<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: 5250's failing to pass traffic after AV software update in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/5250-s-failing-to-pass-traffic-after-av-software-update/m-p/224081#M64380</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/37645"&gt;@Bomi&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;So this has more possibility of being due to the Applications and Threats version then the AV upgrade. When the traffic was failing how was the traffic getting recognized, and did that traffic actually have any rules allowing it to go as the firewall was identifying it?&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 30 Jul 2018 21:38:32 GMT</pubDate>
    <dc:creator>BPry</dc:creator>
    <dc:date>2018-07-30T21:38:32Z</dc:date>
    <item>
      <title>5250's failing to pass traffic after AV software update</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/5250-s-failing-to-pass-traffic-after-av-software-update/m-p/224001#M64361</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;We are on the version 8.1.2 and If I upgrade to the latest ‘Applications and Threats’ version, &amp;nbsp;currently 8044-4859, and then upgrade AV from 2678-3175 to 2683-3180 all rules fail, and traffic drops through the default deny.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I do not see any particular logs except "HA peer Anti-Virus set to Unknown".&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P class="x_MsoNormal"&gt;2018-07-25 08:49:54:user:admin,client:Web,cmd:request anti-virus upgrade download file panup-all-antivirus-2683-3180&lt;/P&gt;&lt;P class="x_MsoNormal"&gt;opcmdhistory.log&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P class="x_MsoNormal"&gt;2018-07-25 08:50:13&lt;/P&gt;&lt;P class="x_MsoNormal"&gt;2018-07-25 08:50:13:user:admin,client:Web,cmd:request anti-virus upgrade info&lt;/P&gt;&lt;P class="x_MsoNormal"&gt;opcmdhistory.log&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P class="x_MsoNormal"&gt;2018-07-25 08:50:43&lt;/P&gt;&lt;P class="x_MsoNormal"&gt;2018-07-25 08:50:43:user:admin,client:Web,cmd:request anti-virus upgrade install commit yes file panup-all-antivirus-2683-3180.tgz&lt;/P&gt;&lt;P class="x_MsoNormal"&gt;ha_agent.log&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P class="x_MsoNormal"&gt;2018-07-25 08:51:42&lt;/P&gt;&lt;P class="x_MsoNormal"&gt;2018-07-25 08:51:42.015 +0100 debug: ha_sysd_general_vers_string(src/ha_sysd_version.c:1800): Got new Anti-Virus: 2683-3180; for local value&lt;/P&gt;&lt;P class="x_MsoNormal"&gt;ha_agent.log&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P class="x_MsoNormal"&gt;2018-07-25 08:51:42&lt;/P&gt;&lt;P class="x_MsoNormal"&gt;2018-07-25 08:51:42.015 +0100 HA peer Anti-Virus set to Unknown&lt;/P&gt;&lt;P class="x_MsoNormal"&gt;opcmdhistory.log&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P class="x_MsoNormal"&gt;2018-07-25 08:56:41&lt;/P&gt;&lt;P class="x_MsoNormal"&gt;2018-07-25 08:56:41:user:admin,client:Web,cmd:request anti-virus upgrade info&lt;/P&gt;&lt;P class="x_MsoNormal"&gt;pan_comm_0.log&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P class="x_MsoNormal"&gt;2018-07-25 09:15:25&lt;/P&gt;&lt;P class="x_MsoNormal"&gt;url get-your-anti-virus-checked.com, delete 0 children more&lt;/P&gt;&lt;P class="x_MsoNormal"&gt;pan_comm_0.log&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P class="x_MsoNormal"&gt;2018-07-25 09:15:25&lt;/P&gt;&lt;P class="x_MsoNormal"&gt;url get-your-anti-virus-checked.com, delete 0 children more&lt;/P&gt;&lt;P class="x_MsoNormal"&gt;opcmdhistory.log&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P class="x_MsoNormal"&gt;2018-07-25 11:26:03&lt;/P&gt;&lt;P class="x_MsoNormal"&gt;2018-07-25 11:26:03:user:admin,client:Web,cmd:request anti-virus upgrade info&lt;/P&gt;&lt;P class="x_MsoNormal"&gt;opcmdhistory.log&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P class="x_MsoNormal"&gt;2018-07-26 12:41:37&lt;/P&gt;&lt;P class="x_MsoNormal"&gt;2018-07-26 12:41:37:user:admin,client:Web,cmd:request anti-virus upgrade info&lt;/P&gt;&lt;P class="x_MsoNormal"&gt;&amp;nbsp;&lt;/P&gt;&lt;P class="x_MsoNormal"&gt;Any ideas?&lt;/P&gt;&lt;P class="x_MsoNormal"&gt;Thanks.&lt;/P&gt;&lt;P class="x_MsoNormal"&gt;&amp;nbsp;&lt;/P&gt;&lt;P class="x_MsoNormal"&gt;Best regards,&lt;/P&gt;&lt;P class="x_MsoNormal"&gt;Bomi&lt;/P&gt;&lt;P class="x_MsoNormal"&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 30 Jul 2018 14:01:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/5250-s-failing-to-pass-traffic-after-av-software-update/m-p/224001#M64361</guid>
      <dc:creator>Bomi</dc:creator>
      <dc:date>2018-07-30T14:01:59Z</dc:date>
    </item>
    <item>
      <title>Re: 5250's failing to pass traffic after AV software update</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/5250-s-failing-to-pass-traffic-after-av-software-update/m-p/224081#M64380</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/37645"&gt;@Bomi&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;So this has more possibility of being due to the Applications and Threats version then the AV upgrade. When the traffic was failing how was the traffic getting recognized, and did that traffic actually have any rules allowing it to go as the firewall was identifying it?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 30 Jul 2018 21:38:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/5250-s-failing-to-pass-traffic-after-av-software-update/m-p/224081#M64380</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2018-07-30T21:38:32Z</dc:date>
    </item>
    <item>
      <title>Re: 5250's failing to pass traffic after AV software update</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/5250-s-failing-to-pass-traffic-after-av-software-update/m-p/224146#M64389</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;SPAN class=""&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&amp;nbsp;&lt;/SPAN&gt;The same thing happend when only AV was updated. Applications were showing up as ‘not-applicable’ for services that should have been matched with our rules, but were dropping to the default deny rule.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 31 Jul 2018 10:39:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/5250-s-failing-to-pass-traffic-after-av-software-update/m-p/224146#M64389</guid>
      <dc:creator>Bomi</dc:creator>
      <dc:date>2018-07-31T10:39:07Z</dc:date>
    </item>
    <item>
      <title>Re: 5250's failing to pass traffic after AV software update</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/5250-s-failing-to-pass-traffic-after-av-software-update/m-p/224159#M64390</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/37645"&gt;@Bomi&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Personally I would contact TAC at this point. It sounds like the update is somehow negating your entire &amp;lt;security/&amp;gt; rulebase, either by making the XML malformed or something like that. I've seen this through OS updates, but never through dynamic updates.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 31 Jul 2018 13:55:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/5250-s-failing-to-pass-traffic-after-av-software-update/m-p/224159#M64390</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2018-07-31T13:55:49Z</dc:date>
    </item>
  </channel>
</rss>

