<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to fix &amp;quot;Unable to fetch external dynamic list. SSL connect error. Using old copy for re in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-fix-quot-unable-to-fetch-external-dynamic-list-ssl/m-p/224413#M64434</link>
    <description>&lt;P&gt;Not that I could find anyway.&amp;nbsp; I think it has to do with a &lt;A href="https://www.paloaltonetworks.com/documentation/80/pan-os/newfeaturesguide/authentication-features/authentication-for-external-dynamic-lists" target="_self"&gt;new requirement in 8.0&lt;/A&gt;&amp;nbsp;but very strange that we didn't see it enforced until we upgraded from 8.0.6 to 8.0.10 though.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; Snipet from the new requirement link above:&lt;/P&gt;&lt;DIV class="parsys titlealts"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class="p"&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; "When retrieving&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A title="" href="https://www.paloaltonetworks.com/documentation/80/pan-os/pan-os/policy/use-an-external-dynamic-list-in-policy.html" target="_blank"&gt;external dynamic lists&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;hosted on SSL/TLS secured servers (servers with an HTTPS URL), the firewall now&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;validates the digital certificates of the server before proceeding with the retrieval. You must now enable server&amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;/DIV&gt;&lt;DIV class="p"&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;authentication for these external dynamic lists for the firewall to retrieve them."&lt;/DIV&gt;</description>
    <pubDate>Wed, 01 Aug 2018 13:55:18 GMT</pubDate>
    <dc:creator>Lora</dc:creator>
    <dc:date>2018-08-01T13:55:18Z</dc:date>
    <item>
      <title>How to fix "Unable to fetch external dynamic list. SSL connect error. Using old copy for refresh"</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-fix-quot-unable-to-fetch-external-dynamic-list-ssl/m-p/224208#M64405</link>
      <description>&lt;P&gt;After upgrading from 8.0.6 to 8.0.10 our local EDL list stopped updating.&amp;nbsp; The&amp;nbsp;logs message states 'Unable to fetch external dynamic list. SSL connect error. Using old copy for refresh'.&amp;nbsp; Anyone have any ideas on how to fix this?&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I looked in the release notes from some hints and came up empty.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks - Lora&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 31 Jul 2018 18:41:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-fix-quot-unable-to-fetch-external-dynamic-list-ssl/m-p/224208#M64405</guid>
      <dc:creator>Lora</dc:creator>
      <dc:date>2018-07-31T18:41:45Z</dc:date>
    </item>
    <item>
      <title>Re: How to fix "Unable to fetch external dynamic list. SSL connect error. Using old copy for re</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-fix-quot-unable-to-fetch-external-dynamic-list-ssl/m-p/224238#M64413</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Anything in the logs that might indicate that the traffic is getting blocked?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Just a thought.&lt;/P&gt;</description>
      <pubDate>Tue, 31 Jul 2018 20:45:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-fix-quot-unable-to-fetch-external-dynamic-list-ssl/m-p/224238#M64413</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2018-07-31T20:45:07Z</dc:date>
    </item>
    <item>
      <title>Re: How to fix "Unable to fetch external dynamic list. SSL connect error. Using old copy for re</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-fix-quot-unable-to-fetch-external-dynamic-list-ssl/m-p/224413#M64434</link>
      <description>&lt;P&gt;Not that I could find anyway.&amp;nbsp; I think it has to do with a &lt;A href="https://www.paloaltonetworks.com/documentation/80/pan-os/newfeaturesguide/authentication-features/authentication-for-external-dynamic-lists" target="_self"&gt;new requirement in 8.0&lt;/A&gt;&amp;nbsp;but very strange that we didn't see it enforced until we upgraded from 8.0.6 to 8.0.10 though.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; Snipet from the new requirement link above:&lt;/P&gt;&lt;DIV class="parsys titlealts"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class="p"&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; "When retrieving&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A title="" href="https://www.paloaltonetworks.com/documentation/80/pan-os/pan-os/policy/use-an-external-dynamic-list-in-policy.html" target="_blank"&gt;external dynamic lists&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;hosted on SSL/TLS secured servers (servers with an HTTPS URL), the firewall now&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;validates the digital certificates of the server before proceeding with the retrieval. You must now enable server&amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;/DIV&gt;&lt;DIV class="p"&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;authentication for these external dynamic lists for the firewall to retrieve them."&lt;/DIV&gt;</description>
      <pubDate>Wed, 01 Aug 2018 13:55:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-fix-quot-unable-to-fetch-external-dynamic-list-ssl/m-p/224413#M64434</guid>
      <dc:creator>Lora</dc:creator>
      <dc:date>2018-08-01T13:55:18Z</dc:date>
    </item>
    <item>
      <title>Re: How to fix "Unable to fetch external dynamic list. SSL connect error. Using old copy for re</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-fix-quot-unable-to-fetch-external-dynamic-list-ssl/m-p/224437#M64437</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/36916"&gt;@Lora&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;There was a slight hicup with that where you might not have noticed it directly until post 8.0.7 when that issue was addressed. That being said this would normally generate a more informative error instead of what you posted, which is rather generic. Regardless if you setup the certificate profile or set the EDL to "None" on the Server Authentication it should be able to actually pull the SSL again if that's the issue, so it should be a pretty quick thing to test.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 01 Aug 2018 15:08:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-fix-quot-unable-to-fetch-external-dynamic-list-ssl/m-p/224437#M64437</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2018-08-01T15:08:48Z</dc:date>
    </item>
    <item>
      <title>Re: How to fix "Unable to fetch external dynamic list. SSL connect error. Using old copy for re</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-fix-quot-unable-to-fetch-external-dynamic-list-ssl/m-p/224439#M64439</link>
      <description>&lt;P&gt;We have it set to none and it's not working and that is the only log message I am able to locate &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 01 Aug 2018 15:13:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-fix-quot-unable-to-fetch-external-dynamic-list-ssl/m-p/224439#M64439</guid>
      <dc:creator>Lora</dc:creator>
      <dc:date>2018-08-01T15:13:45Z</dc:date>
    </item>
    <item>
      <title>Re: How to fix "Unable to fetch external dynamic list. SSL connect error. Using old copy for re</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-fix-quot-unable-to-fetch-external-dynamic-list-ssl/m-p/224447#M64445</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/36916"&gt;@Lora&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Maybe this doesn't matter but did you do this through the CLI or the GUI. I recall an issue a while back that was specific to GUI where setting the certificate-profile to None wasn't the same on the GUI as specifying it in the CLI. Not sure if that ever got fixed or not.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 01 Aug 2018 15:40:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-fix-quot-unable-to-fetch-external-dynamic-list-ssl/m-p/224447#M64445</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2018-08-01T15:40:50Z</dc:date>
    </item>
    <item>
      <title>Re: How to fix "Unable to fetch external dynamic list. SSL connect error. Using old copy for re</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-fix-quot-unable-to-fetch-external-dynamic-list-ssl/m-p/224468#M64449</link>
      <description>&lt;P&gt;I tried&amp;nbsp;setting the profile to none via the CLI and that didn't fix either.&amp;nbsp; For those following along the CLI commands I used to set the ertificate-profile to None via the CLI on a Panroma device were:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp;From &lt;STRONG&gt;configure&lt;/STRONG&gt; mode:&amp;nbsp;&amp;nbsp;&lt;STRONG&gt;&lt;SPAN class="s1"&gt;set shared external-list "Name of Your List" type url certificate-profile None &amp;lt;enter&amp;gt;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="s1"&gt;&amp;nbsp; &amp;nbsp;then I isseud a comitt and exited configure and issued a&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN class="s1"&gt;commit-all shared-policy device-group &amp;lt;name&amp;gt;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="s1"&gt;I then watched the system logs on the firewall directly and see the same warning messages as before.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="s1"&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-right" image-alt="Screen Shot 2018-08-01 at 2.44.06 PM.png" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/16126iF6A2EC6F509D029E/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Screen Shot 2018-08-01 at 2.44.06 PM.png" alt="Screen Shot 2018-08-01 at 2.44.06 PM.png" /&gt;&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="s1"&gt;I then checked the object list entries to determine if the list had been update or not and found it was not &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="s1"&gt;Looks like we will need to open a case.&amp;nbsp; Thanks all for the ideas!&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 01 Aug 2018 21:30:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-fix-quot-unable-to-fetch-external-dynamic-list-ssl/m-p/224468#M64449</guid>
      <dc:creator>Lora</dc:creator>
      <dc:date>2018-08-01T21:30:48Z</dc:date>
    </item>
    <item>
      <title>Re: How to fix "Unable to fetch external dynamic list. SSL connect error. Using old copy for re</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-fix-quot-unable-to-fetch-external-dynamic-list-ssl/m-p/224480#M64453</link>
      <description>&lt;P&gt;PANTAC has determined this is a TLS mismatch problem and is checking to see if there is an available work&amp;nbsp;around while we determine&amp;nbsp;internaly if we can upgrade the server or move the EDL to a more modern host.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For those following along (and since I could not find this command anywhere)&amp;nbsp; this is what PANTAC did &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;Set up TCPDump PCAP to capture traffic to the EDL from one CLI window&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;STRONG&gt;tcpdump filter "host xx.xx.xx.xx&lt;/STRONG&gt;" (xx= ip of the external server hosting the EDL)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;From a second CLI window;&amp;nbsp;&lt;SPAN&gt;&amp;nbsp;Ran a manual EDL refresh via the CLI by "&lt;STRONG&gt;request system external-list refresh type url name &amp;lt;name&amp;gt;&lt;/STRONG&gt;"&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;We then exported the PCAP file to my workstatoin&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;STRONG&gt;scp export mgmt-pcap from mgmt.pcap to user@analyst_workstation_ip:./&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;SPAN&gt;Reviewed the PCAP using wireshark and discovered the&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;Client Hello from the firewall showing TLS 1.2 and the Server Hello shows TLS 1.0, then the firewall sends a fatal error protocol version message.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Lastly to view the local logs from the CLI instead of the GUI, you can issue a command such as this:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp; &amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="s1"&gt;&lt;STRONG&gt;tail follow yes mp-log ms.log&lt;/STRONG&gt; from one terminal window while re-issuing the&amp;nbsp;&lt;STRONG&gt;request system external-list refresh type url name &amp;lt;name&amp;gt; &lt;/STRONG&gt;commands from a second window.&amp;nbsp; In this particular case the raw logs were not more helpful than the GUI logs though - they both just stated "&lt;/SPAN&gt;&lt;SPAN class="s1"&gt;Unable to fetch external dynamic list. SSL connect error. Using old copy for refresh."&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="s1"&gt;More to come when we finally resolve the issue.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp; &amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 01 Aug 2018 21:29:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-fix-quot-unable-to-fetch-external-dynamic-list-ssl/m-p/224480#M64453</guid>
      <dc:creator>Lora</dc:creator>
      <dc:date>2018-08-01T21:29:50Z</dc:date>
    </item>
    <item>
      <title>Re: How to fix "Unable to fetch external dynamic list. SSL connect error. Using old copy for re</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-fix-quot-unable-to-fetch-external-dynamic-list-ssl/m-p/226648#M65236</link>
      <description>&lt;P&gt;The TLS mismatch issue has been resolved by hosting the internally sourced EDL&amp;nbsp;from a more modern web server that supports TLS1.2.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 09 Aug 2018 19:08:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-fix-quot-unable-to-fetch-external-dynamic-list-ssl/m-p/226648#M65236</guid>
      <dc:creator>Lora</dc:creator>
      <dc:date>2018-08-09T19:08:58Z</dc:date>
    </item>
  </channel>
</rss>

