<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SCP Dynamic updates in Panorama Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/panorama-discussions/scp-dynamic-updates/m-p/999937#M2718</link>
    <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/220883"&gt;@MarcoMancini&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Sorry I could not update on the post directly.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Olivier&lt;/P&gt;</description>
    <pubDate>Thu, 02 Jan 2025 01:11:40 GMT</pubDate>
    <dc:creator>ozheng</dc:creator>
    <dc:date>2025-01-02T01:11:40Z</dc:date>
    <item>
      <title>SCP Dynamic updates</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/scp-dynamic-updates/m-p/999255#M2706</link>
      <description>&lt;P&gt;Hi Community,&lt;/P&gt;
&lt;P&gt;Our setup follows the steps outlined in the Palo Alto article: &lt;A href="https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-upgrade/upgrade-panorama/install-content-and-software-updates-for-panorama/install-updates-automatically-for-panorama-without-an-internet-connection" target="_new" rel="noopener"&gt;&lt;SPAN&gt;Install&lt;/SPAN&gt;&lt;SPAN&gt; Updates&lt;/SPAN&gt;&lt;SPAN&gt; Automatically&lt;/SPAN&gt;&lt;SPAN&gt; for&lt;/SPAN&gt;&lt;SPAN&gt; Panorama&lt;/SPAN&gt;&lt;SPAN&gt; Without&lt;/SPAN&gt;&lt;SPAN&gt; an&lt;/SPAN&gt;&lt;SPAN&gt; Internet&lt;/SPAN&gt;&lt;SPAN&gt; Connection&lt;/SPAN&gt;&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;Here’s the issue:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;The Panorama &lt;STRONG&gt;with an internet connection&lt;/STRONG&gt; successfully downloads updates and uploads them to the SCP server.&lt;/LI&gt;
&lt;LI&gt;The Panorama &lt;STRONG&gt;without an internet connection&lt;/STRONG&gt; pulls updates from the SCP server.&lt;/LI&gt;
&lt;LI&gt;The application and threats update &lt;STRONG&gt;fails validation&lt;/STRONG&gt; and is not pushed to the managed firewall.&lt;/LI&gt;
&lt;LI&gt;The Antivirus and Wildfire updates &lt;STRONG&gt;are successfully pushed&lt;/STRONG&gt; to the managed firewall.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;From the logs, I see that after downloading the update, Panorama tries to reach the update server configured under &lt;STRONG&gt;Panorama → Setup → Services → Update Server&lt;/STRONG&gt; on port 443 for validating the update. Of course, this fails since there is no internet connection anymore and it looks like something odd.&lt;/P&gt;
&lt;P&gt;I set the SCP server as the update server, but how is it supposed to listen on port 443? I even tried forcing the SCP URL with &lt;CODE&gt;:22&lt;/CODE&gt; (e.g., &lt;CODE&gt;scp.url:22&lt;/CODE&gt;), but it didn’t resolve the issue.&lt;/P&gt;
&lt;P&gt;Has anyone encountered a similar issue, or could someone clarify how to properly configure the update server in this case? I tried to raise a TAC case but we are running in circle without a solution&lt;/P&gt;
&lt;P&gt;Any suggestions would be greatly appreciated!&lt;/P&gt;</description>
      <pubDate>Sun, 22 Dec 2024 09:17:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/scp-dynamic-updates/m-p/999255#M2706</guid>
      <dc:creator>MarcoMancini</dc:creator>
      <dc:date>2024-12-22T09:17:35Z</dc:date>
    </item>
    <item>
      <title>Re: SCP Dynamic updates</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/scp-dynamic-updates/m-p/999888#M2715</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/220883"&gt;@MarcoMancini&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I would advise to work it with a TAC engineer.&lt;/P&gt;
&lt;P&gt;I mean in the TAC case you would share the TSF from the inner and the outer panorama, so the TAC engineer can review the configuration and the data.&lt;BR /&gt;&lt;BR /&gt;Olivier&lt;/P&gt;</description>
      <pubDate>Tue, 31 Dec 2024 07:34:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/scp-dynamic-updates/m-p/999888#M2715</guid>
      <dc:creator>ozheng</dc:creator>
      <dc:date>2024-12-31T07:34:58Z</dc:date>
    </item>
    <item>
      <title>Re: SCP Dynamic updates</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/scp-dynamic-updates/m-p/999894#M2716</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/109098"&gt;@ozheng&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;Thanks for your suggestion. I opened a TAC case two weeks ago, but progress has been slow, so I posted here for additional input.&lt;/P&gt;
&lt;P&gt;TAC recommended manually uploading the latest content update to the air-gapped Panorama. While this is feasible, it’s not currently possible due to the time-intensive approval process for importing external files. Honestly, I don’t fully understand the point of the manual upload in this situation.&lt;/P&gt;
&lt;P&gt;I also suspect the issue might be with the SCP server, as I’ve read Panorama can have compatibility issues with Windows-based SCP servers in some discussions (and we have a windows SCP server). This could potentially affect the checksum, but I’m speculating since TAC support hasn’t been very helpful so far.&lt;/P&gt;
&lt;P&gt;Marco&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 31 Dec 2024 08:14:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/scp-dynamic-updates/m-p/999894#M2716</guid>
      <dc:creator>MarcoMancini</dc:creator>
      <dc:date>2024-12-31T08:14:51Z</dc:date>
    </item>
    <item>
      <title>Re: SCP Dynamic updates</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/scp-dynamic-updates/m-p/999937#M2718</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/220883"&gt;@MarcoMancini&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Sorry I could not update on the post directly.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Olivier&lt;/P&gt;</description>
      <pubDate>Thu, 02 Jan 2025 01:11:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/scp-dynamic-updates/m-p/999937#M2718</guid>
      <dc:creator>ozheng</dc:creator>
      <dc:date>2025-01-02T01:11:40Z</dc:date>
    </item>
  </channel>
</rss>

