<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Active/Passive - Failed to check Antivirus content upgrade info due to generic communication error in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/active-passive-failed-to-check-antivirus-content-upgrade-info/m-p/24902#M18175</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Steven,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If the firewalls are configured to use an L3 interface to go out for updates (Device &amp;gt; Setup &amp;gt; Services tab &amp;gt; Service Route Configuration), the default setting for the passive L3 interfaces is to be down. This setting allows them to become active during a failure of the primary and ARP for the shared IP.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The management interface is still up even when a device is in the passive state, so if the service route is configured to use that interface and you can configure a route on the connected devices to allow Internet access from that interface you should be able to eliminate those messages.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You could also disable antivirus checking on the passive unit ensuring that the active syncs it, but that would stop updates if a failure happened.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps,&lt;/P&gt;&lt;P&gt;Greg&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 22 Jul 2013 16:24:50 GMT</pubDate>
    <dc:creator>gwesson</dc:creator>
    <dc:date>2013-07-22T16:24:50Z</dc:date>
    <item>
      <title>Active/Passive - Failed to check Antivirus content upgrade info due to generic communication error</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/active-passive-failed-to-check-antivirus-content-upgrade-info/m-p/24901#M18174</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I am getting a daily notification that states that&lt;STRONG&gt; Failed to check Antivirus content upgrade info due to generic communication error&lt;/STRONG&gt; . I have a HA Active/Passive set up on my network.&amp;nbsp; The Active is connecting to updates.paloaltonetworks.com fine and is getting the most recent verison, and there is a Green Dot that connection is okay from the Management Interface.&amp;nbsp; I believe however, that the alerts are being sent out from the Passive device for some reason even though the two devices are connected together fine.&amp;nbsp; Any help on how to verify that things are okay on the cluster, and how to stop these Alerts from being sent?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;TABLE jive-data-cell="{&amp;quot;color&amp;quot;:&amp;quot;#575757&amp;quot;,&amp;quot;textAlign&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;padding&amp;quot;:&amp;quot;NaN&amp;quot;,&amp;quot;backgroundColor&amp;quot;:&amp;quot;transparent&amp;quot;,&amp;quot;fontFamily&amp;quot;:&amp;quot;arial,helvetica,sans-serif&amp;quot;}" jive-data-header="{&amp;quot;color&amp;quot;:&amp;quot;#FFFFFF&amp;quot;,&amp;quot;backgroundColor&amp;quot;:&amp;quot;#6690BC&amp;quot;,&amp;quot;textAlign&amp;quot;:&amp;quot;center&amp;quot;,&amp;quot;padding&amp;quot;:&amp;quot;2&amp;quot;}"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD class="label" style="text-align: right;"&gt;Model&lt;/TD&gt;&lt;TD style="padding-left: 10px;"&gt;PA-4020&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD class="label" style="text-align: right;"&gt;Software version&lt;/TD&gt;&lt;TD style="padding-left: 10px;"&gt;4.1.11&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD class="label" style="text-align: right;"&gt;GlobalProtect &lt;BR /&gt;Client&lt;/TD&gt;&lt;TD style="padding-left: 10px;"&gt;1.1.6&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD class="label" style="text-align: right;"&gt;Application version&lt;/TD&gt;&lt;TD style="padding-left: 10px;"&gt;384-1877&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD class="label" style="text-align: right;"&gt;Threat version&lt;/TD&gt;&lt;TD style="padding-left: 10px;"&gt;384-1877&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD class="label" style="text-align: right;"&gt;Antivirus version&lt;/TD&gt;&lt;TD style="padding-left: 10px;"&gt;1061-1478&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 22 Jul 2013 15:17:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/active-passive-failed-to-check-antivirus-content-upgrade-info/m-p/24901#M18174</guid>
      <dc:creator>steven_walbroehl</dc:creator>
      <dc:date>2013-07-22T15:17:58Z</dc:date>
    </item>
    <item>
      <title>Re: Active/Passive - Failed to check Antivirus content upgrade info due to generic communication error</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/active-passive-failed-to-check-antivirus-content-upgrade-info/m-p/24902#M18175</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Steven,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If the firewalls are configured to use an L3 interface to go out for updates (Device &amp;gt; Setup &amp;gt; Services tab &amp;gt; Service Route Configuration), the default setting for the passive L3 interfaces is to be down. This setting allows them to become active during a failure of the primary and ARP for the shared IP.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The management interface is still up even when a device is in the passive state, so if the service route is configured to use that interface and you can configure a route on the connected devices to allow Internet access from that interface you should be able to eliminate those messages.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You could also disable antivirus checking on the passive unit ensuring that the active syncs it, but that would stop updates if a failure happened.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps,&lt;/P&gt;&lt;P&gt;Greg&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 22 Jul 2013 16:24:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/active-passive-failed-to-check-antivirus-content-upgrade-info/m-p/24902#M18175</guid>
      <dc:creator>gwesson</dc:creator>
      <dc:date>2013-07-22T16:24:50Z</dc:date>
    </item>
  </channel>
</rss>

