<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Error fetching External Dynamic List (EDL) in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/error-fetching-external-dynamic-list-edl/m-p/222923#M64086</link>
    <description>&lt;P&gt;Is the EDL external to your network?&amp;nbsp; If so, is there a security policy (and likely a nat policy) allowing the management interface of the firewall to access it?&amp;nbsp; AFAIK, TLS 1.1 and 1.2&amp;nbsp;are supported&lt;/P&gt;</description>
    <pubDate>Thu, 19 Jul 2018 11:25:28 GMT</pubDate>
    <dc:creator>JoeAndreini</dc:creator>
    <dc:date>2018-07-19T11:25:28Z</dc:date>
    <item>
      <title>Error fetching External Dynamic List (EDL)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/error-fetching-external-dynamic-list-edl/m-p/222889#M64080</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When trying to fetch an EDL from a web server configured without support for TLSv1 (only support TLSv1.1 or 1.2) the result is "Server error : URL access error".&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I don't know if PAN-OS 7.1.18 fetch client for EDL only support TLSv1. Checking ciphers compatibility for 7.1 I can't find the answer:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A title="PAN-OS 7.1 Decryption Cipher Suites" href="https://www.paloaltonetworks.com/documentation/global/compatibility-matrix/supported-cipher-suites/cipher-suites-supported-in-pan-os-7-1/cipher-suites-supported-in-pan-os-7-1-decryption" target="_blank"&gt;https://www.paloaltonetworks.com/documentation/global/compatibility-matrix/supported-cipher-suites/cipher-suites-supported-in-pan-os-7-1/cipher-suites-supported-in-pan-os-7-1-decryption&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advance.&lt;/P&gt;&lt;P&gt;Regards.&lt;/P&gt;</description>
      <pubDate>Thu, 19 Jul 2018 07:08:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/error-fetching-external-dynamic-list-edl/m-p/222889#M64080</guid>
      <dc:creator>fjmjugr</dc:creator>
      <dc:date>2018-07-19T07:08:30Z</dc:date>
    </item>
    <item>
      <title>Re: Error fetching External Dynamic List (EDL)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/error-fetching-external-dynamic-list-edl/m-p/222923#M64086</link>
      <description>&lt;P&gt;Is the EDL external to your network?&amp;nbsp; If so, is there a security policy (and likely a nat policy) allowing the management interface of the firewall to access it?&amp;nbsp; AFAIK, TLS 1.1 and 1.2&amp;nbsp;are supported&lt;/P&gt;</description>
      <pubDate>Thu, 19 Jul 2018 11:25:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/error-fetching-external-dynamic-list-edl/m-p/222923#M64086</guid>
      <dc:creator>JoeAndreini</dc:creator>
      <dc:date>2018-07-19T11:25:28Z</dc:date>
    </item>
    <item>
      <title>Re: Error fetching External Dynamic List (EDL)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/error-fetching-external-dynamic-list-edl/m-p/222973#M64098</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/12668"&gt;@fjmjugr&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;As&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/83021"&gt;@JoeAndreini&lt;/a&gt;&amp;nbsp;stated I'm willing to bet that this is a security/nat policy issue more then anything else.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 19 Jul 2018 17:14:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/error-fetching-external-dynamic-list-edl/m-p/222973#M64098</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2018-07-19T17:14:39Z</dc:date>
    </item>
    <item>
      <title>Re: Error fetching External Dynamic List (EDL)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/error-fetching-external-dynamic-list-edl/m-p/222979#M64104</link>
      <description>&lt;P&gt;Hi Joe,&lt;/P&gt;&lt;P&gt;Thanks for your answer.&lt;/P&gt;&lt;P&gt;Web server is inernal and there aren't any problem if we use http instead of https or https with TLSv1 enabled&amp;nbsp;&lt;/P&gt;&lt;P&gt;With TLSv1, 1.1 &amp;amp; 2 versions at web server, logs show FW is negotiating TLSv1:&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;[18/Jul/2018:21:32:26 +0200] *.*.*.* TLSv1 ECDHE-RSA-AES256-SHA "GET /***** HTTP/1.1" 8&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But if we disable TLSv1, the result is "&lt;SPAN&gt;Server error : URL access error" when testing it from CLI.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Sorry, probably I'm not beeing clear:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;1.- Web server with only TLS1.1 and TLS1.2 enabled -&amp;gt; result: error&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;2.- Web server with all TLS versions (1, 1.1 &amp;amp; 2) -&amp;gt; result: success (negotiating v1).&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Aparently&amp;nbsp; this is not related with policy.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thanks!&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Regards.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 19 Jul 2018 17:29:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/error-fetching-external-dynamic-list-edl/m-p/222979#M64104</guid>
      <dc:creator>fjmjugr</dc:creator>
      <dc:date>2018-07-19T17:29:25Z</dc:date>
    </item>
    <item>
      <title>Re: Error fetching External Dynamic List (EDL)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/error-fetching-external-dynamic-list-edl/m-p/222980#M64105</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/12668"&gt;@fjmjugr&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Are you using a certificate profile when you go to grab that EDL?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 19 Jul 2018 17:40:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/error-fetching-external-dynamic-list-edl/m-p/222980#M64105</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2018-07-19T17:40:39Z</dc:date>
    </item>
    <item>
      <title>Re: Error fetching External Dynamic List (EDL)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/error-fetching-external-dynamic-list-edl/m-p/222982#M64107</link>
      <description>&lt;P&gt;Is the Certificate signed by a trusted external CA?&amp;nbsp; Make sure the root/intermediate certificates are in teh trusted root store.&lt;/P&gt;</description>
      <pubDate>Thu, 19 Jul 2018 18:07:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/error-fetching-external-dynamic-list-edl/m-p/222982#M64107</guid>
      <dc:creator>JoeAndreini</dc:creator>
      <dc:date>2018-07-19T18:07:05Z</dc:date>
    </item>
    <item>
      <title>Re: Error fetching External Dynamic List (EDL)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/error-fetching-external-dynamic-list-edl/m-p/223016#M64116</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;, I think&amp;nbsp; Authetication for EDL is a new feature of PAN-OS 8.0, but I'm using 7.1.18&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A title="Authentication for External Dynamic Lists" href="https://www.paloaltonetworks.com/documentation/80/pan-os/newfeaturesguide/authentication-features/authentication-for-external-dynamic-lists" target="_blank"&gt;https://www.paloaltonetworks.com/documentation/80/pan-os/newfeaturesguide/authentication-features/authentication-for-external-dynamic-lists&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/83021"&gt;@JoeAndreini&lt;/a&gt;&amp;nbsp;I think that is not necesary (using 7.1). For example, I'm testing Minemeld and at this moment I'm using selfsigned certificate &amp;amp; MM CA. With that configuration, firewalls can fetch EDLs from MM withot having included CA at them.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;I found a resolved issue:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;&lt;DIV class="p"&gt;&lt;STRONG&gt;PAN-85047&lt;/STRONG&gt;&lt;/DIV&gt;&lt;/TD&gt;&lt;TD&gt;&lt;DIV class="p"&gt;Fixed an issue where the firewall failed to retrieve a domain list from an external dynamic list (EDL) server over a TLSv1.0 connection.&lt;/DIV&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&lt;SPAN class=""&gt;but it is for 8.0.7 and only talks about TLSv1 (probably, not related to my initial question).&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;Thanks you both for your suggestions.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;Regards.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 20 Jul 2018 00:08:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/error-fetching-external-dynamic-list-edl/m-p/223016#M64116</guid>
      <dc:creator>fjmjugr</dc:creator>
      <dc:date>2018-07-20T00:08:51Z</dc:date>
    </item>
  </channel>
</rss>

