<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Global Protect Datafile Version mismatch in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-datafile-version-mismatch/m-p/33741#M24764</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Im working thru the process to roll out the Global Protect VPN software to our laptop users - I have three PA boxes, a 2050 and two 2020s - all are running 4.1.3, all have GP gateway licences &amp;amp; client 1.1.4 installed although we only have one portal licence for the 2050 (and so only one portal configured).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have the portal setup &amp;amp; publishing a profile with all three gateways in it, it appears to work correctly &amp;amp; connect you to the closest gateway - good ! - the next step is to setup the HIP profiles to control which machines are allowed access to the internal network. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I notice that I have different versions of the GP datafile on each box - Dynamic Update is set to check daily &amp;amp; everything else (URL filter, threats etc) are in sync - but the GP datafiles are not. They are updating, but the versions appear to be different for each gateway.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The versions I have are:&lt;/P&gt;&lt;P&gt;2050&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1332385291&lt;/P&gt;&lt;P&gt;2020&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1332381691&lt;/P&gt;&lt;P&gt;2020&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1332183690&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- so the question is why are they different, &amp;amp; will that be a problem when I enable the HIP checks ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks - Nick.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 22 Mar 2012 14:23:35 GMT</pubDate>
    <dc:creator>SimmSimm</dc:creator>
    <dc:date>2012-03-22T14:23:35Z</dc:date>
    <item>
      <title>Global Protect Datafile Version mismatch</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-datafile-version-mismatch/m-p/33741#M24764</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Im working thru the process to roll out the Global Protect VPN software to our laptop users - I have three PA boxes, a 2050 and two 2020s - all are running 4.1.3, all have GP gateway licences &amp;amp; client 1.1.4 installed although we only have one portal licence for the 2050 (and so only one portal configured).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have the portal setup &amp;amp; publishing a profile with all three gateways in it, it appears to work correctly &amp;amp; connect you to the closest gateway - good ! - the next step is to setup the HIP profiles to control which machines are allowed access to the internal network. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I notice that I have different versions of the GP datafile on each box - Dynamic Update is set to check daily &amp;amp; everything else (URL filter, threats etc) are in sync - but the GP datafiles are not. They are updating, but the versions appear to be different for each gateway.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The versions I have are:&lt;/P&gt;&lt;P&gt;2050&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1332385291&lt;/P&gt;&lt;P&gt;2020&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1332381691&lt;/P&gt;&lt;P&gt;2020&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1332183690&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- so the question is why are they different, &amp;amp; will that be a problem when I enable the HIP checks ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks - Nick.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 22 Mar 2012 14:23:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-datafile-version-mismatch/m-p/33741#M24764</guid>
      <dc:creator>SimmSimm</dc:creator>
      <dc:date>2012-03-22T14:23:35Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect Datafile Version mismatch</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-datafile-version-mismatch/m-p/33742#M24765</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi SimmSimm,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It looks like there are a couple different sites we pull these data files from. You may need to get a case open for us to fully review it, but my assumption is each site is giving a different data file.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can run:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;gt; less mp-log avdata.log&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-----Example Output&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;lt;GlobalProtect xmlns:xsi="&lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://www.w3.org/2001/XMLSchema-instance"&gt;http://www.w3.org/2001/XMLSchema-instance&lt;/A&gt;&lt;SPAN&gt;" xmlns:xsd="&lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://www.w3.org/2001/XMLSchema"&gt;http://www.w3.org/2001/XMLSchema&lt;/A&gt;&lt;SPAN&gt;" xmlns="&lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://www.paloaltonetworks.com/"&gt;http://www.paloaltonetworks.com/&lt;/A&gt;&lt;SPAN&gt;"&amp;gt;&amp;nbsp; &amp;lt;result&amp;gt;New version found.&amp;lt;/result&amp;gt;&amp;nbsp; &amp;lt;file_version&amp;gt;1332460882&amp;lt;/file_version&amp;gt;&amp;nbsp; &amp;lt;lastModified&amp;gt;2012-03-22T17:12:09&amp;lt;/lastModified&amp;gt;&amp;nbsp; &amp;lt;file_location&amp;gt;&lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://c733.r33.cf1.rackcdn.com/epupdate_hist.140"&gt;http://c733.r33.cf1.rackcdn.com/epupdate_hist.140&lt;/A&gt;&lt;SPAN&gt;&amp;lt;/file_location&amp;gt;&amp;nbsp; &amp;lt;encryption_key&amp;gt;21728451bcb06c96dab005f3a8ae55450e16114f731ce0a40b6eb292c246ef6a&amp;lt;/encryption_key&amp;gt;&amp;lt;/GlobalProtect&amp;gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-----Example Output&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can then see which location each device went and what data file version it pulled down. Perhaps comparing this output on each device will yield some information for you.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I don't think this will cause an issue if you enable HIP checks, because according to the documentation the files just contain a list of vendors.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"The &lt;STRONG&gt;GlobalProtet Data File&lt;/STRONG&gt;, located on the &lt;STRONG&gt;Device&lt;/STRONG&gt; tab&amp;gt; &lt;STRONG&gt;Dynamic Updates, &lt;/STRONG&gt;contains the OPSWAT file that lists the vendors to be used in the HIP object configuration.&amp;nbsp; You must have valid Global Protect Gateway and Portal licensing and configure the&lt;STRONG&gt;Schedule &lt;/STRONG&gt;for the downloads before they will occur."&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jason Seals&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 23 Mar 2012 01:32:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-datafile-version-mismatch/m-p/33742#M24765</guid>
      <dc:creator>jseals</dc:creator>
      <dc:date>2012-03-23T01:32:58Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect Datafile Version mismatch</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-datafile-version-mismatch/m-p/33743#M24766</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Jason - thanks - thats useful.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The answer seems to be that the servers are in different timezones &amp;amp; the GP datafile versions seem to be changing hourly: &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="text-decoration: underline;"&gt;For the London server in GMT TZ, I see:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;﻿﻿&amp;lt;GlobalProtect xmlns:xsi="&lt;A href="http://www.w3.org/2001/XMLSchema-instance&amp;amp;quot;" style="color: #3465a4;"&gt;http://www.w3.org/2001/XMLSchema-instance"&lt;/A&gt; xmlns:xsd="&lt;A href="http://www.w3.org/2001/XMLSchema&amp;amp;quot;" style="color: #3465a4;"&gt;http://www.w3.org/2001/XMLSchema"&lt;/A&gt; xmlns="&lt;A href="http://www.paloaltonetworks.com/&amp;amp;quot;&amp;gt;" style="color: #3465a4;"&gt;http://www.paloaltonetworks.com/"&amp;gt;&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;lt;result&amp;gt;New version found.&amp;lt;/result&amp;gt;&lt;BR /&gt; &amp;lt;file_version&amp;gt;1332471712&amp;lt;/file_version&amp;gt;&lt;BR /&gt; &amp;lt;lastModified&amp;gt;2012-03-22T20:12:08&amp;lt;/lastModified&amp;gt;&lt;BR /&gt; &amp;lt;file_location&amp;gt;&lt;A href="http://c733.r33.cf1.rackcdn.com/epupdate_hist.142&amp;lt;/file_location&amp;gt;" style="color: #3465a4;"&gt;http://c733.r33.cf1.rackcdn.com/epupdate_hist.142&amp;lt;/file_location&amp;gt;&lt;/A&gt;&lt;BR /&gt; &amp;lt;encryption_key&amp;gt;a74d03595fdfc36b0f4df117f303955b1b250669671a1b140881c60da227743b&amp;lt;/encryption_key&amp;gt;&lt;BR /&gt;&amp;lt;/GlobalProtect&amp;gt;&lt;BR /&gt;Fri Mar 23 04:05:04 GMT 2012 : update version exist&lt;BR /&gt;Fri Mar 23 04:05:04 GMT 2012 : file location &lt;A class="active_link" href="http://c733.r33.cf1.rackcdn.com/epupdate_hist.142" style="color: #3465a4;"&gt;http://c733.r33.cf1.rackcdn.com/epupdate_hist.142&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="text-decoration: underline;"&gt;For the Europe server in CET TZ I see:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;lt;GlobalProtect xmlns:xsi="&lt;A href="http://www.w3.org/2001/XMLSchema-instance&amp;amp;quot;" style="color: #3465a4;"&gt;http://www.w3.org/2001/XMLSchema-instance"&lt;/A&gt; xmlns:xsd="&lt;A href="http://www.w3.org/2001/XMLSchema&amp;amp;quot;" style="color: #3465a4;"&gt;http://www.w3.org/2001/XMLSchema"&lt;/A&gt; xmlns="&lt;A href="http://www.paloaltonetworks.com/&amp;amp;quot;&amp;gt;" style="color: #3465a4;"&gt;http://www.paloaltonetworks.com/"&amp;gt;&lt;/A&gt;&lt;BR /&gt; &amp;lt;result&amp;gt;New version found.&amp;lt;/result&amp;gt;&lt;BR /&gt; &amp;lt;file_version&amp;gt;1332468075&amp;lt;/file_version&amp;gt;&lt;BR /&gt; &amp;lt;lastModified&amp;gt;2012-03-22T19:12:09&amp;lt;/lastModified&amp;gt;&lt;BR /&gt; &amp;lt;file_location&amp;gt;&lt;A href="http://c733.r33.cf1.rackcdn.com/epupdate_hist.141&amp;lt;/file_location&amp;gt;" style="color: #3465a4;"&gt;http://c733.r33.cf1.rackcdn.com/epupdate_hist.141&amp;lt;/file_location&amp;gt;&lt;/A&gt;&lt;BR /&gt; &amp;lt;encryption_key&amp;gt;c6bb1d1662a63d7426f91d3d00b6c68c777bbad5d21f6fee99798d4514965fa0&amp;lt;/encryption_key&amp;gt;&lt;BR /&gt;&amp;lt;/GlobalProtect&amp;gt;&lt;BR /&gt;Fri Mar 23 04:05:04 CET 2012 : update version exist&lt;BR /&gt;Fri Mar 23 04:05:04 CET 2012 : file location &lt;A class="active_link" href="http://c733.r33.cf1.rackcdn.com/epupdate_hist.141" style="color: #3465a4;"&gt;http://c733.r33.cf1.rackcdn.com/epupdate_hist.141&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="text-decoration: underline;"&gt;&amp;amp; for the Asia server in HKT I see:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;lt;GlobalProtect xmlns:xsi="&lt;A href="http://www.w3.org/2001/XMLSchema-instance&amp;amp;quot;" style="color: #3465a4;"&gt;http://www.w3.org/2001/XMLSchema-instance"&lt;/A&gt; xmlns:xsd="&lt;A href="http://www.w3.org/2001/XMLSchema&amp;amp;quot;" style="color: #3465a4;"&gt;http://www.w3.org/2001/XMLSchema"&lt;/A&gt; xmlns="&lt;A href="http://www.paloaltonetworks.com/&amp;amp;quot;&amp;gt;" style="color: #3465a4;"&gt;http://www.paloaltonetworks.com/"&amp;gt;&lt;/A&gt;&lt;BR /&gt; &amp;lt;result&amp;gt;New version found.&amp;lt;/result&amp;gt;&lt;BR /&gt; &amp;lt;file_version&amp;gt;1332442882&amp;lt;/file_version&amp;gt;&lt;BR /&gt; &amp;lt;lastModified&amp;gt;2012-03-22T12:12:07&amp;lt;/lastModified&amp;gt;&lt;BR /&gt; &amp;lt;file_location&amp;gt;&lt;A href="http://c733.r33.cf1.rackcdn.com/epupdate_hist.135&amp;lt;/file_location&amp;gt;" style="color: #3465a4;"&gt;http://c733.r33.cf1.rackcdn.com/epupdate_hist.135&amp;lt;/file_location&amp;gt;&lt;/A&gt;&lt;BR /&gt; &amp;lt;encryption_key&amp;gt;2f155bda6a20349c1259fce9cedeb554f207bce85b579dfcf0093d4632af94a4&amp;lt;/encryption_key&amp;gt;&lt;BR /&gt;&amp;lt;/GlobalProtect&amp;gt;&lt;BR /&gt;Fri Mar 23 04:02:10 HKT 2012 : update version exist&lt;BR /&gt;Fri Mar 23 04:02:10 HKT 2012 : file location &lt;A class="active_link" href="http://c733.r33.cf1.rackcdn.com/epupdate_hist.135" style="color: #3465a4;"&gt;http://c733.r33.cf1.rackcdn.com/epupdate_hist.135&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So I expect that if I set the update to hourly for GP datafile all three should get into sync.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For completeness, the reason that I would like them in sync is that I use Panorama to push a global HIP policy, &amp;amp; appear to have had policy fail to load on one gateway in the past because vendor information that I use in the HIP objects is not available in the version of the datafile on that gateway, but is available on the others.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks - Nick.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 23 Mar 2012 10:29:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-datafile-version-mismatch/m-p/33743#M24766</guid>
      <dc:creator>SimmSimm</dc:creator>
      <dc:date>2012-03-23T10:29:46Z</dc:date>
    </item>
  </channel>
</rss>

