<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Palo Alto Updates not passing through another PA firewall in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-updates-not-passing-through-another-pa-firewall/m-p/155515#M51136</link>
    <description>&lt;P&gt;IP of updates server can change. I'd strongly suggest using FQDN in settings (and app in policy).&lt;/P&gt;</description>
    <pubDate>Mon, 08 May 2017 13:24:24 GMT</pubDate>
    <dc:creator>santonic</dc:creator>
    <dc:date>2017-05-08T13:24:24Z</dc:date>
    <item>
      <title>Palo Alto Updates not passing through another PA firewall</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-updates-not-passing-through-another-pa-firewall/m-p/153330#M50637</link>
      <description>&lt;P&gt;Network setup:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;PA3020 E1/2--&amp;gt;E1/1 PA500 E1/2--&amp;gt;Internet.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In PA3020, we have configured the service route to paloaltoupdates through e1/2. Then traffic will reach pa500 e1/1 which will be routed to internet via e1/2. PAT configured on e1/2 which will be going to internet.I'm sure route, NAT,security policies are proper.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In PA3020, connection to paloalto update server is established. even anti-virus updates download also started. when we check the show session id xxx. its showing lots of bytes exchanged between C2S and S2C. but at last TCP-reset by client ( send by palo alto firewall ).&lt;/P&gt;&lt;P&gt;we are using staticupdates.paloaltonetworks.com which is working fine in PA500 but not working in PA3020.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Since the PA-3020 deployement, updates are working fine. there is no configuration changes made recently. but suddenly stops working and session end reason is tcp-rst-by-client.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;we have created app-override on both firewalls to update server IP. but no luck. Please suggest how can we proceed further.&lt;/P&gt;</description>
      <pubDate>Thu, 20 Apr 2017 09:14:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-updates-not-passing-through-another-pa-firewall/m-p/153330#M50637</guid>
      <dc:creator>MohamedSharief</dc:creator>
      <dc:date>2017-04-20T09:14:41Z</dc:date>
    </item>
    <item>
      <title>Re: Palo Alto Updates not passing through another PA firewall</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-updates-not-passing-through-another-pa-firewall/m-p/153346#M50639</link>
      <description>&lt;P&gt;can you please change your server to the:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;updates.paloaltonetworks.com&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 20 Apr 2017 09:55:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-updates-not-passing-through-another-pa-firewall/m-p/153346#M50639</guid>
      <dc:creator>TranceforLife</dc:creator>
      <dc:date>2017-04-20T09:55:14Z</dc:date>
    </item>
    <item>
      <title>Re: Palo Alto Updates not passing through another PA firewall</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-updates-not-passing-through-another-pa-firewall/m-p/153388#M50648</link>
      <description>&lt;P&gt;Are you running SSL decryption on edge firewall? If so having "Verify Update Server Identity" enabled (Device &amp;gt; Setup &amp;gt; Session &amp;gt; Session Settings) will cause the firewall to send a client reset if the&amp;nbsp;update server certificate is not signed by a trusted certificate authority.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I would also capture&amp;nbsp;&lt;SPAN&gt;tcp-rst-by-client in a pcap and verifyi the SSL Session end reason provided by the firewall when connecting to the update server.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 20 Apr 2017 16:02:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-updates-not-passing-through-another-pa-firewall/m-p/153388#M50648</guid>
      <dc:creator>MangoTango</dc:creator>
      <dc:date>2017-04-20T16:02:43Z</dc:date>
    </item>
    <item>
      <title>Re: Palo Alto Updates not passing through another PA firewall</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-updates-not-passing-through-another-pa-firewall/m-p/153616#M50697</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/37163"&gt;@TranceforLife&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Already tried that, same result.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/37340"&gt;@MangoTango&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;No SSL decryption is configured on both firewalls. Also I tried to enable 'Verify Update Server Identity' and disabled it also and I got the same result.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Sharief&lt;/P&gt;</description>
      <pubDate>Fri, 21 Apr 2017 13:04:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-updates-not-passing-through-another-pa-firewall/m-p/153616#M50697</guid>
      <dc:creator>MohamedSharief</dc:creator>
      <dc:date>2017-04-21T13:04:49Z</dc:date>
    </item>
    <item>
      <title>Re: Palo Alto Updates not passing through another PA firewall</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-updates-not-passing-through-another-pa-firewall/m-p/153621#M50700</link>
      <description>&lt;P&gt;Let's do a step back:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is it software update or dynamic updates?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;On the PA3020 when are you trying to check it manually with "check now" button", what can you see in the system logs? l expect the same as per below snip:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="UP.PNG" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/8892i1CDE82A84378533B/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="UP.PNG" alt="UP.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;How PA500 sees this traffic?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Apr 2017 13:31:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-updates-not-passing-through-another-pa-firewall/m-p/153621#M50700</guid>
      <dc:creator>TranceforLife</dc:creator>
      <dc:date>2017-04-21T13:31:51Z</dc:date>
    </item>
    <item>
      <title>Re: Palo Alto Updates not passing through another PA firewall</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-updates-not-passing-through-another-pa-firewall/m-p/155514#M51135</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/37163"&gt;@TranceforLife&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I opened a case with support and after long troubleshooting while checking the ms.log they found one XML file is missing error and they assumed the router doesn't have a route to the internal DNS server. They added a static route and it started to work but my concern is why the DNS is required when I put only the IP address of the updates website not FQDN!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I think its a bug in PA-3020.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 08 May 2017 13:13:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-updates-not-passing-through-another-pa-firewall/m-p/155514#M51135</guid>
      <dc:creator>MohamedSharief</dc:creator>
      <dc:date>2017-05-08T13:13:29Z</dc:date>
    </item>
    <item>
      <title>Re: Palo Alto Updates not passing through another PA firewall</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-updates-not-passing-through-another-pa-firewall/m-p/155515#M51136</link>
      <description>&lt;P&gt;IP of updates server can change. I'd strongly suggest using FQDN in settings (and app in policy).&lt;/P&gt;</description>
      <pubDate>Mon, 08 May 2017 13:24:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-updates-not-passing-through-another-pa-firewall/m-p/155515#M51136</guid>
      <dc:creator>santonic</dc:creator>
      <dc:date>2017-05-08T13:24:24Z</dc:date>
    </item>
    <item>
      <title>Re: Palo Alto Updates not passing through another PA firewall</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-updates-not-passing-through-another-pa-firewall/m-p/155516#M51137</link>
      <description>&lt;P&gt;Deffenetly better to use FQDN, but in your case do you remember&amp;nbsp;which ip&amp;nbsp;addresses you were using before. Are they the same ip addresses&amp;nbsp;if you trying to resolve an FQDN? &amp;nbsp;If not then you were pointing to the&amp;nbsp;wrong updates server ip&amp;nbsp;address.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 08 May 2017 13:34:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-updates-not-passing-through-another-pa-firewall/m-p/155516#M51137</guid>
      <dc:creator>TranceforLife</dc:creator>
      <dc:date>2017-05-08T13:34:14Z</dc:date>
    </item>
  </channel>
</rss>

