<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Not-resolved URL blocking PAN url cloud updates in Advanced Threat Prevention Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/not-resolved-url-blocking-pan-url-cloud-updates/m-p/550133#M1968</link>
    <description>&lt;P&gt;Yes, I have had this happen before. The default URL Filtering profile action for "unknown" and "not-resolved" is allow, but I suspect many people setup custom URL Filtering profiles to block or continue for additional security. When you upgrade from the PAN-DB database to URL-Cloud database (8.x to 9.x) the database is defaulted and must be repopulated from the cloud. I have also had the URL-Cloud database mysteriously reset and need to re-initialize. Unfortunately when this happens the URLs needed to initialize the database become "not-resolved" and are blocked in your custom URL Filter...&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;To handle this startup case I added "*.urlcloud.paloaltonetworks.com/" to a Custom URL Category object that always allows in my custom URL Filtering profiles. Since Custom URL Categories are defined outside of URL-Cloud they always resolve, and that allows the *.urlcloud.paloaltonetworks.com update addresses to pass URL Filtering, even when the URL-Cloud database is uninitialized or broken.&lt;/P&gt;</description>
    <pubDate>Thu, 20 Jul 2023 07:06:00 GMT</pubDate>
    <dc:creator>Adrian_Jensen</dc:creator>
    <dc:date>2023-07-20T07:06:00Z</dc:date>
    <item>
      <title>Not-resolved URL blocking PAN url cloud updates</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/not-resolved-url-blocking-pan-url-cloud-updates/m-p/550070#M1966</link>
      <description>&lt;P&gt;I am in a pickle, I have PANs managed by panorama but I can't push any URL updates to the PAN that is blocking itself.&amp;nbsp; Can I just update that policy that this traffic is hitting and remove the URL category action on it?&amp;nbsp; Will that allow it to connect?&amp;nbsp;I tried updating service routes to use the outside interface but still URL updates are not happening and it looks to be because the new license was installed on the 18th which in turn broke this someway.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You can see below the screenshot from the log timestamps line up with the logs from CLI but after 13:48 its still broken but not being logged.&amp;nbsp; I think that is after I changed DNS/NTP/PA Network Services and URL updates to use the outside interface.&amp;nbsp; But still no joy in getting this working.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="drewdown_0-1689801015481.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/51800i3C704F288E694A12/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="drewdown_0-1689801015481.png" alt="drewdown_0-1689801015481.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;(active)&amp;gt; show log system direction equal backward receive_time in last-24-hrs | match PAN-DB
2023/07/19 15:48:59 medium   url-fil        url-dow 0  PAN-DB cloud list loading failed (ERROR:Couldn't connect to server).
2023/07/19 15:19:25 medium   url-fil        url-dow 0  PAN-DB cloud list loading failed (ERROR:Couldn't connect to server).
2023/07/19 14:49:52 medium   url-fil        url-dow 0  PAN-DB cloud list loading failed (ERROR:Couldn't connect to server).
2023/07/19 14:20:18 medium   url-fil        url-dow 0  PAN-DB cloud list loading failed (ERROR:Couldn't connect to server).
2023/07/19 13:50:44 medium   url-fil        url-dow 0  PAN-DB cloud list loading failed (ERROR:Couldn't connect to server).
2023/07/19 13:45:43 medium   url-fil        url-dow 0  PAN-DB cloud list loading failed (ERROR:Couldn't connect to server).
2023/07/19 13:43:28 medium   url-fil        url-dow 0  PAN-DB cloud list loading failed (ERROR:SSL connect error).
2023/07/19 13:43:27 medium   url-fil        url-dow 0  PAN-DB cloud list loading failed (ERROR:Couldn't resolve host name).
2023/07/19 13:29:35 medium   url-fil        url-dow 0  PAN-DB cloud list loading failed (ERROR:SSL connect error).
2023/07/19 13:09:23 medium   url-fil        url-dow 0  PAN-DB cloud list loading failed (ERROR:SSL connect error).
2023/07/19 12:49:10 medium   url-fil        url-dow 0  PAN-DB cloud list loading failed (ERROR:SSL connect error).
2023/07/19 12:28:58 medium   url-fil        url-dow 0  PAN-DB cloud list loading failed (ERROR:SSL connect error).
2023/07/19 12:14:39 info     url-fil        url-bac 0  Backup of PAN-DB finished successfully.
2023/07/19 12:08:45 medium   url-fil        url-dow 0  PAN-DB cloud list loading failed (ERROR:SSL connect error).
2023/07/19 11:48:32 medium   url-fil        url-dow 0  PAN-DB cloud list loading failed (ERROR:SSL connect error).
2023/07/19 11:28:19 medium   url-fil        url-dow 0  PAN-DB cloud list loading failed (ERROR:SSL connect error).
2023/07/19 11:08:07 medium   url-fil        url-dow 0  PAN-DB cloud list loading failed (ERROR:SSL connect error).
2023/07/19 10:47:53 medium   url-fil        url-dow 0  PAN-DB cloud list loading failed (ERROR:SSL connect error).
2023/07/19 10:27:41 medium   url-fil        url-dow 0  PAN-DB cloud list loading failed (ERROR:SSL connect error).
2023/07/19 10:07:29 medium   url-fil        url-dow 0  PAN-DB cloud list loading failed (ERROR:SSL connect error).
2023/07/19 09:47:15 medium   url-fil        url-dow 0  PAN-DB cloud list loading failed (ERROR:SSL connect error).
2023/07/19 09:27:03 medium   url-fil        url-dow 0  PAN-DB cloud list loading failed (ERROR:SSL connect error).
2023/07/19 09:06:51 medium   url-fil        url-dow 0  PAN-DB cloud list loading failed (ERROR:SSL connect error).
2023/07/19 08:46:39 medium   url-fil        url-dow 0  PAN-DB cloud list loading failed (ERROR:SSL connect error).
2023/07/19 08:26:26 medium   url-fil        url-dow 0  PAN-DB cloud list loading failed (ERROR:SSL connect error).
2023/07/19 08:14:38 info     url-fil        url-bac 0  Backup of PAN-DB finished successfully.
2023/07/19 08:06:13 medium   url-fil        url-dow 0  PAN-DB cloud list loading failed (ERROR:SSL connect error).
2023/07/19 07:45:59 medium   url-fil        url-dow 0  PAN-DB cloud list loading failed (ERROR:SSL connect error).
2023/07/19 07:25:45 medium   url-fil        url-dow 0  PAN-DB cloud list loading failed (ERROR:SSL connect error).
2023/07/19 07:05:31 medium   url-fil        url-dow 0  PAN-DB cloud list loading failed (ERROR:SSL connect error).
2023/07/19 06:45:18 medium   url-fil        url-dow 0  PAN-DB cloud list loading failed (ERROR:SSL connect error).
2023/07/19 06:25:06 medium   url-fil        url-dow 0  PAN-DB cloud list loading failed (ERROR:SSL connect error).
2023/07/19 06:04:55 medium   url-fil        url-dow 0  PAN-DB cloud list loading failed (ERROR:SSL connect error).
2023/07/19 05:44:42 medium   url-fil        url-dow 0  PAN-DB cloud list loading failed (ERROR:SSL connect error).
2023/07/19 05:24:28 medium   url-fil        url-dow 0  PAN-DB cloud list loading failed (ERROR:SSL connect error).
2023/07/19 05:04:15 medium   url-fil        url-dow 0  PAN-DB cloud list loading failed (ERROR:SSL connect error).
2023/07/19 04:44:03 medium   url-fil        url-dow 0  PAN-DB cloud list loading failed (ERROR:SSL connect error).
2023/07/19 04:23:50 medium   url-fil        url-dow 0  PAN-DB cloud list loading failed (ERROR:SSL connect error).
2023/07/19 04:14:37 info     url-fil        url-bac 0  Backup of PAN-DB finished successfully.
2023/07/19 04:03:38 medium   url-fil        url-dow 0  PAN-DB cloud list loading failed (ERROR:SSL connect error).
2023/07/19 03:43:25 medium   url-fil        url-dow 0  PAN-DB cloud list loading failed (ERROR:SSL connect error).
2023/07/19 03:23:13 medium   url-fil        url-dow 0  PAN-DB cloud list loading failed (ERROR:SSL connect error).
2023/07/19 03:03:01 medium   url-fil        url-dow 0  PAN-DB cloud list loading failed (ERROR:SSL connect error).
2023/07/19 00:14:35 info     url-fil        url-bac 0  Backup of PAN-DB finished successfully.
2023/07/18 20:14:34 info     url-fil        url-bac 0  Backup of PAN-DB finished successfully.
2023/07/18 16:14:33 info     url-fil        url-bac 0  Backup of PAN-DB finished successfully.


(active)&amp;gt; delete license key
  Advanced_URL_Filtering_2023_07_18_94880943.key   2023/07/19 07:40:31        0.3K&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;(active)&amp;gt; show url-cloud status

PAN-DB URL Filtering
License :                          valid
Cloud connection :                 not connected
URL database version - device :    0000.00.00.000
URL protocol version - device :    pan/0.0.

(active)&amp;gt; ping host s0000.urlcloud.paloaltonetworks.com
PING s000new.urlcloud.paloaltonetworks.com (35.244.200.72) 56(84) bytes of data.
64 bytes from 72.200.244.35.bc.googleusercontent.com (35.244.200.72): icmp_seq=1 ttl=55 time=17.9 ms
64 bytes from 72.200.244.35.bc.googleusercontent.com (35.244.200.72): icmp_seq=2 ttl=55 time=17.9 ms&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 19 Jul 2023 21:32:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/not-resolved-url-blocking-pan-url-cloud-updates/m-p/550070#M1966</guid>
      <dc:creator>drewdown</dc:creator>
      <dc:date>2023-07-19T21:32:04Z</dc:date>
    </item>
    <item>
      <title>Re: Not-resolved URL blocking PAN url cloud updates</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/not-resolved-url-blocking-pan-url-cloud-updates/m-p/550080#M1967</link>
      <description>&lt;P&gt;Welp..&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;I changed all those service routes to use my MGMT interface (didn't work using outside interface or any other one)&lt;/LI&gt;
&lt;LI&gt;I added &lt;STRONG&gt;pan-db-cloud&lt;/STRONG&gt; to my&amp;nbsp; list of allowed APPs&lt;/LI&gt;
&lt;LI&gt;I changed the unresolved category to ALERT vs block/block.&amp;nbsp;&lt;/LI&gt;
&lt;LI&gt;I deleted all the old license key files from the CLI&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;Why after 6+ years I had to do all this I have no idea..I can't say what broke or what fixed it but its working again.&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;PAN-DB URL Filtering
License :                          valid
Current cloud server :             serverlist3.urlcloud.paloaltonetworks.com
Cloud connection :                 connected
Cloud mode :                       public
URL database version - device :    20230719.20330
URL database version - cloud :     20230719.20330  ( last update time 2023/07/19 16:38:48 )
URL database status :              good
URL protocol version - device :    pan/2.0.0
URL protocol version - cloud :     pan/2.0.0
Protocol compatibility status :    compatible&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="drewdown_0-1689804009729.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/51801i8482483D069C4A3E/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="drewdown_0-1689804009729.png" alt="drewdown_0-1689804009729.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;DIV id="tinyMceEditor_15ef82254cee1fdrewdown_1" class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="drewdown_2-1689804061578.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/51803i026B56A6305E14EE/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="drewdown_2-1689804061578.png" alt="drewdown_2-1689804061578.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 19 Jul 2023 22:04:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/not-resolved-url-blocking-pan-url-cloud-updates/m-p/550080#M1967</guid>
      <dc:creator>drewdown</dc:creator>
      <dc:date>2023-07-19T22:04:39Z</dc:date>
    </item>
    <item>
      <title>Re: Not-resolved URL blocking PAN url cloud updates</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/not-resolved-url-blocking-pan-url-cloud-updates/m-p/550133#M1968</link>
      <description>&lt;P&gt;Yes, I have had this happen before. The default URL Filtering profile action for "unknown" and "not-resolved" is allow, but I suspect many people setup custom URL Filtering profiles to block or continue for additional security. When you upgrade from the PAN-DB database to URL-Cloud database (8.x to 9.x) the database is defaulted and must be repopulated from the cloud. I have also had the URL-Cloud database mysteriously reset and need to re-initialize. Unfortunately when this happens the URLs needed to initialize the database become "not-resolved" and are blocked in your custom URL Filter...&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;To handle this startup case I added "*.urlcloud.paloaltonetworks.com/" to a Custom URL Category object that always allows in my custom URL Filtering profiles. Since Custom URL Categories are defined outside of URL-Cloud they always resolve, and that allows the *.urlcloud.paloaltonetworks.com update addresses to pass URL Filtering, even when the URL-Cloud database is uninitialized or broken.&lt;/P&gt;</description>
      <pubDate>Thu, 20 Jul 2023 07:06:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/not-resolved-url-blocking-pan-url-cloud-updates/m-p/550133#M1968</guid>
      <dc:creator>Adrian_Jensen</dc:creator>
      <dc:date>2023-07-20T07:06:00Z</dc:date>
    </item>
    <item>
      <title>Re: Not-resolved URL blocking PAN url cloud updates</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/not-resolved-url-blocking-pan-url-cloud-updates/m-p/550179#M1969</link>
      <description>&lt;P&gt;Which is what we did, un-resolved was set to block and I believe PA told me to do that but when doing that you can be left in the lurch like I was.&amp;nbsp; No upgrade was done of late as all of my PANs are running 9.1.14-h as that is the latest version the majority of them support.&amp;nbsp;&amp;nbsp;I am going to take your suggestion and add&amp;nbsp;&lt;SPAN&gt;*.urlcloud.paloaltonetworks.com/ to my profiles.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Another odd thing I noticed, all of my URL category/Filters are from Panorama but when I make a change to them in the BRANCHES level I don't get the option to push it to my firewalls.&amp;nbsp; Only COMMIT.&amp;nbsp; &amp;nbsp;I see whatever change I made in those device groups but again no way to PUSH it.&amp;nbsp; So right now something is broken that won't let me push any URL category changes down to the firewalls from Panroama.&amp;nbsp; I also see Panorama shows a different URL category then what the local FWs show via CLI.&amp;nbsp; So something is wrong here and I can't seem to figure out what that is.&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Anyone know why that is?&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 20 Jul 2023 15:20:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/not-resolved-url-blocking-pan-url-cloud-updates/m-p/550179#M1969</guid>
      <dc:creator>drewdown</dc:creator>
      <dc:date>2023-07-20T15:20:28Z</dc:date>
    </item>
  </channel>
</rss>

