-settings/m-p/288118#M21</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2019-09-12T15:37:55Z</dc:date>
    </item>
    <item>
      <title>Re: Pathfinder 16.02 not working with Proxy Settings</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/pathfinder-16-02-not-working-with-proxy-settings/m-p/292834#M22</link>
      <description>&lt;P&gt;Support has announced resolution of those 3 bugs for next release of Pathfinder.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Let's cross fingers&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Frank&lt;/P&gt;</description>
      <pubDate>Mon, 14 Oct 2019 09:57:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/pathfinder-16-02-not-working-with-proxy-settings/m-p/292834#M22</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2019-10-14T09:57:15Z</dc:date>
    </item>
  </channel>
</rss>

