<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic External Dynamic Lists requires &amp;quot;google-app-engine&amp;quot; ?? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/external-dynamic-lists-requires-quot-google-app-engine-quot/m-p/148828#M49655</link>
    <description>&lt;P&gt;Greetings&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;On PAN-OS 7.1.8 configuring EDL is giving some unexpected results -&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have an application based security policie set for my PA management IP addresses to fetch the updates i.e. "paloalto-updates, widlfire, pan-db-cloud, ssl and web-browsing" with service set to application default. &amp;nbsp;No profile actions set to block.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;After populating the EDL with the lists from&amp;nbsp;&lt;A href="http://panwdbl.appspot.com" target="_blank"&gt;http://panwdbl.appspot.com&lt;/A&gt;, I went on to one of the added lists and tried "Test Source URL" and the return message was &lt;STRONG&gt;"URL access error"&lt;/STRONG&gt;.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As a test,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;- Set the service route configuration to use my external interface - &lt;STRONG&gt;"URL access error"&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;- Then created an open policy for the management IP addresses with "any" "any" and the test source URL works returning &lt;STRONG&gt;"source URL is accessbile"&lt;/STRONG&gt;.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Looking at the logs, I noticed the session to start on web-browsing and then move to "google-app-engine" when contacting 216.58.198.244 (panwdbl.appspot.com/lists).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So deleted my wide open policy and amended the application based policy by adding "google-app-engine", set my service route back to use the management interface. &amp;nbsp;Commit the configuration and &lt;STRONG&gt;&lt;FONT color="#008000"&gt;it works&lt;/FONT&gt;. &amp;nbsp;&lt;/STRONG&gt;Google-app-engine's default ports are TCP 443 and 80&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Looking in to the logs, it uses "google-app-engine" to speak to the website -&lt;STRONG&gt; is this expected behaviour?&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;I find this to be abnormal unless I have missed a very basic point somewhere.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any ideas / thoughts will be helpful.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;KP&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 22 Mar 2017 12:49:38 GMT</pubDate>
    <dc:creator>kalyanram.piratla</dc:creator>
    <dc:date>2017-03-22T12:49:38Z</dc:date>
    <item>
      <title>External Dynamic Lists requires "google-app-engine" ??</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/external-dynamic-lists-requires-quot-google-app-engine-quot/m-p/148828#M49655</link>
      <description>&lt;P&gt;Greetings&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;On PAN-OS 7.1.8 configuring EDL is giving some unexpected results -&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have an application based security policie set for my PA management IP addresses to fetch the updates i.e. "paloalto-updates, widlfire, pan-db-cloud, ssl and web-browsing" with service set to application default. &amp;nbsp;No profile actions set to block.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;After populating the EDL with the lists from&amp;nbsp;&lt;A href="http://panwdbl.appspot.com" target="_blank"&gt;http://panwdbl.appspot.com&lt;/A&gt;, I went on to one of the added lists and tried "Test Source URL" and the return message was &lt;STRONG&gt;"URL access error"&lt;/STRONG&gt;.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As a test,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;- Set the service route configuration to use my external interface - &lt;STRONG&gt;"URL access error"&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;- Then created an open policy for the management IP addresses with "any" "any" and the test source URL works returning &lt;STRONG&gt;"source URL is accessbile"&lt;/STRONG&gt;.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Looking at the logs, I noticed the session to start on web-browsing and then move to "google-app-engine" when contacting 216.58.198.244 (panwdbl.appspot.com/lists).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So deleted my wide open policy and amended the application based policy by adding "google-app-engine", set my service route back to use the management interface. &amp;nbsp;Commit the configuration and &lt;STRONG&gt;&lt;FONT color="#008000"&gt;it works&lt;/FONT&gt;. &amp;nbsp;&lt;/STRONG&gt;Google-app-engine's default ports are TCP 443 and 80&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Looking in to the logs, it uses "google-app-engine" to speak to the website -&lt;STRONG&gt; is this expected behaviour?&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;I find this to be abnormal unless I have missed a very basic point somewhere.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any ideas / thoughts will be helpful.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;KP&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 22 Mar 2017 12:49:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/external-dynamic-lists-requires-quot-google-app-engine-quot/m-p/148828#M49655</guid>
      <dc:creator>kalyanram.piratla</dc:creator>
      <dc:date>2017-03-22T12:49:38Z</dc:date>
    </item>
    <item>
      <title>Re: External Dynamic Lists requires "google-app-engine" ??</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/external-dynamic-lists-requires-quot-google-app-engine-quot/m-p/148834#M49659</link>
      <description>&lt;P&gt;"&lt;SPAN&gt;Google App Engine is a platform for developing and hosting web applications in Google-managed data centers."&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;This is to be expected as that is what the website is built upon. I'm not positive if it's supposed to hit that app id but looking through my logs I can see that plenty of my users get the same ID when accessing websites hosted on the platform.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 22 Mar 2017 13:20:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/external-dynamic-lists-requires-quot-google-app-engine-quot/m-p/148834#M49659</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2017-03-22T13:20:04Z</dc:date>
    </item>
  </channel>
</rss>

