<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: brightcloud active option unavailable in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/brightcloud-active-option-unavailable/m-p/66418#M39196</link>
    <description>&lt;P&gt;Hi Tom,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Thanks for the reply.&lt;/P&gt;&lt;P&gt;I did a packet caputre on the firewall I found that CA of next hop is not trusted by palo alto.&lt;/P&gt;&lt;P&gt;In my scenario palo alto is behind the proxy server, during the connection palo alto doesnt trust the proxy.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;IMG src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/618i449EDF13E2BC44B7/image-size/original?v=mpbl-1&amp;amp;px=-1" alt="pcap.PNG" title="pcap.PNG" border="0" /&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;And in the certificate trust list, import option is unavaiable.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;IMG src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/619i940FC244F50F8347/image-size/original?v=mpbl-1&amp;amp;px=-1" alt="trustlist.PNG" title="trustlist.PNG" border="0" /&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;kindly give some suggestions.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;with regards,&lt;/P&gt;&lt;P&gt;Ram.&lt;/P&gt;</description>
    <pubDate>Mon, 12 Oct 2015 10:16:01 GMT</pubDate>
    <dc:creator>Gururaj</dc:creator>
    <dc:date>2015-10-12T10:16:01Z</dc:date>
    <item>
      <title>brightcloud active option unavailable</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/brightcloud-active-option-unavailable/m-p/66402#M39185</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; We couldn't activate brightcloud url filtering with our old database.&lt;/P&gt;&lt;P&gt;I have attached the screenshot for you reference, kindly look into it and help.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;with regards,&lt;/P&gt;&lt;P&gt;Ram&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;IMG src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/614iBCB7B8C1CD92A08B/image-size/original?v=mpbl-1&amp;amp;px=-1" alt="PA_URL_license.png" title="PA_URL_license.png" border="0" /&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 12 Oct 2015 07:32:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/brightcloud-active-option-unavailable/m-p/66402#M39185</guid>
      <dc:creator>Gururaj</dc:creator>
      <dc:date>2015-10-12T07:32:30Z</dc:date>
    </item>
    <item>
      <title>Re: brightcloud active option unavailable</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/brightcloud-active-option-unavailable/m-p/66412#M39193</link>
      <description>&lt;P&gt;Hi Ram&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It looks like the device is having trouble downloading the DB on both URL filtering, you may need to troubleshoot connectivity from your management interface towards the internet first before you'll be able to switch databases.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You'll want to verify if DNS is being resolved&lt;/P&gt;
&lt;PRE&gt;&amp;gt; ping host service.brightcloud.com
&amp;gt; ping host updates.paloaltonetworks.com&lt;/PRE&gt;
&lt;P&gt;Don't worry if you don't get ping replies, these services don't respond to ping, but it's an easy way to check if your firewall is able to resolve DNS for these hosts. If the IP is not resolcved, please verify your DNS settings.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Next you can try a manual download&lt;/P&gt;
&lt;PRE&gt;&amp;gt; request url-filtering upgrade brightcloud
&amp;gt; request url-filtering download status vendor brightcloud&lt;/PRE&gt;
&lt;P&gt;If this is still failing you may need to verify your traffic logs to see if the download is being blocked by a security policy&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Once the DB is downloaded you should be able to active the url filtering&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;hope this helps&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;</description>
      <pubDate>Mon, 12 Oct 2015 09:52:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/brightcloud-active-option-unavailable/m-p/66412#M39193</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2015-10-12T09:52:32Z</dc:date>
    </item>
    <item>
      <title>Re: brightcloud active option unavailable</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/brightcloud-active-option-unavailable/m-p/66418#M39196</link>
      <description>&lt;P&gt;Hi Tom,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Thanks for the reply.&lt;/P&gt;&lt;P&gt;I did a packet caputre on the firewall I found that CA of next hop is not trusted by palo alto.&lt;/P&gt;&lt;P&gt;In my scenario palo alto is behind the proxy server, during the connection palo alto doesnt trust the proxy.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;IMG src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/618i449EDF13E2BC44B7/image-size/original?v=mpbl-1&amp;amp;px=-1" alt="pcap.PNG" title="pcap.PNG" border="0" /&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;And in the certificate trust list, import option is unavaiable.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;IMG src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/619i940FC244F50F8347/image-size/original?v=mpbl-1&amp;amp;px=-1" alt="trustlist.PNG" title="trustlist.PNG" border="0" /&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;kindly give some suggestions.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;with regards,&lt;/P&gt;&lt;P&gt;Ram.&lt;/P&gt;</description>
      <pubDate>Mon, 12 Oct 2015 10:16:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/brightcloud-active-option-unavailable/m-p/66418#M39196</guid>
      <dc:creator>Gururaj</dc:creator>
      <dc:date>2015-10-12T10:16:01Z</dc:date>
    </item>
    <item>
      <title>Re: brightcloud active option unavailable</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/brightcloud-active-option-unavailable/m-p/66421#M39197</link>
      <description>&lt;P&gt;Hi Ram&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;you could try setting a service route for updates or bypassing the proxy entirely for management plane connections, the proxy may not be forwarding the crl/ocsp properly&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;IMG src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/620i4E4F7BD58F95B238/image-size/original?v=mpbl-1&amp;amp;px=-1" alt="2015-10-12_13-39-33.png" title="2015-10-12_13-39-33.png" border="0" /&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 12 Oct 2015 11:41:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/brightcloud-active-option-unavailable/m-p/66421#M39197</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2015-10-12T11:41:56Z</dc:date>
    </item>
  </channel>
</rss>

