<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Issues with geolocation IP addresses in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/issues-with-geolocation-ip-addresses/m-p/6893#M5076</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;To answer your first question, how often is the ip geo location updated, you should contact your Sales engineer or open a support case.&amp;nbsp; As a general rule if the a feature setting is not in the documentation PA does not post the answer in a public forum so you have to use one of these inside communications channels.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You should check the IANA database to see if they do correctly identify the subnets in questions as being from Spain or Andorra.&amp;nbsp; Because if the IANA db is wrong then this is not a refresh interval issue with Palo Alto but the time to update from the service providers to IANA.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What is your security policies architecture?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would create a new address group for the incorrectly classified addresses that you can populate with with the incorrectly classified addresses as they are discovered.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you block other countries at the top of the policy then create your server allow rules, I would add a permit rule above the block with this new address group.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If your server allow rules are constructed using the geo ip address groups then I would add this new address group to these rules.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sat, 07 Mar 2015 12:47:31 GMT</pubDate>
    <dc:creator>pulukas</dc:creator>
    <dc:date>2015-03-07T12:47:31Z</dc:date>
    <item>
      <title>Issues with geolocation IP addresses</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/issues-with-geolocation-ip-addresses/m-p/6885#M5068</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;We have policies (geolocation) which only allow connection from Spain and Andorra.&lt;/P&gt;&lt;P&gt;In many cases the IP addresses identified by geolocation, is not properly updated and sometimes Palo Alto identifies an IP like another country rather than as Spain or vice versa.&lt;/P&gt;&lt;P&gt;How does a query to get that information Palo Alto?&lt;/P&gt;&lt;P&gt;What are the files that query PA?&lt;/P&gt;&lt;P&gt;Is the firewall establishes a connection to servers in Palo Alto?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 05 Mar 2015 13:28:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/issues-with-geolocation-ip-addresses/m-p/6885#M5068</guid>
      <dc:creator>SOC_CSG</dc:creator>
      <dc:date>2015-03-05T13:28:01Z</dc:date>
    </item>
    <item>
      <title>Re: Issues with geolocation IP addresses</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/issues-with-geolocation-ip-addresses/m-p/6886#M5069</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On Palo Alto Networks, a certain set of regions are pre-defined. Each IP can be matched to their belonging zone by using the CLI command:&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;show location ip &amp;lt;IP Address&amp;gt;&lt;/SPAN&gt;.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For example:&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;&amp;gt; show location ip 54.12.11.211&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;&amp;nbsp;&amp;nbsp; 54.12.11.211&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;&amp;nbsp;&amp;nbsp; United States&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The pre-defined regions database that Palo Alto Networks uses is the one defined by the Internet Assigned Numbers Authority (IANA) per globe zones that can be found at the following locations:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;AfriNIC Africa Region --&amp;gt; &lt;A class="jive-link-external-small" href="ftp://anonymous:anonymous@ftp.afrinic.net/pub/stats/afrinic/" rel="nofollow"&gt;ftp://ftp.afrinic.net/pub/stats/afrinic/&lt;/A&gt;&lt;/LI&gt;&lt;LI&gt;APNIC Asia/Pacific Region --&amp;gt; &lt;A class="jive-link-external-small" href="http://ftp.apnic.net/stats/apnic/"&gt;http://ftp.apnic.net/stats/apnic/&lt;/A&gt; &lt;/LI&gt;&lt;LI&gt;ARIN North America Region --&amp;gt; &lt;A class="jive-link-external-small" href="ftp://anonymous:anonymous@ftp.arin.net/pub/stats/arin/" rel="nofollow"&gt;ftp://ftp.arin.net/pub/stats/arin/&lt;/A&gt;&lt;/LI&gt;&lt;LI&gt;LACNIC Latin America and some Caribbean Islands --&amp;gt; &lt;A class="jive-link-external-small" href="http://bgp.potaroo.net/stats/lacnic/delegated"&gt;http://bgp.potaroo.net/stats/lacnic/delegated&lt;/A&gt;&amp;nbsp;&amp;nbsp; &amp;lt;&amp;lt; direct link&lt;/LI&gt;&lt;LI&gt;RIPE NCC (Europe, Russia, Middle East, Central Asia) --&amp;gt; &lt;A class="jive-link-external-small" href="http://ftp.apnic.net/stats/ripe-ncc/"&gt;http://ftp.apnic.net/stats/ripe-ncc/&lt;/A&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can find more information here &lt;A href="https://live.paloaltonetworks.com/docs/DOC-4856"&gt;Palo Alto Networks Pre-defined Regions&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 05 Mar 2015 15:04:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/issues-with-geolocation-ip-addresses/m-p/6886#M5069</guid>
      <dc:creator>gbogojevic</dc:creator>
      <dc:date>2015-03-05T15:04:38Z</dc:date>
    </item>
    <item>
      <title>Re: Issues with geolocation IP addresses</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/issues-with-geolocation-ip-addresses/m-p/6887#M5070</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;So this query to know the country, its done by the Palo Alto or the PA connect to any server in order to take the info&lt;/P&gt;&lt;P&gt;there is any way to force this refresh????&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sometimes PA thinks that an ip is coming from foreign country and this ip is from my country......&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 05 Mar 2015 15:10:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/issues-with-geolocation-ip-addresses/m-p/6887#M5070</guid>
      <dc:creator>SOC_CSG</dc:creator>
      <dc:date>2015-03-05T15:10:51Z</dc:date>
    </item>
    <item>
      <title>Re: Issues with geolocation IP addresses</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/issues-with-geolocation-ip-addresses/m-p/6888#M5071</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;PA takes this information from IANA (Internet Assigned Numbers Authority) -&amp;nbsp; from relevant national registries.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 05 Mar 2015 15:38:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/issues-with-geolocation-ip-addresses/m-p/6888#M5071</guid>
      <dc:creator>gbogojevic</dc:creator>
      <dc:date>2015-03-05T15:38:17Z</dc:date>
    </item>
    <item>
      <title>Re: Issues with geolocation IP addresses</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/issues-with-geolocation-ip-addresses/m-p/6889#M5072</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;how often the PA query IANA to get the info?????&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 13.3333330154419px;"&gt;any way to force this queries????&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 13.3333330154419px;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 13.3333330154419px;"&gt;thanks&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 05 Mar 2015 15:39:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/issues-with-geolocation-ip-addresses/m-p/6889#M5072</guid>
      <dc:creator>SOC_CSG</dc:creator>
      <dc:date>2015-03-05T15:39:23Z</dc:date>
    </item>
    <item>
      <title>Re: Issues with geolocation IP addresses</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/issues-with-geolocation-ip-addresses/m-p/6890#M5073</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;AFAIK there is not way to refresh manually but this information is updated through dynamic content updates.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 05 Mar 2015 15:45:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/issues-with-geolocation-ip-addresses/m-p/6890#M5073</guid>
      <dc:creator>gbogojevic</dc:creator>
      <dc:date>2015-03-05T15:45:38Z</dc:date>
    </item>
    <item>
      <title>Re: Issues with geolocation IP addresses</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/issues-with-geolocation-ip-addresses/m-p/6891#M5074</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello COS,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; font-size: 13px;"&gt;how often the PA query IANA to get the info?????&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; font-size: 13px;"&gt;This is updated through dynamic updates(Apps&amp;amp;Threats) installed on the firewall.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; font-size: 13px;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-size: 13.3333330154419px; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;any way to force this queries????&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-size: 13.3333330154419px; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;No&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-size: 13.3333330154419px; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-size: 13.3333330154419px; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;Regards,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-size: 13.3333330154419px; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;Hari Yadavalli&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 05 Mar 2015 23:41:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/issues-with-geolocation-ip-addresses/m-p/6891#M5074</guid>
      <dc:creator>hyadavalli</dc:creator>
      <dc:date>2015-03-05T23:41:50Z</dc:date>
    </item>
    <item>
      <title>Re: Issues with geolocation IP addresses</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/issues-with-geolocation-ip-addresses/m-p/6892#M5075</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;My customer has a streaming service that not foreign countries can access to this streaming.....(only can access SPAIN and ANDORRA).&lt;/P&gt;&lt;P&gt;Sometimes palo alto erroneously detects an ip is out of Spain when it really is from Spain.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Does the Firewall try in any point after downloading these updates, direct access to these ftp sites we return addresses DNS resolving those addresses first and then accessing? or conversely, that information download to your computer and consultation locally, later to consult the geo. how you do in this case?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is there any way to tell accessing other repositories of geolocation that has these latest data more updated/personalized? if not it will it be available in later PANOS versions?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We observed that in other documentations PaloAlto the access to geolocation databases have changed in over time, I guess that changes in the IANA did it,. This ftp access that you gave us, are they applicable to the version we have (5.0.8) or later versions differ? There is any changes in new versions (6.x.x) to improve the PA geolocation?????&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards....&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 06 Mar 2015 13:28:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/issues-with-geolocation-ip-addresses/m-p/6892#M5075</guid>
      <dc:creator>SOC_CSG</dc:creator>
      <dc:date>2015-03-06T13:28:54Z</dc:date>
    </item>
    <item>
      <title>Re: Issues with geolocation IP addresses</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/issues-with-geolocation-ip-addresses/m-p/6893#M5076</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;To answer your first question, how often is the ip geo location updated, you should contact your Sales engineer or open a support case.&amp;nbsp; As a general rule if the a feature setting is not in the documentation PA does not post the answer in a public forum so you have to use one of these inside communications channels.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You should check the IANA database to see if they do correctly identify the subnets in questions as being from Spain or Andorra.&amp;nbsp; Because if the IANA db is wrong then this is not a refresh interval issue with Palo Alto but the time to update from the service providers to IANA.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What is your security policies architecture?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would create a new address group for the incorrectly classified addresses that you can populate with with the incorrectly classified addresses as they are discovered.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you block other countries at the top of the policy then create your server allow rules, I would add a permit rule above the block with this new address group.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If your server allow rules are constructed using the geo ip address groups then I would add this new address group to these rules.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 07 Mar 2015 12:47:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/issues-with-geolocation-ip-addresses/m-p/6893#M5076</guid>
      <dc:creator>pulukas</dc:creator>
      <dc:date>2015-03-07T12:47:31Z</dc:date>
    </item>
    <item>
      <title>Re: Issues with geolocation IP addresses</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/issues-with-geolocation-ip-addresses/m-p/6894#M5077</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes we have a white-list permitting the "not well-categorized" ips by Palo Alto, but its a bit annoying to do this all the weeks, errors in geolocation happens every week....&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i guess PA only can use this DB for geolocation, it cant use another source for geolocation , right?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks a lot. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 09 Mar 2015 15:07:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/issues-with-geolocation-ip-addresses/m-p/6894#M5077</guid>
      <dc:creator>SOC_CSG</dc:creator>
      <dc:date>2015-03-09T15:07:42Z</dc:date>
    </item>
    <item>
      <title>Re: Issues with geolocation IP addresses</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/issues-with-geolocation-ip-addresses/m-p/6895#M5078</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;There may be other other sources, but certainly IANA is the official and final authority on the assignment of addresses.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm sure as we continue to deal with ipv4 address depletion these movements of address blocks will become more common.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 09 Mar 2015 21:48:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/issues-with-geolocation-ip-addresses/m-p/6895#M5078</guid>
      <dc:creator>pulukas</dc:creator>
      <dc:date>2015-03-09T21:48:49Z</dc:date>
    </item>
  </channel>
</rss>

