<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: New Palo Alto User - Dynamic Block List in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/new-palo-alto-user-dynamic-block-list/m-p/19769#M14424</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Usually, PA uses own MGT port as a source port.&lt;/P&gt;&lt;P&gt;Are you connecting MGT port to your network and is it reachable from MGT to Win2003?&lt;/P&gt;&lt;P&gt;My PA-200 with 5.0.4 is working fine for Dynamic Block List.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Emr&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 18 Apr 2013 04:32:52 GMT</pubDate>
    <dc:creator>emr_1</dc:creator>
    <dc:date>2013-04-18T04:32:52Z</dc:date>
    <item>
      <title>New Palo Alto User - Dynamic Block List</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/new-palo-alto-user-dynamic-block-list/m-p/19768#M14423</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi there,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I just got a new Palo Alto and I would like to load some IPs in a Dynamic Block List.&amp;nbsp; I have set up a Windows IIS Webserver on an old Server 2003 box with an IP 192.168.1.33&amp;nbsp; I have the site up and working and anoymous users can connect to it by going to &lt;A href="http://192.168.1.33/test.txt"&gt;http://192.168.1.33/test.txt&lt;/A&gt;.&amp;nbsp; The document test.txt and is formatted like so:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;192.168.1.97&lt;/P&gt;&lt;P&gt;192.168.1.98&lt;/P&gt;&lt;P&gt;192.168.1.99&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When I configure the Dynamic Block List and click "Test URL"&amp;nbsp; I get URL Access Error.&amp;nbsp; If I use a non-domain account or computer on the network and type the URL as above I get access to the site.&amp;nbsp; Can anyone advise what I am missing to get this to work?&amp;nbsp; I have tried turning off the firewall, I can connect with anoymous users, there are no error logs on the server, wireshark doesn't show any attempt or traffic from the firewall IP when I click test URL.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for any advice!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 18 Apr 2013 00:23:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/new-palo-alto-user-dynamic-block-list/m-p/19768#M14423</guid>
      <dc:creator>dmodien</dc:creator>
      <dc:date>2013-04-18T00:23:23Z</dc:date>
    </item>
    <item>
      <title>Re: New Palo Alto User - Dynamic Block List</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/new-palo-alto-user-dynamic-block-list/m-p/19769#M14424</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Usually, PA uses own MGT port as a source port.&lt;/P&gt;&lt;P&gt;Are you connecting MGT port to your network and is it reachable from MGT to Win2003?&lt;/P&gt;&lt;P&gt;My PA-200 with 5.0.4 is working fine for Dynamic Block List.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Emr&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 18 Apr 2013 04:32:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/new-palo-alto-user-dynamic-block-list/m-p/19769#M14424</guid>
      <dc:creator>emr_1</dc:creator>
      <dc:date>2013-04-18T04:32:52Z</dc:date>
    </item>
    <item>
      <title>Re: New Palo Alto User - Dynamic Block List</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/new-palo-alto-user-dynamic-block-list/m-p/19770#M14425</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Have you checked if your management ip has access to that ip address ? &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 18 Apr 2013 04:33:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/new-palo-alto-user-dynamic-block-list/m-p/19770#M14425</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2013-04-18T04:33:29Z</dc:date>
    </item>
    <item>
      <title>Re: New Palo Alto User - Dynamic Block List</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/new-palo-alto-user-dynamic-block-list/m-p/19771#M14426</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I'm running 5.0.2 on a 5060 and have the same problem.&amp;nbsp; The firewall is wide open to the 5060 and I'm running tcpdump on the webserver, with no sign that the 5060 has even tried to connect to port 80 and retrieve the page.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We will be upgrading to 5.0.4, so hopefully this problem goes away with the upgrade.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 26 Apr 2013 19:21:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/new-palo-alto-user-dynamic-block-list/m-p/19771#M14426</guid>
      <dc:creator>MashRotor</dc:creator>
      <dc:date>2013-04-26T19:21:01Z</dc:date>
    </item>
    <item>
      <title>Re: New Palo Alto User - Dynamic Block List</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/new-palo-alto-user-dynamic-block-list/m-p/19772#M14427</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Do you want the management interface to access the dynamic block list&lt;/P&gt;&lt;P&gt;If so, &lt;/P&gt;&lt;P&gt;1. the dynamic block list must be referenced in a security policy&lt;/P&gt;&lt;P&gt;2. the management interface must have access to the web server that houses the dynamic block list&lt;/P&gt;&lt;P&gt;3. If you have a service route for the URL (brightcloud updates) pointing out of the Untrust or the Trust interface, the request for the dynamic block list will also go out that way as such you must then create as service route explicitly stating that to get to the web server with the block list use the management interface (you can configure this in the right hand panel of the service router configuration)&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 26 Apr 2013 22:40:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/new-palo-alto-user-dynamic-block-list/m-p/19772#M14427</guid>
      <dc:creator>sjamaluddin</dc:creator>
      <dc:date>2013-04-26T22:40:25Z</dc:date>
    </item>
    <item>
      <title>Re: New Palo Alto User - Dynamic Block List</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/new-palo-alto-user-dynamic-block-list/m-p/19773#M14428</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;My problem was fixed by adding a service route under device, service tab and then clicking add service route.&amp;nbsp; In this section I had to add info specifying that the PA use internal interface to reach my web server rather than the management IP.&amp;nbsp; This was pretty easy and it worked immediately after the commit.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks to everyone who responded.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 26 Apr 2013 23:55:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/new-palo-alto-user-dynamic-block-list/m-p/19773#M14428</guid>
      <dc:creator>dmodien</dc:creator>
      <dc:date>2013-04-26T23:55:50Z</dc:date>
    </item>
  </channel>
</rss>

