<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: FQDN refresh  problems in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/fqdn-refresh-problems/m-p/237952#M68175</link>
    <description>&lt;P&gt;Thanks for your answer.&lt;/P&gt;&lt;P&gt;I searched for the active-directory application and saw that we have one rule with it.&lt;/P&gt;&lt;P&gt;For testing I deleted the application in the rule and then the FQDN resolve started to work. I thought "ok, weird that this solved it". For testing again, I added the active-directory application to the exact same rule and to my surprise, the FQDN refresh is still working.... So in the end it solved the problem for now but at the same time it was not the trigger. I will monitor it if the refresh will start to fail again.&lt;/P&gt;</description>
    <pubDate>Wed, 31 Oct 2018 13:41:44 GMT</pubDate>
    <dc:creator>ErrantOsi</dc:creator>
    <dc:date>2018-10-31T13:41:44Z</dc:date>
    <item>
      <title>FQDN refresh  problems</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/fqdn-refresh-problems/m-p/237800#M68136</link>
      <description>&lt;P&gt;Hell guys,&lt;/P&gt;&lt;P&gt;We have a problem that the FQDN refresh fails nearly everytime. What I mean with "nearly" everytime is, that there are periods in which the FQDN refresh is running smoothly, and then suddenly it fails again.&lt;/P&gt;&lt;P&gt;Example: A few days ago the FQDN refresh failed for the 365th time. We then disabled the DNS Proxy because there was something in the logs regarding DNS proxy and then it worked again. Two days later, out of nothing, the FQDN refreshes started failing again. Today early morning at 00:37 the FQDN refresh worked again, and later at 10:12 it started to fail again. No changes in between. (except dynamic updates from PAN)&lt;/P&gt;&lt;P&gt;Below you will find the MP logs (manual FQDN refresh). It can resolve all FQDN, but then somehow fails.&lt;/P&gt;&lt;P&gt;Does anyone have the same problems? Any tips?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advance and best regards&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;2018-10-29 09:15:08.416 +0100 debug: pan_dnscfg_recv_resp(pan_cfg_dnscfg.c:550): dnscfgmod: response received 12, to resolve 12&lt;BR /&gt;&lt;STRONG&gt;2018-10-29 09:15:08.416 +0100 debug: pan_dnscfg_recv_resp(pan_cfg_dnscfg.c:559): dnscfgmod: All Fqdns responses received&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;2018-10-29 09:15:08.416 +0100 debug: pan_dnscfg_resolve_now(pan_cfg_dnscfg.c:3417): dnscfgmod: Done timedwait&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;2018-10-29 09:15:08.416 +0100 dnscfgmod: Resolving fqdns took 1 secs&lt;/STRONG&gt;&lt;BR /&gt;2018-10-29 09:15:08.416 +0100 Fqdn refresher thread device requested last config&lt;BR /&gt;2018-10-29 09:15:08.429 +0100 debug: pan_cfg_populate_candidate_ids(pan_cfg_commit_jobs.c:338): id population started&lt;BR /&gt;2018-10-29 09:15:11.904 +0100 debug: pan_comm_lcs_get_next_addr(cs_conn.c:4770): connmgr:&amp;nbsp; &amp;gt;&amp;gt;&amp;gt; pan_comm_lcs_get_next_addr()&lt;BR /&gt;2018-10-29 09:15:12.024 +0100 debug: pan_lcsa_tcp_connect_pref_list(src_panos/lcs_agent.c:1488): pan_fd_watcher_wait, time elapsed = 30000&lt;BR /&gt;2018-10-29 09:15:12.024 +0100 debug: pan_lcsa_tcp_connect_pref_list(src_panos/lcs_agent.c:1497): timedout from watcher&lt;BR /&gt;2018-10-29 09:15:12.024 +0100 debug: pan_lcsa_tcp_connect_pref_list(src_panos/lcs_agent.c:1458): get MIN earliest timeout from conn &amp;amp; pref list = 30000&lt;BR /&gt;2018-10-29 09:15:12.179 +0100 Populating id readonly: size: 16777216 nofree_chunk, allocated 3 chunks, chunk size 16777216&lt;BR /&gt;alloc usage 46829131 max. usage 46829131&lt;BR /&gt;2018-10-29 09:15:12.189 +0100 shm alloc(read-only) 'pan_shm_base' size 104172048&lt;BR /&gt;2018-10-29 09:15:12.189 +0100 debug: pan_config_populate_vrouter(pan_config_handler.c:342): populate vrouter name = default found with id 1&lt;BR /&gt;2018-10-29 09:15:12.196 +0100 Warning:&amp;nbsp; pan_config_populate_global_app(pan_config_handler.c:631): application active-directory has the same id 4 as active-directory-base.&lt;BR /&gt;2018-10-29 09:15:12.197 +0100 Error:&amp;nbsp; pan_shmgr_add_mmap(pan_shmgr.c:1467): readonly shmgr, can't create id&lt;BR /&gt;2018-10-29 09:15:12.197 +0100 Error:&amp;nbsp; __pan_shmgr_preprocess_obj_type(pan_shmgr.c:1630): func(type 9) failed: Error: Error inserting shared-application id for 'active-directory' (4)&lt;BR /&gt;&lt;BR /&gt;2018-10-29 09:15:12.197 +0100 Error:&amp;nbsp; __pan_shmgr_preprocess_obj_type(pan_shmgr.c:1673): __pan_shmgr_preprocess_obj_type(entry:i) failed&lt;BR /&gt;2018-10-29 09:15:12.197 +0100 Error:&amp;nbsp; __pan_shmgr_preprocess_obj_type(pan_shmgr.c:1673): __pan_shmgr_preprocess_obj_type(application) failed&lt;BR /&gt;2018-10-29 09:15:12.197 +0100 Error:&amp;nbsp; pan_config_populate_id_readonly(pan_config_handler.c:794): pan_config_preprocess_obj() failed&lt;BR /&gt;2018-10-29 09:15:12.221 +0100 Error:&amp;nbsp; pan_cfg_populate_candidate_ids(pan_cfg_commit_jobs.c:342): Unable to populate ids into the config:&lt;BR /&gt;Error: Error inserting shared-application id for 'active-directory' (4)&lt;BR /&gt;&lt;BR /&gt;2018-10-29 09:15:12.224 +0100 Error:&amp;nbsp; pan_cfg_get_lastcfg_fqdnrefresh(pan_cfg_commit_jobs.c:753): Unable to populate ids into candidate config:&lt;BR /&gt;Error: Error inserting shared-application id for 'active-directory' (4)&lt;BR /&gt;&lt;BR /&gt;2018-10-29 09:15:12.224 +0100 Error:&amp;nbsp; pan_cfg_dnscfg_refresh_fqdns(pan_cfg_dnscfg.c:4416): dnscfgmod: Failed to get valid last config for fqdn refresh&lt;BR /&gt;2018-10-29 09:15:12.225 +0100 debug: _pan_cfg_run_query_match(pan_log_handler.c:4776): query match using fsm at index: 0&lt;BR /&gt;2018-10-29 09:15:12.225 +0100 debug: pan_logfwd_syslog_handler(pan_logforward.c:1181): Running pan_logfwd_syslog_handler() ...&lt;BR /&gt;2018-10-29 09:15:12.225 +0100 debug: pan_logfwd_syslog_handler(pan_logforward.c:1209): subtype: 0&lt;BR /&gt;2018-10-29 09:15:12.225 +0100 debug: pan_logfwd_syslog(pan_syslog.c:866): Running pan_logfwd_syslog() ...&lt;BR /&gt;2018-10-29 09:15:12.225 +0100 debug: pan_logfwd_email_handler(pan_logforward.c:1669): Running pan_logfwd_email_handler() ...&lt;BR /&gt;2018-10-29 09:15:12.225 +0100 debug: pan_logfwd_email_handler(pan_logforward.c:1681): subtype: 0&lt;BR /&gt;2018-10-29 09:15:12.225 +0100 debug: pan_get_vsys_dns_from_sysd_obj(pan_dnsproxyd_sysd_api.c:778): DNS_API - sysd 0x1088a700 - vsysname 0x1932182c&lt;BR /&gt;2018-10-29 09:15:12.226 +0100 Error:&amp;nbsp; pan_jobmgr_process_job(pan_job_mgr.c:3274): Fqdn Refresh job failed&lt;BR /&gt;2018-10-29 09:15:12.226 +0100 debug: _pan_cfg_run_query_match(pan_log_handler.c:4776): query match using fsm at index: 0&lt;BR /&gt;2018-10-29 09:15:12.226 +0100 debug: pan_logfwd_syslog_handler(pan_logforward.c:1181): Running pan_logfwd_syslog_handler() ...&lt;BR /&gt;2018-10-29 09:15:12.226 +0100 debug: pan_logfwd_syslog_handler(pan_logforward.c:1209): subtype: 0&lt;BR /&gt;2018-10-29 09:15:12.226 +0100 debug: pan_logfwd_syslog(pan_syslog.c:866): Running pan_logfwd_syslog() ...&lt;BR /&gt;2018-10-29 09:15:12.462 +0100 debug: pan_logfwd_email_handler(pan_logforward.c:1669): Running pan_logfwd_email_handler() ...&lt;BR /&gt;2018-10-29 09:15:12.462 +0100 debug: pan_logfwd_email_handler(pan_logforward.c:1681): subtype: 0&lt;BR /&gt;2018-10-29 09:15:12.462 +0100 debug: pan_get_vsys_dns_from_sysd_obj(pan_dnsproxyd_sysd_api.c:778): DNS_API - sysd 0x1088a700 - vsysname 0x110d112c&lt;BR /&gt;2018-10-29 09:15:15.463 +0100 debug: pan_cfg_handle_op(pan_cfg_op_handler.c:1621): operational cmd target:mgmt complete?:no handler:show_session_timeout_handler&lt;BR /&gt;2018-10-29 09:15:15.463 +0100 debug: pan_cfg_execute_mgmtop(pan_ops_common.c:38401): OPCMD show_session_timeout_handler&lt;BR /&gt;2018-10-29 09:15:15.629 +0100 debug: _pan_cfg_exec_ctxt_init(pan_cfg_engine.c:2177): effective xpath is:/config/devices/entry[@name='localhost.localdomain']/deviceconfig/system/update-schedule/statistics-service/threat-prevention-information&lt;/P&gt;</description>
      <pubDate>Tue, 30 Oct 2018 15:53:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/fqdn-refresh-problems/m-p/237800#M68136</guid>
      <dc:creator>ErrantOsi</dc:creator>
      <dc:date>2018-10-30T15:53:07Z</dc:date>
    </item>
    <item>
      <title>Re: FQDN refresh  problems</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/fqdn-refresh-problems/m-p/237835#M68147</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/100717"&gt;@ErrantOsi&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;The refresh does a bit of work in the background, since it actually has to input the IPs that resolved to the FQDN objects into the functioning rulebase of the device. Nothing really looks alarming in your output until you get to the following line:&lt;/P&gt;&lt;PRE&gt;2018-10-29 09:15:12.196 +0100 Warning:  pan_config_populate_global_app(pan_config_handler.c:631): application active-directory has the same id 4 as active-directory-base.&lt;/PRE&gt;&lt;P&gt;Since that's failing the system can't actually build the functional config of the device, as further evident in the below error.&lt;/P&gt;&lt;PRE&gt;2018-10-29 09:15:12.221 +0100 Error:  pan_cfg_populate_candidate_ids(pan_cfg_commit_jobs.c:342): Unable to populate ids into the config:
Error: Error inserting shared-application id for 'active-directory' (4)&lt;/PRE&gt;&lt;P&gt;Since it can't build a functional configuration it can't very well populate the fqdn resolved IPs into said cconfiguration.&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;2018-10-29 09:15:12.224 +0100 Error:  pan_cfg_dnscfg_refresh_fqdns(pan_cfg_dnscfg.c:4416): dnscfgmod: Failed to get valid last config for fqdn refresh&lt;/PRE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For something like this I would highly recommend reaching out to TAC and opening a case with them, so they can see exactly what's going on. The bigger question for me would actually be why it's working at all; as if you have an issue with the application base you wouldn't expect that to 'fix' itself.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 30 Oct 2018 18:28:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/fqdn-refresh-problems/m-p/237835#M68147</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2018-10-30T18:28:00Z</dc:date>
    </item>
    <item>
      <title>Re: FQDN refresh  problems</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/fqdn-refresh-problems/m-p/237952#M68175</link>
      <description>&lt;P&gt;Thanks for your answer.&lt;/P&gt;&lt;P&gt;I searched for the active-directory application and saw that we have one rule with it.&lt;/P&gt;&lt;P&gt;For testing I deleted the application in the rule and then the FQDN resolve started to work. I thought "ok, weird that this solved it". For testing again, I added the active-directory application to the exact same rule and to my surprise, the FQDN refresh is still working.... So in the end it solved the problem for now but at the same time it was not the trigger. I will monitor it if the refresh will start to fail again.&lt;/P&gt;</description>
      <pubDate>Wed, 31 Oct 2018 13:41:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/fqdn-refresh-problems/m-p/237952#M68175</guid>
      <dc:creator>ErrantOsi</dc:creator>
      <dc:date>2018-10-31T13:41:44Z</dc:date>
    </item>
  </channel>
</rss>

