<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Problems with URL-DB (it's missing!) in Next-Generation Firewall Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/problems-with-url-db-it-s-missing/m-p/532437#M951</link>
    <description>&lt;P&gt;Hi!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Wanted to wait until this morning (after doing the relevant to make it work) :-&lt;BR /&gt;&lt;BR /&gt;If you apply url filtering to outgoing web traffic from servers you might want to make sure you aren't blocking "not-resolved" because all traffic is resolved as "not-resolved" if you don't have a URL database downloaded. Which results in the URL database download being blocked &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Allowing "not-resolved", and making the misbehaving firewall active resulted in the database being downloaded successfully before we had a chance to login to check.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;All is good again!&lt;/P&gt;</description>
    <pubDate>Tue, 28 Feb 2023 09:19:46 GMT</pubDate>
    <dc:creator>MikeMeredith</dc:creator>
    <dc:date>2023-02-28T09:19:46Z</dc:date>
    <item>
      <title>Problems with URL-DB (it's missing!)</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/problems-with-url-db-it-s-missing/m-p/532178#M943</link>
      <description>&lt;P&gt;Hi!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We've been having on going issues after an upgrade (since downgraded) with our standby firewall - when made live it only functioned at about 10% (i.e. most legitimate traffic was blocked for one reason or another). We fixed an issue with DNS resolution - apparently the domain string being present broke DNS resolution(!), but there remains an issue with URL filtering.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Specifically the URL database is at version&amp;nbsp;0000.00.00.000, and it doesn't successfully fetch anything from the cloud (which of course is disruptive as we have to make it live to get it to try). The cloud fetch is currently going through a proxy server - which we can see working not only for the active firewall (which successfully gets something) and for the standby (although it doesn't seem to get anything). One suggestion is to turn off the proxy - which is something we'll likely try when a suitable 'disruptive diagnostic' window can be arranged.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;And whilst this needs to be fixed, I was thinking that manually installing the url-db would be helpful, but I've tried :-&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;a) Via the Panorama GUI which doesn't like /any/ of the firewalls when trying to set up a schedule for "Download and install".&lt;/P&gt;
&lt;P&gt;b) Via the command line command&amp;nbsp;request url-filtering install. But that obviously requires a copy of the url-db.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is there a supported way to get hold of this url database file? And is this a sensible idea?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;[This has been logged with TAC]&lt;/P&gt;</description>
      <pubDate>Fri, 24 Feb 2023 14:16:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/problems-with-url-db-it-s-missing/m-p/532178#M943</guid>
      <dc:creator>MikeMeredith</dc:creator>
      <dc:date>2023-02-24T14:16:44Z</dc:date>
    </item>
    <item>
      <title>Re: Problems with URL-DB (it's missing!)</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/problems-with-url-db-it-s-missing/m-p/532257#M946</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/12701"&gt;@MikeMeredith&lt;/a&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;this looks like expected behavior. Passive Firewall does not connect to PAN-DB. Cold you please check this KB:&amp;nbsp;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u000000HCi1CAG?" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u000000HCi1CAG?&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you make Firewall with missing PAN-DB active (Under assumption you have valid URL filtering license) and it still does not work, you might be hitting this issue:&amp;nbsp;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000PNx4CAG" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000PNx4CAG&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Lastly,&amp;nbsp;"Download and Install" installs applications / threat signatures. This is unrelated to PAN-DB.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Kind Regards&lt;/P&gt;
&lt;P&gt;Pavel&lt;/P&gt;</description>
      <pubDate>Fri, 24 Feb 2023 21:01:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/problems-with-url-db-it-s-missing/m-p/532257#M946</guid>
      <dc:creator>PavelK</dc:creator>
      <dc:date>2023-02-24T21:01:30Z</dc:date>
    </item>
    <item>
      <title>Re: Problems with URL-DB (it's missing!)</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/problems-with-url-db-it-s-missing/m-p/532437#M951</link>
      <description>&lt;P&gt;Hi!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Wanted to wait until this morning (after doing the relevant to make it work) :-&lt;BR /&gt;&lt;BR /&gt;If you apply url filtering to outgoing web traffic from servers you might want to make sure you aren't blocking "not-resolved" because all traffic is resolved as "not-resolved" if you don't have a URL database downloaded. Which results in the URL database download being blocked &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Allowing "not-resolved", and making the misbehaving firewall active resulted in the database being downloaded successfully before we had a chance to login to check.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;All is good again!&lt;/P&gt;</description>
      <pubDate>Tue, 28 Feb 2023 09:19:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/problems-with-url-db-it-s-missing/m-p/532437#M951</guid>
      <dc:creator>MikeMeredith</dc:creator>
      <dc:date>2023-02-28T09:19:46Z</dc:date>
    </item>
  </channel>
</rss>

