<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Content update 709 revoked? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/content-update-709-revoked/m-p/162000#M52634</link>
    <description>&lt;P&gt;I concur with&amp;nbsp;&lt;A href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/17469" target="_blank"&gt;SuryaR&lt;/A&gt;´s suggestion to differentiate between normal and emergency updates. With long threshold times like 48h it can happen that the device is waiting and waiting for the threshold to be reached.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Normal content update released =&amp;gt; do not install until 48h old&lt;/P&gt;&lt;P&gt;Within 48h, emergency content update released =&amp;gt; do not install until 48h old&lt;/P&gt;&lt;P&gt;etc.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Rolling out content updates manually thwarts the ability to prevent known attacks automatically.&lt;/P&gt;</description>
    <pubDate>Mon, 19 Jun 2017 16:08:59 GMT</pubDate>
    <dc:creator>Anon1</dc:creator>
    <dc:date>2017-06-19T16:08:59Z</dc:date>
    <item>
      <title>Content update 709 revoked?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/content-update-709-revoked/m-p/161570#M52558</link>
      <description>&lt;P&gt;All firewalls automatically downgraded content version from 709 to 708. Was 709 revoked? Anybody else having the same behavior?&lt;/P&gt;</description>
      <pubDate>Fri, 16 Jun 2017 14:02:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/content-update-709-revoked/m-p/161570#M52558</guid>
      <dc:creator>Anon1</dc:creator>
      <dc:date>2017-06-16T14:02:34Z</dc:date>
    </item>
    <item>
      <title>Re: Content update 709 revoked?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/content-update-709-revoked/m-p/161581#M52561</link>
      <description>&lt;P&gt;Yes. The update was revoked.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;More details here:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Customer-Advisories/Important-information-regarding-Content-Apps-amp-Threats-version/ta-p/161418" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Customer-Advisories/Important-information-regarding-Content-Apps-amp-Threats-version/ta-p/161418&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 16 Jun 2017 14:20:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/content-update-709-revoked/m-p/161581#M52561</guid>
      <dc:creator>SuryaR</dc:creator>
      <dc:date>2017-06-16T14:20:11Z</dc:date>
    </item>
    <item>
      <title>Re: Content update 709 revoked?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/content-update-709-revoked/m-p/161582#M52562</link>
      <description>&lt;P&gt;Thank you for the link. I wish PA would send information email to customers like for new content released.&lt;/P&gt;</description>
      <pubDate>Fri, 16 Jun 2017 14:24:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/content-update-709-revoked/m-p/161582#M52562</guid>
      <dc:creator>Anon1</dc:creator>
      <dc:date>2017-06-16T14:24:45Z</dc:date>
    </item>
    <item>
      <title>Re: Content update 709 revoked?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/content-update-709-revoked/m-p/161767#M52604</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/715"&gt;@Anon1&lt;/a&gt;, they do. &amp;nbsp;Do you not get e-mails about new content signatures being released?&lt;/P&gt;</description>
      <pubDate>Sat, 17 Jun 2017 13:14:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/content-update-709-revoked/m-p/161767#M52604</guid>
      <dc:creator>Brandon_Wertz</dc:creator>
      <dc:date>2017-06-17T13:14:18Z</dc:date>
    </item>
    <item>
      <title>Re: Content update 709 revoked?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/content-update-709-revoked/m-p/161768#M52605</link>
      <description>&lt;P&gt;Hello Brandon,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;yes, I get email notifications when new content updates are released.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I also got an email "Important customer update regarding content version 709" with a link to the mentioned article in the meanwhile. However, I would prefer to get such notifications about content updates being revoked at the time it is revoked, not some days later.&lt;/P&gt;</description>
      <pubDate>Sat, 17 Jun 2017 14:08:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/content-update-709-revoked/m-p/161768#M52605</guid>
      <dc:creator>Anon1</dc:creator>
      <dc:date>2017-06-17T14:08:55Z</dc:date>
    </item>
    <item>
      <title>Re: Content update 709 revoked?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/content-update-709-revoked/m-p/161770#M52606</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/715"&gt;@Anon1&lt;/a&gt;&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/5300"&gt;@Brandon_Wertz&lt;/a&gt;&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/17469"&gt;@SuryaR&lt;/a&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Palo Alto published a&amp;nbsp;Dynamic Content Update issue announced last Thursday with Content Release 709&lt;/SPAN&gt;&lt;STRONG&gt;. &lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Customer-Advisories/UPDATED-Important-information-regarding-Content-Apps-amp-Threats/ta-p/161418" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Customer-Advisories/UPDATED-Important-information-regarding-Content-Apps-amp-Threats/ta-p/161418&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I would like to remind you of the following vendor’s best practices.&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;&lt;SPAN&gt;For regular content update that comes out every Tuesday, we should&amp;nbsp;recommend that customers wait a minimum of 24-48 hours before rolling it out to their environment. This is because with any content update, a bug may be introduced that will break production&amp;nbsp;traffic (false positive). Waiting for at least 24-48 hours allows our Content Team to notify customers of any potential issue before they are impacted.&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;For emergency content update, we should&amp;nbsp;recommend customers to roll it out asap because it contains threat signature for zero day exploits. Please be aware that all Palo Alto&amp;nbsp;content updates are cumulative (i.e. emergency update 123 = regular update 122 + new emergency signature). So by installing it you will also install the previous regular update. In some cases, this may void the 24-48 hour delay recommendation above. But in this case the risk of getting hit by zero day exploit outweighs potential app ID/signature false positive.&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;At the end of the day, we should&amp;nbsp;try to help customers strike a reasonable balance between securing networks and minimizing outages.&lt;/SPAN&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&lt;SPAN&gt;Below is a good configuration example:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;From PANOS UI, go to Devices &amp;gt; Dynamic Updates &amp;gt; Application and Threats. In this case we are asking firewall to download and install content update every day at 2AM but with threshold (wait period) of 24 hours. So no matter when a content update is released, we will always wait 24 hours before installation. You can adjust threshold to your requirement.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="image001.png" style="width: 475px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/9769iE7FAD9A68A7E9560/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="image001.png" alt="image001.png" /&gt;&lt;/span&gt;&lt;/SPAN&gt;I hope this helps.&lt;/P&gt;</description>
      <pubDate>Sat, 17 Jun 2017 15:39:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/content-update-709-revoked/m-p/161770#M52606</guid>
      <dc:creator>acc6d0b3610eec313831f7900fdbd235</dc:creator>
      <dc:date>2017-06-17T15:39:37Z</dc:date>
    </item>
    <item>
      <title>Re: Content update 709 revoked?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/content-update-709-revoked/m-p/161810#M52607</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/36590"&gt;@acc6d0b3610eec313831f7900fdbd235&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you for detailed explanation. Understood about the recommendations.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My question:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;How is this feasible in an enviroment if I have 50+(not including passive pair) firewalls .&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I also thought panorama might be of help here. But in case, if a update is revoked and you try to push dynamic updates via panorama, it fails horribly.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For example:&lt;/P&gt;&lt;P&gt;We have dynamic updates set &amp;nbsp;to check daily, with a threshold of 8 hrs.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;709 was relased( threshold was set to 8 hrs ). After 8 hrs 709 is installed on every firewall.&lt;/P&gt;&lt;P&gt;~14 hrs later&amp;nbsp;PA decides to revoke 709.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Next, all I can think of is panorama, I do check updates (I find 708 is latest/available). Awesome, lets try now to push 708 to all firewalls,.&lt;/P&gt;&lt;P&gt;Panorama complains, the firewalls have better version than what it am trying to push.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;EPIC Fail...!!!&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Only thing I can do is to Login to every firewall and push it back to 708 or wait for 24 hrs before the firewall updates itself.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My 0.02$ &amp;nbsp;is PA should make emergency and regular updates different in the dynamic updates tab, rather than combining them and pushing them once, just how checkpoint does.&lt;/P&gt;&lt;P&gt;Hope I made sense.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 17 Jun 2017 23:39:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/content-update-709-revoked/m-p/161810#M52607</guid>
      <dc:creator>SuryaR</dc:creator>
      <dc:date>2017-06-17T23:39:23Z</dc:date>
    </item>
    <item>
      <title>Re: Content update 709 revoked?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/content-update-709-revoked/m-p/161811#M52608</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/17469"&gt;@SuryaR&lt;/a&gt;&lt;/P&gt;&lt;P&gt;I agree with your suggestion. This would most likely be a feature request or something that they may be working in the background to get it fixed, since it is not the first time it happens. In fact this it the 3rd issue since last year. 2 in the past 2 weeks, but this issues happend with every vendor unfortunately.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The way I am dealing with it currently using Panorama, is creating an update schedule in Panorama itself. This takes care of the issue when you have multiple firewall like you described. &lt;STRONG&gt;Device Deployment --&amp;gt; Dynamic Updates --&amp;gt; Schedules.&lt;/STRONG&gt; This way you can centrally control from Panorama directly which and when the updates should be pushed to the firewalls.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As I mentioned previously, best practices is to set the threshold for 24 or 48 hours after the update is released, so that if an issue with the signature occurs, you are safe for a little while, until they can release the correct signature.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I hope this helps.&lt;/P&gt;</description>
      <pubDate>Sun, 18 Jun 2017 02:31:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/content-update-709-revoked/m-p/161811#M52608</guid>
      <dc:creator>acc6d0b3610eec313831f7900fdbd235</dc:creator>
      <dc:date>2017-06-18T02:31:33Z</dc:date>
    </item>
    <item>
      <title>Re: Content update 709 revoked?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/content-update-709-revoked/m-p/162000#M52634</link>
      <description>&lt;P&gt;I concur with&amp;nbsp;&lt;A href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/17469" target="_blank"&gt;SuryaR&lt;/A&gt;´s suggestion to differentiate between normal and emergency updates. With long threshold times like 48h it can happen that the device is waiting and waiting for the threshold to be reached.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Normal content update released =&amp;gt; do not install until 48h old&lt;/P&gt;&lt;P&gt;Within 48h, emergency content update released =&amp;gt; do not install until 48h old&lt;/P&gt;&lt;P&gt;etc.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Rolling out content updates manually thwarts the ability to prevent known attacks automatically.&lt;/P&gt;</description>
      <pubDate>Mon, 19 Jun 2017 16:08:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/content-update-709-revoked/m-p/162000#M52634</guid>
      <dc:creator>Anon1</dc:creator>
      <dc:date>2017-06-19T16:08:59Z</dc:date>
    </item>
  </channel>
</rss>

