<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Can't join Windows Updates server, application &amp;quot;not applicable&amp;quot; in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/can-t-join-windows-updates-server-application-quot-not/m-p/158040#M51753</link>
    <description>&lt;P&gt;You could use a custom URL category where you enter the fqdn's which you now have configured as address objects. After that remove all the address objects from your security policy and add the custom URL category to this rule. (no URL filtering license required)&lt;/P&gt;&lt;P&gt;This way it should be able to limit the access to only the Microsoft Update Servers while not having problems with FQDN objects (where it is, specially with CDN's,&amp;nbsp; likely that the firewall does not resolve the FQDN to the same ip as your internal server)&lt;/P&gt;</description>
    <pubDate>Wed, 24 May 2017 09:46:18 GMT</pubDate>
    <dc:creator>Remo</dc:creator>
    <dc:date>2017-05-24T09:46:18Z</dc:date>
    <item>
      <title>Can't join Windows Updates server, application "not applicable"</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/can-t-join-windows-updates-server-application-quot-not/m-p/158033#M51747</link>
      <description>&lt;P&gt;Hi !&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm trying to connect the server to&amp;nbsp;the Internet in order to download and to install updates. My server is a Windows Server 2016, so i'm trying to reach Windows Updates servers.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In order to do that, I created a rule in the firewall :&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Regle SRVACD WU.PNG" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/9382iEFE3546986E067DD/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Regle SRVACD WU.PNG" alt="Regle SRVACD WU.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;The address group contain theses addresses :&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="adresse.PNG" style="width: 633px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/9385i2C440631B208CCD1/image-dimensions/633x105/is-moderation-mode/true?v=v2" width="633" height="105" role="button" title="adresse.PNG" alt="adresse.PNG" /&gt;&lt;/span&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;To verifiy that my server can reach Windows Update server, I checked the logs.&lt;/P&gt;&lt;P&gt;&amp;nbsp;I've got in Application field "not applicable" :&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="Log.PNG" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/9383iCE204A5C8CAEA8BA/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Log.PNG" alt="Log.PNG" /&gt;&lt;/span&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Support says : "Not-applicable means that the Palo Alto device has received data that will be discarded because the port or service that the traffic is coming in on is not allowed, or there is no rule or policy allowing that port or service"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here is an example of a detailed log :&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="Srv - WU not applicable trame.PNG" style="width: 694px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/9384iB64CC5E52DFAF1A4/image-dimensions/694x528/is-moderation-mode/true?v=v2" width="694" height="528" role="button" title="Srv - WU not applicable trame.PNG" alt="Srv - WU not applicable trame.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Do you have any idea to solve the problem ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Best regards,&lt;/P&gt;&lt;P&gt;Alexandre&lt;/P&gt;</description>
      <pubDate>Wed, 24 May 2017 09:04:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/can-t-join-windows-updates-server-application-quot-not/m-p/158033#M51747</guid>
      <dc:creator>informatiq</dc:creator>
      <dc:date>2017-05-24T09:04:06Z</dc:date>
    </item>
    <item>
      <title>Re: Can't join Windows Updates server, application "not applicable"</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/can-t-join-windows-updates-server-application-quot-not/m-p/158034#M51748</link>
      <description>&lt;P&gt;Your traffic is not hitting your policy. Instead it is hitting All_Deny rule&lt;/P&gt;</description>
      <pubDate>Wed, 24 May 2017 09:27:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/can-t-join-windows-updates-server-application-quot-not/m-p/158034#M51748</guid>
      <dc:creator>TranceforLife</dc:creator>
      <dc:date>2017-05-24T09:27:48Z</dc:date>
    </item>
    <item>
      <title>Re: Can't join Windows Updates server, application "not applicable"</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/can-t-join-windows-updates-server-application-quot-not/m-p/158038#M51751</link>
      <description>&lt;P&gt;Those sessions' destination IPs are not matching the FQDN objects you created so the connection bypasses the security policy and hits the deny_all instead.&lt;/P&gt;
&lt;P&gt;At this point, APP-ID is not going to try and identify the application (as the session is getting discarded by policy anyway) so the app is labeled as not applicable&lt;/P&gt;</description>
      <pubDate>Wed, 24 May 2017 09:37:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/can-t-join-windows-updates-server-application-quot-not/m-p/158038#M51751</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2017-05-24T09:37:32Z</dc:date>
    </item>
    <item>
      <title>Re: Can't join Windows Updates server, application "not applicable"</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/can-t-join-windows-updates-server-application-quot-not/m-p/158039#M51752</link>
      <description>&lt;P&gt;Taking "off" FQDNs from the policy should allow you to get updates.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 24 May 2017 09:40:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/can-t-join-windows-updates-server-application-quot-not/m-p/158039#M51752</guid>
      <dc:creator>TranceforLife</dc:creator>
      <dc:date>2017-05-24T09:40:02Z</dc:date>
    </item>
    <item>
      <title>Re: Can't join Windows Updates server, application "not applicable"</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/can-t-join-windows-updates-server-application-quot-not/m-p/158040#M51753</link>
      <description>&lt;P&gt;You could use a custom URL category where you enter the fqdn's which you now have configured as address objects. After that remove all the address objects from your security policy and add the custom URL category to this rule. (no URL filtering license required)&lt;/P&gt;&lt;P&gt;This way it should be able to limit the access to only the Microsoft Update Servers while not having problems with FQDN objects (where it is, specially with CDN's,&amp;nbsp; likely that the firewall does not resolve the FQDN to the same ip as your internal server)&lt;/P&gt;</description>
      <pubDate>Wed, 24 May 2017 09:46:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/can-t-join-windows-updates-server-application-quot-not/m-p/158040#M51753</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2017-05-24T09:46:18Z</dc:date>
    </item>
    <item>
      <title>Re: Can't join Windows Updates server, application "not applicable"</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/can-t-join-windows-updates-server-application-quot-not/m-p/158042#M51754</link>
      <description>&lt;P&gt;Thanks all. It was FQDN the problem !&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I will create addresses object, and I will see what IP are used, to modify the rule.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Have a good day ! Thanks !&lt;/P&gt;</description>
      <pubDate>Wed, 24 May 2017 09:53:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/can-t-join-windows-updates-server-application-quot-not/m-p/158042#M51754</guid>
      <dc:creator>informatiq</dc:creator>
      <dc:date>2017-05-24T09:53:28Z</dc:date>
    </item>
    <item>
      <title>Re: Can't join Windows Updates server, application "not applicable"</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/can-t-join-windows-updates-server-application-quot-not/m-p/158046#M51756</link>
      <description>&lt;P&gt;In this case I would not recommend doing that. Create the rule either only application based as &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/37163"&gt;@TranceforLife&lt;/a&gt; proposed or limit it by using a custom URL category.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But because Microsoft distributes the updates with a CDN you will most likely end up with often changing your security policy (adding new ip's regularly; deleting old ones; and not to forget to troubleshoot everytime to find out which ip really belongs to this FQDN's and which ones are just traffic you don't want to allow)&lt;/P&gt;</description>
      <pubDate>Wed, 24 May 2017 10:38:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/can-t-join-windows-updates-server-application-quot-not/m-p/158046#M51756</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2017-05-24T10:38:10Z</dc:date>
    </item>
    <item>
      <title>Re: Can't join Windows Updates server, application "not applicable"</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/can-t-join-windows-updates-server-application-quot-not/m-p/158047#M51757</link>
      <description>&lt;P&gt;Hey,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Totally agreed. Anyway, sometimes FQDNs just simply fail to refresh.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 24 May 2017 11:22:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/can-t-join-windows-updates-server-application-quot-not/m-p/158047#M51757</guid>
      <dc:creator>TranceforLife</dc:creator>
      <dc:date>2017-05-24T11:22:27Z</dc:date>
    </item>
    <item>
      <title>Re: Can't join Windows Updates server, application "not applicable"</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/can-t-join-windows-updates-server-application-quot-not/m-p/158060#M51760</link>
      <description>&lt;P&gt;So I created an URL category, and it works ! I have "deny" for some IP, but I can have updates !&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks all !&lt;/P&gt;</description>
      <pubDate>Wed, 24 May 2017 13:10:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/can-t-join-windows-updates-server-application-quot-not/m-p/158060#M51760</guid>
      <dc:creator>informatiq</dc:creator>
      <dc:date>2017-05-24T13:10:54Z</dc:date>
    </item>
  </channel>
</rss>

