<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PA-VM Update Check Fails in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/pa-vm-update-check-fails/m-p/74634#M41743</link>
    <description>&lt;P&gt;Hey&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Can you verify the content version i.e Application and Threats version.&lt;/P&gt;
&lt;P&gt;Ideally you should have a version higher than 550.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you are runningn on a verison less than that, then please upgrade the version to any value higher than 550.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Disable the Verify server identity and also check.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If these things do not work out, then the pcap on the management interface is the best.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Sun, 13 Mar 2016 19:23:36 GMT</pubDate>
    <dc:creator>schopra</dc:creator>
    <dc:date>2016-03-13T19:23:36Z</dc:date>
    <item>
      <title>PA-VM Update Check Fails</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-vm-update-check-fails/m-p/74552#M41719</link>
      <description>&lt;P&gt;We have recently deployed PA-VM to ESXi for testing and we have found that any attempt to upgrade the unit fails with a very vague message.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;cfg.platform.serial': NO_MATCHES
'cfg.general.vm-mode-type': NO_MATCHES
2016-03-10 09:14:42.447 -0800 updater error code:-1
2016-03-10 09:14:48.140 -0800 Error:  refresh_uploaded_image_info(pan_ops_common.c:8516): Bad update information on disk2016-03-10 09:14:48.140 -0800 Error:  refresh_uploaded_image_info(pan_ops_common.c:8519): Error removing /opt/pancfg/mgmt/global/upgradeinfo.xml
2016-03-10 09:14:48.412 -0800 No update information available
2016-03-10 09:14:48.412 -0800 Error:  get_sw_version_info(pan_ops_common.c:7675): Error extracting sw version info from file upgradeinfo.xml
2016-03-10 09:14:48.412 -0800 No upload information available&lt;/PRE&gt;&lt;PRE&gt;admin@PA-VM&amp;gt; request system software check

Server error : Failed to check upgrade info due to generic communication error. Please check network connectivity and try again.
admin@PA-VM&amp;gt; &lt;/PRE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have set the update server in Device &amp;gt; Setup &amp;gt; Services to&amp;nbsp;199.167.52.141 and updates.paloaltonetworks.com.&lt;/P&gt;&lt;P&gt;I put in proxy information to assist in the debug but no requests are ever made. &amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My assumption is that the appliance never touches the network because of some file issues.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Does anyone have any ideas on how I can go about fixing this?&lt;/P&gt;</description>
      <pubDate>Thu, 10 Mar 2016 17:18:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-vm-update-check-fails/m-p/74552#M41719</guid>
      <dc:creator>xandout</dc:creator>
      <dc:date>2016-03-10T17:18:43Z</dc:date>
    </item>
    <item>
      <title>Re: PA-VM Update Check Fails</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-vm-update-check-fails/m-p/74553#M41720</link>
      <description>&lt;P&gt;Hey,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Does look like a connectivity problem.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You could try changing the service routes of the firewall so that it uses a dataplane interface rather than the management?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Device &amp;gt; Setup &amp;gt; &amp;nbsp;Services &amp;gt; Service Features &amp;gt; Service Route Configuration.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Change DNS &amp;amp; Updates to a dataplane interface. If you prefer to use the management then make sure your device can make DNS requests ok in order to resolve the updates.paloaltonetworks.com server and make sure that if traffic is routed through the device, the device is not blocking itself.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;hope that helps,&lt;/P&gt;
&lt;P&gt;Ben&lt;/P&gt;</description>
      <pubDate>Thu, 10 Mar 2016 17:28:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-vm-update-check-fails/m-p/74553#M41720</guid>
      <dc:creator>bmorris1</dc:creator>
      <dc:date>2016-03-10T17:28:58Z</dc:date>
    </item>
    <item>
      <title>Re: PA-VM Update Check Fails</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-vm-update-check-fails/m-p/74554#M41721</link>
      <description>I have verified that the device can resolve updates.paloaltonetworks.com. a ping host gives me the IP,&lt;BR /&gt;&lt;BR /&gt;I will setup a data plane interface and see if that helps.&lt;BR /&gt;&lt;BR /&gt;Should the appliance be able to use the mgmt interface for updates?</description>
      <pubDate>Thu, 10 Mar 2016 17:32:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-vm-update-check-fails/m-p/74554#M41721</guid>
      <dc:creator>xandout</dc:creator>
      <dc:date>2016-03-10T17:32:20Z</dc:date>
    </item>
    <item>
      <title>Re: PA-VM Update Check Fails</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-vm-update-check-fails/m-p/74558#M41723</link>
      <description>&lt;P&gt;I went as far as doing a fresh install&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P class="p1"&gt;&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;&lt;BR /&gt;admin@PA-VM&amp;gt; ping host updates.paloaltonetworks.com&lt;BR /&gt;PING updates.paloaltonetworks.com (199.167.52.141) 56(84) bytes of data.&lt;BR /&gt;^C&lt;BR /&gt;--- updates.paloaltonetworks.com ping statistics ---&lt;BR /&gt;2 packets transmitted, 0 received, 100% packet loss, time 1007ms&lt;BR /&gt;&lt;BR /&gt;admin@PA-VM&amp;gt; request system software check

Server error : Failed to check upgrade info due to generic communication error. Please check network connectivity and try again.
admin@PA-VM&amp;gt; tail 
+ follow          output appended data as the file grows
+ lines           output the last N lines, instead of the last 10
&amp;gt; agent-log       agent-log 
&amp;gt; mp-log          mp-log 
&amp;gt; webserver-log   webserver-log 

admin@PA-VM&amp;gt; tail mp-log m
masterd.log         masterd_apps.log    masterd_detail.log  mgmt_fb.log         mp-monitor.log      ms.log              mprelay.log         
admin@PA-VM&amp;gt; tail mp-log ms.log 
ln: creating symbolic link `3a7f6b22.0' to `/opt/pancfg/certificates/predefined/Thawte Personal Basic CA.cer': File exists
ln: creating symbolic link `64d1f6f4.0' to `/opt/pancfg/certificates/predefined/Thawte Personal Freemail CA.cer': File exists
ln: creating symbolic link `09ca81a7.0' to `/opt/pancfg/certificates/predefined/Thawte Personal Premium CA d.cer': File exists
ln: creating symbolic link `98ec67f0.0' to `/opt/pancfg/certificates/predefined/Thawte_Premium_Server_CA.cer': File exists
ln: creating symbolic link `6cc3c4c3.0' to `/opt/pancfg/certificates/predefined/Thawte_Server_CA.cer': File exists
ln: creating symbolic link `415660c1.0' to `/opt/pancfg/certificates/predefined/Verisign_Class_3_Public_Primary_Certification_Authority.cer': File exists
2016-03-10 11:12:24.819 -0800 updater error code:-1
'cfg.platform.serial': NO_MATCHES
'cfg.general.vm-mode-type': NO_MATCHES
2016-03-10 11:12:49.998 -0800 updater error code:-1
admin@PA-VM&amp;gt; 
admin@PA-VM&amp;gt; 
admin@PA-VM&amp;gt; 
admin@PA-VM&amp;gt; 
admin@PA-VM&amp;gt; 
admin@PA-VM&amp;gt; request system software 
&amp;gt; check      Get information from PaloAlto Networks server
&amp;gt; download   Download software packages
&amp;gt; info       Show information about available software packages
&amp;gt; install    Install a downloaded software package

admin@PA-VM&amp;gt; request system software 
&amp;gt; check      Get information from PaloAlto Networks server
&amp;gt; download   Download software packages
&amp;gt; info       Show information about available software packages
&amp;gt; install    Install a downloaded software package

admin@PA-VM&amp;gt; request system software in
&amp;gt; info      Show information about available software packages
&amp;gt; install   Install a downloaded software package

admin@PA-VM&amp;gt; request system software info 

Server error : No update information available
admin@PA-VM&amp;gt; 
admin@PA-VM&amp;gt; 
admin@PA-VM&amp;gt; 
admin@PA-VM&amp;gt; 
admin@PA-VM&amp;gt; tail mp-log ms.log
ln: creating symbolic link `6cc3c4c3.0' to `/opt/pancfg/certificates/predefined/Thawte_Server_CA.cer': File exists
ln: creating symbolic link `415660c1.0' to `/opt/pancfg/certificates/predefined/Verisign_Class_3_Public_Primary_Certification_Authority.cer': File exists
2016-03-10 11:12:24.819 -0800 updater error code:-1
'cfg.platform.serial': NO_MATCHES
'cfg.general.vm-mode-type': NO_MATCHES
2016-03-10 11:12:49.998 -0800 updater error code:-1
2016-03-10 11:13:25.284 -0800 Error:  refresh_uploaded_image_info(pan_ops_common.c:8516): Bad update information on disk2016-03-10 11:13:25.284 -0800 Error:  refresh_uploaded_image_info(pan_ops_common.c:8519): Error removing /opt/pancfg/mgmt/global/upgradeinfo.xml
2016-03-10 11:13:25.528 -0800 No update information available
2016-03-10 11:13:25.528 -0800 Error:  get_sw_version_info(pan_ops_common.c:7675): Error extracting sw version info from file upgradeinfo.xml
2016-03-10 11:13:25.528 -0800 No upload information available&lt;/PRE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 10 Mar 2016 19:15:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-vm-update-check-fails/m-p/74558#M41723</guid>
      <dc:creator>xandout</dc:creator>
      <dc:date>2016-03-10T19:15:21Z</dc:date>
    </item>
    <item>
      <title>Re: PA-VM Update Check Fails</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-vm-update-check-fails/m-p/74577#M41727</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;what is your OS version you are running? If you have 7.0.0 or some beta release, download 7.0.1 image, install that one and try to upgrade from it.&lt;/P&gt;
&lt;P&gt;If not, you can do pcaps on management interface to verify what is going on with traffic because by default it does use management interface to communicate to the cloud; commands to do that would be:&lt;/P&gt;
&lt;P&gt;tcpdump snaplen 0 filter "host 199.167.52.141"&lt;/P&gt;
&lt;P&gt;view-pcap verbose++ yes mgmt-pcap mgmt.pcap&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;change 199.167.52.141 to whatever you resolve updates.paloaltonetworks.com&lt;/P&gt;
&lt;P&gt;you can also export pcap by tftp export mgmt-pcap... or scp export mgmt-pcap&lt;/P&gt;
&lt;P&gt;Check if you are attempting to decrypt that traffic along the way somewhere as well - that would break updates too.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Let us know if none of above helps.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Best regards,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Luciano&lt;/P&gt;</description>
      <pubDate>Fri, 11 Mar 2016 07:30:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-vm-update-check-fails/m-p/74577#M41727</guid>
      <dc:creator>Lucky</dc:creator>
      <dc:date>2016-03-11T07:30:22Z</dc:date>
    </item>
    <item>
      <title>Re: PA-VM Update Check Fails</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-vm-update-check-fails/m-p/74619#M41739</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Could you be able to check the Time and date on ther firewall are accurate or not&lt;/P&gt;
&lt;P&gt;Also kindly open the cli run this command and &amp;nbsp;do a check now paste the output here&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;admin@admin&amp;gt; tail follow yes mp-log devsrv.log &amp;nbsp; &amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;and do you see any message in the system logs regarding to the url filtering&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 12 Mar 2016 01:31:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-vm-update-check-fails/m-p/74619#M41739</guid>
      <dc:creator>tsrivastav</dc:creator>
      <dc:date>2016-03-12T01:31:28Z</dc:date>
    </item>
    <item>
      <title>Re: PA-VM Update Check Fails</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-vm-update-check-fails/m-p/74620#M41740</link>
      <description>&lt;P&gt;DNS resultions are working fine, that means changing service route &amp;nbsp;may not address the isse however if the traffic is passing through the firewall Mgmt port&amp;gt;&amp;gt;&amp;gt;firewalls data port&amp;gt;&amp;gt;&amp;gt;cloud &amp;nbsp;make fure you have allow rules for Managment ip address more or you can check global counters also if the traffic is passing through the firewalls data port&lt;/P&gt;</description>
      <pubDate>Sat, 12 Mar 2016 01:32:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-vm-update-check-fails/m-p/74620#M41740</guid>
      <dc:creator>tsrivastav</dc:creator>
      <dc:date>2016-03-12T01:32:31Z</dc:date>
    </item>
    <item>
      <title>Re: PA-VM Update Check Fails</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-vm-update-check-fails/m-p/74622#M41742</link>
      <description>&lt;P&gt;In these situations I generally download the PanOS file to my workstation and do the upload and upgrade from there instead of from the cloud. &amp;nbsp;This will generally get around the issue of communications errors.&lt;/P&gt;</description>
      <pubDate>Sat, 12 Mar 2016 11:11:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-vm-update-check-fails/m-p/74622#M41742</guid>
      <dc:creator>pulukas</dc:creator>
      <dc:date>2016-03-12T11:11:26Z</dc:date>
    </item>
    <item>
      <title>Re: PA-VM Update Check Fails</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-vm-update-check-fails/m-p/74634#M41743</link>
      <description>&lt;P&gt;Hey&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Can you verify the content version i.e Application and Threats version.&lt;/P&gt;
&lt;P&gt;Ideally you should have a version higher than 550.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you are runningn on a verison less than that, then please upgrade the version to any value higher than 550.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Disable the Verify server identity and also check.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If these things do not work out, then the pcap on the management interface is the best.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 13 Mar 2016 19:23:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-vm-update-check-fails/m-p/74634#M41743</guid>
      <dc:creator>schopra</dc:creator>
      <dc:date>2016-03-13T19:23:36Z</dc:date>
    </item>
    <item>
      <title>Re: PA-VM Update Check Fails</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-vm-update-check-fails/m-p/74760#M41778</link>
      <description>&lt;P&gt;Could you verify the licenses are proper and installed and updated in the support portal?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Also please enable debug mode on management server and collect the logs:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;gt; debug management-server on debug&lt;/P&gt;
&lt;P&gt;&amp;gt; tail follow yes mp-log ms.log&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Now do a Check Now from GUI or "request content upgrade check" from another CLI to see what are the logs showing.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;At the end set the management-server debug to info level:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;gt; debug management-server on info&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;If licenses are properly installed, and logs do not show enough information, kindly open a support case&lt;/P&gt;</description>
      <pubDate>Wed, 16 Mar 2016 06:18:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-vm-update-check-fails/m-p/74760#M41778</guid>
      <dc:creator>abjain</dc:creator>
      <dc:date>2016-03-16T06:18:41Z</dc:date>
    </item>
    <item>
      <title>Re: PA-VM Update Check Fails</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-vm-update-check-fails/m-p/74763#M41781</link>
      <description>&lt;P&gt;I have resolved this kind of issues by clicking once on the "retrieve licenses link, then do check now.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 16 Mar 2016 06:22:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-vm-update-check-fails/m-p/74763#M41781</guid>
      <dc:creator>rbista</dc:creator>
      <dc:date>2016-03-16T06:22:37Z</dc:date>
    </item>
  </channel>
</rss>

