<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Palo Alto Software/Threat/AntiVirus Update Policy in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-software-threat-antivirus-update-policy/m-p/26432#M19278</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am having an internet facing firewall which needs to be kept updated with the Threat/AV software. &lt;/P&gt;&lt;P&gt;I have configured the service route to use the correct interface for updates. However, it still cant check and download the required updates. As its evident I need to have a policy in place to allow the above traffic. I know what source to use, but can some one shed light on the destination address? Should I use "Any" with application as paloalto-updates?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Many thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 25 Oct 2013 10:53:32 GMT</pubDate>
    <dc:creator>DCN</dc:creator>
    <dc:date>2013-10-25T10:53:32Z</dc:date>
    <item>
      <title>Palo Alto Software/Threat/AntiVirus Update Policy</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-software-threat-antivirus-update-policy/m-p/26432#M19278</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am having an internet facing firewall which needs to be kept updated with the Threat/AV software. &lt;/P&gt;&lt;P&gt;I have configured the service route to use the correct interface for updates. However, it still cant check and download the required updates. As its evident I need to have a policy in place to allow the above traffic. I know what source to use, but can some one shed light on the destination address? Should I use "Any" with application as paloalto-updates?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Many thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 25 Oct 2013 10:53:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-software-threat-antivirus-update-policy/m-p/26432#M19278</guid>
      <dc:creator>DCN</dc:creator>
      <dc:date>2013-10-25T10:53:32Z</dc:date>
    </item>
    <item>
      <title>Re: Palo Alto Software/Threat/AntiVirus Update Policy</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-software-threat-antivirus-update-policy/m-p/26433#M19279</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Please check what you have configured in this plase&lt;/P&gt;&lt;P&gt;&lt;IMG alt="2013-10-25_171240.png" class="jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/9430_2013-10-25_171240.png" style="width: 620px; height: 232px;" /&gt;&lt;/P&gt;&lt;P&gt;I have IP of my untrust interfece in CRL status field.&lt;/P&gt;&lt;P&gt;Please log by SSH and check that you can ping from managemet interface any internet site.&lt;/P&gt;&lt;P&gt;As I remember to get updates after first run of my PA device I have to do check for upates few time...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Slawek&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 25 Oct 2013 15:15:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-software-threat-antivirus-update-policy/m-p/26433#M19279</guid>
      <dc:creator>_slv_</dc:creator>
      <dc:date>2013-10-25T15:15:43Z</dc:date>
    </item>
    <item>
      <title>Re: Palo Alto Software/Threat/AntiVirus Update Policy</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-software-threat-antivirus-update-policy/m-p/26434#M19280</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;HI,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Fro me two things:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; - Or you want to use Management interface for updating your palo and this traffic go through the palo himself then,&amp;nbsp; you need to create policy allowing taffic from management ip to dns named object " updates.paloaltonetworks.com" and pan-update app on Https&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; - Or you enable the palo update from your outside interface and in this case just keep in ming to allow traffic from your outside zone to outside zone (Traffic denied automatically as soon as you create a deny all policy).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope Help&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;V.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 27 Oct 2013 15:34:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-software-threat-antivirus-update-policy/m-p/26434#M19280</guid>
      <dc:creator>VinceM</dc:creator>
      <dc:date>2013-10-27T15:34:56Z</dc:date>
    </item>
    <item>
      <title>Re: Palo Alto Software/Threat/AntiVirus Update Policy</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-software-threat-antivirus-update-policy/m-p/26435#M19281</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for your response slv and VinceM.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am using an outside interface for update in my case. While writing the policy I have the source as my outside interface (public IP) and destination as ANY, and applications as paloalto-updates, ssl and couple of other paloalto applications.&lt;/P&gt;&lt;P&gt;My question is do I have keep the destination address in policy as "ANY". I understand the IP for updates changes frequently and the actual updates are hosted at akamai servers, IP of which changes every time as well.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 28 Oct 2013 14:21:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-software-threat-antivirus-update-policy/m-p/26435#M19281</guid>
      <dc:creator>DCN</dc:creator>
      <dc:date>2013-10-28T14:21:44Z</dc:date>
    </item>
    <item>
      <title>Re: Palo Alto Software/Threat/AntiVirus Update Policy</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-software-threat-antivirus-update-policy/m-p/26436#M19282</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The short answer is that if yet set an address you'll have to frequently change it&amp;nbsp; Using the FDQN name accessed might be more helpful. &lt;/P&gt;&lt;P&gt;You can keep the FDQN the same as that doesn't change but the IP address would need to changed on a regular basis. Since the FDQN is common to both the firewall and the update program the addresses for the policy and the updates will be the same. While I haven't done this for the updates, I've used this approach successfully with other hosts that tended to shift their IP addresses.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 28 Oct 2013 16:06:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-software-threat-antivirus-update-policy/m-p/26436#M19282</guid>
      <dc:creator>SMF</dc:creator>
      <dc:date>2013-10-28T16:06:20Z</dc:date>
    </item>
    <item>
      <title>Re: Palo Alto Software/Threat/AntiVirus Update Policy</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-software-threat-antivirus-update-policy/m-p/26437#M19283</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks SMF. &lt;/P&gt;&lt;P&gt;I didnt knew I can add FQDN as destination. To add that I had to create an object, thats where it gives the option of FQDN, and then added that object as destination.&lt;/P&gt;&lt;P&gt;Now I am able to check the updates, however downloading the updates is being denied. I assume the IP of which is not covered under the update URL.&lt;/P&gt;&lt;P&gt;Can you help in what subnet /URL should I include to get the download working as well.&lt;/P&gt;&lt;P&gt;I have allowed SSL applicaion in the policy.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 29 Oct 2013 09:49:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-software-threat-antivirus-update-policy/m-p/26437#M19283</guid>
      <dc:creator>DCN</dc:creator>
      <dc:date>2013-10-29T09:49:56Z</dc:date>
    </item>
  </channel>
</rss>

