<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Download PAN-OS from GUI failing, potential MTU Problem ... in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/download-pan-os-from-gui-failing-potential-mtu-problem/m-p/198972#M59015</link>
    <description>&lt;P&gt;Ok folks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here's an interesting one for you.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This is to do with connectivity between Panorama and updates.paloaltonetworks.com&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We can retrieve licence info and download list of updates available for downloads (SW and Threats), but when clicking on download link the connection fails with standard connectivity to updates.palo error, try again later.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This is long shot, but has anyone seen this before?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;PAN-OS 8.0.2 VM base image, intending to upgrade to 8.0.7 if the download worked &lt;span class="lia-unicode-emoji" title=":confused_face:"&gt;😕&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Ajaz Nawaz&lt;/P&gt;&lt;P&gt;JNCIE-SEC No.254&lt;/P&gt;&lt;P&gt;CCIE-RS No.15721&lt;/P&gt;</description>
    <pubDate>Tue, 06 Feb 2018 09:41:49 GMT</pubDate>
    <dc:creator>nawaza</dc:creator>
    <dc:date>2018-02-06T09:41:49Z</dc:date>
    <item>
      <title>Download PAN-OS from GUI failing, potential MTU Problem ...</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/download-pan-os-from-gui-failing-potential-mtu-problem/m-p/198972#M59015</link>
      <description>&lt;P&gt;Ok folks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here's an interesting one for you.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This is to do with connectivity between Panorama and updates.paloaltonetworks.com&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We can retrieve licence info and download list of updates available for downloads (SW and Threats), but when clicking on download link the connection fails with standard connectivity to updates.palo error, try again later.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This is long shot, but has anyone seen this before?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;PAN-OS 8.0.2 VM base image, intending to upgrade to 8.0.7 if the download worked &lt;span class="lia-unicode-emoji" title=":confused_face:"&gt;😕&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Ajaz Nawaz&lt;/P&gt;&lt;P&gt;JNCIE-SEC No.254&lt;/P&gt;&lt;P&gt;CCIE-RS No.15721&lt;/P&gt;</description>
      <pubDate>Tue, 06 Feb 2018 09:41:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/download-pan-os-from-gui-failing-potential-mtu-problem/m-p/198972#M59015</guid>
      <dc:creator>nawaza</dc:creator>
      <dc:date>2018-02-06T09:41:49Z</dc:date>
    </item>
    <item>
      <title>Re: Download PAN-OS from GUI failing, potential MTU Problem ...</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/download-pan-os-from-gui-failing-potential-mtu-problem/m-p/198986#M59016</link>
      <description>&lt;P&gt;Have you tried re-running 'check now' ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Have you followed the connection through a firewall (packetcapture + global counters) to see what may be happiening, have you seen MTU error messages?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;MTU issues can be fixed by changing the MTU and/or setting TCP MSS rewrites, but you'll want to investigate the connection to see what is actually happening before changing these settings&lt;/P&gt;</description>
      <pubDate>Tue, 06 Feb 2018 10:39:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/download-pan-os-from-gui-failing-potential-mtu-problem/m-p/198986#M59016</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2018-02-06T10:39:08Z</dc:date>
    </item>
    <item>
      <title>Re: Download PAN-OS from GUI failing, potential MTU Problem ...</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/download-pan-os-from-gui-failing-potential-mtu-problem/m-p/198994#M59021</link>
      <description>&lt;P&gt;hmmm..&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So its nothing to do with MTU after all.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Currently investigating but updates.paloaltonetworks.com is resolving to :&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;a92-122-165-117.deploy.akamaitechnologies.com.https&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But... in front of Panorama there is a perimeter SRX fw allowing updates.paloaltonetworks.com ONLY !&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;admin@asfdsadfasdf&amp;gt; view-pcap mgmt-pcap mgmt.pcap&lt;/P&gt;&lt;P&gt;17:22:58.515102 IP &amp;lt;ip-addr-removed&amp;gt;.36347 &amp;gt; a92-122-165-117.deploy.akamaitechnologies.com.https: S 1831023988:1831023988(0) win 14600 &amp;lt;mss 1460,sackOK,timestamp 2046968 0,nop,wscale 7&amp;gt;&lt;BR /&gt;17:22:59.192528 IP fl-7034162.sc.reg.net.51362 &amp;gt; &amp;lt;ip-addr-removed&amp;gt;.https: P 17867:18679(812) ack 17555 win 256&lt;BR /&gt;17:22:59.192544 IP &amp;lt;ip-addr-removed&amp;gt;.https &amp;gt; fl-7034162.sc.reg.net.51362: . ack 18679 win 330&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So it seems we need to introduce another policy on SRXs but they are native fw's not next-gen, so dynamic policy is not an option.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Stay tuned !&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Ajaz&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 06 Feb 2018 11:36:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/download-pan-os-from-gui-failing-potential-mtu-problem/m-p/198994#M59021</guid>
      <dc:creator>nawaza</dc:creator>
      <dc:date>2018-02-06T11:36:41Z</dc:date>
    </item>
    <item>
      <title>Re: Download PAN-OS from GUI failing, potential MTU Problem ...</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/download-pan-os-from-gui-failing-potential-mtu-problem/m-p/199126#M59047</link>
      <description>&lt;P&gt;Ok so Palo use CDN (Content Delivery Network e.g Akamai), to deliver dynamic updates and downloads. If your network does not allow for the 'Dynamic' nature of CDN in terms of DNS, then modify your update server from:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;updates.paloaltonetworks.com&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;TO&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;staticupdates.paloaltonetworks.com&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Or.. architect your network to tolerate and act upon dynamic DNS&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also please take look at this for further details:&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.paloaltonetworks.com/documentation/71/pan-os/pan-os/threat-prevention/content-delivery-network-infrastructure-for-dynamic-updates" target="_blank"&gt;https://www.paloaltonetworks.com/documentation/71/pan-os/pan-os/threat-prevention/content-delivery-network-infrastructure-for-dynamic-updates&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope this helps !&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Ajaz&lt;/P&gt;</description>
      <pubDate>Wed, 07 Feb 2018 14:43:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/download-pan-os-from-gui-failing-potential-mtu-problem/m-p/199126#M59047</guid>
      <dc:creator>nawaza</dc:creator>
      <dc:date>2018-02-07T14:43:39Z</dc:date>
    </item>
  </channel>
</rss>

