<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cannot contact update server from public IP address interface in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/cannot-contact-update-server-from-public-ip-address-interface/m-p/246068#M70096</link>
    <description>&lt;P&gt;If you have your DNS set correctly in the services tab then try changing the service route to the same as your palo alto updates.&lt;/P&gt;</description>
    <pubDate>Tue, 15 Jan 2019 13:55:35 GMT</pubDate>
    <dc:creator>Mick_Ball</dc:creator>
    <dc:date>2019-01-15T13:55:35Z</dc:date>
    <item>
      <title>Cannot contact update server from public IP address interface</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/cannot-contact-update-server-from-public-ip-address-interface/m-p/246040#M70091</link>
      <description>&lt;P&gt;After click "Check Now" in "Dynamic Updates". Show the error popup as below link&lt;/P&gt;&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClkuCAC" target="_self"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClkuCAC&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The above KB not apply to my case. As I&amp;nbsp;not allow my management interface to reach internet.&lt;/P&gt;&lt;P&gt;So I go to customize "Service Route Configuration", and set the Source Address of Service - "Palo Alto Networks Services" and "URL Updates" to be the internet facing interface which assigned a public IP address. Still now work. Although I'm not sure these 2 services is for Dynamic Updates or not.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;SSH to CLI. I ping source interface public IP to host &lt;A href="http://www.google.com" target="_blank"&gt;www.google.com&lt;/A&gt;. Result is unknown host.&amp;nbsp;If change to ping the IP of &lt;A href="http://www.google.com.&amp;nbsp;" target="_blank"&gt;www.google.com.&amp;nbsp;&lt;/A&gt;&lt;SPAN&gt;Result is 100% lost. But webUI Traffic logs show ping allow.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;That's weird since all internal users go to internet through that interface without problem. But ping source from it result in all packet lost.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any possible reason cause this problem?&lt;/P&gt;</description>
      <pubDate>Tue, 15 Jan 2019 08:56:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/cannot-contact-update-server-from-public-ip-address-interface/m-p/246040#M70091</guid>
      <dc:creator>jeremylo</dc:creator>
      <dc:date>2019-01-15T08:56:48Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot contact update server from public IP address interface</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/cannot-contact-update-server-from-public-ip-address-interface/m-p/246066#M70095</link>
      <description>&lt;P&gt;"unknown host"&amp;nbsp;&amp;nbsp; would suggest that your DNS is not working correctly for your services.&lt;/P&gt;</description>
      <pubDate>Tue, 15 Jan 2019 13:45:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/cannot-contact-update-server-from-public-ip-address-interface/m-p/246066#M70095</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2019-01-15T13:45:36Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot contact update server from public IP address interface</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/cannot-contact-update-server-from-public-ip-address-interface/m-p/246068#M70096</link>
      <description>&lt;P&gt;If you have your DNS set correctly in the services tab then try changing the service route to the same as your palo alto updates.&lt;/P&gt;</description>
      <pubDate>Tue, 15 Jan 2019 13:55:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/cannot-contact-update-server-from-public-ip-address-interface/m-p/246068#M70096</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2019-01-15T13:55:35Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot contact update server from public IP address interface</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/cannot-contact-update-server-from-public-ip-address-interface/m-p/246076#M70098</link>
      <description>&lt;P&gt;To confirm: the correct service route is "Palo Alto Updates"&lt;/P&gt;</description>
      <pubDate>Tue, 15 Jan 2019 13:57:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/cannot-contact-update-server-from-public-ip-address-interface/m-p/246076#M70098</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2019-01-15T13:57:19Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot contact update server from public IP address interface</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/cannot-contact-update-server-from-public-ip-address-interface/m-p/246430#M70173</link>
      <description>&lt;P&gt;Hello MickBall,&lt;/P&gt;&lt;P&gt;The PAN OS version is 8.0.7&lt;/P&gt;&lt;P&gt;Service Route has no "&lt;SPAN&gt;Palo Alto Updates".&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 17 Jan 2019 06:52:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/cannot-contact-update-server-from-public-ip-address-interface/m-p/246430#M70173</guid>
      <dc:creator>jeremylo</dc:creator>
      <dc:date>2019-01-17T06:52:44Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot contact update server from public IP address interface</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/cannot-contact-update-server-from-public-ip-address-interface/m-p/246433#M70175</link>
      <description>&lt;P&gt;Yes, sorry the description changed in v8.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;anyhows... seems like dns is not working. What is your dns address in services.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;try setting it to 8.8.8.8 and changedns service route to the same as your palo alto updates.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;not sure but you may need a dns policy to allow this out.&lt;/P&gt;</description>
      <pubDate>Thu, 17 Jan 2019 07:36:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/cannot-contact-update-server-from-public-ip-address-interface/m-p/246433#M70175</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2019-01-17T07:36:03Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot contact update server from public IP address interface</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/cannot-contact-update-server-from-public-ip-address-interface/m-p/246434#M70176</link>
      <description>&lt;P&gt;I temporary change the service route config to "Use Management Interface for all". But still cannot ping outside.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The Management interface set as below:&lt;/P&gt;&lt;P&gt;IP Address: 192.168.123.123&lt;/P&gt;&lt;P&gt;Netmask: 255.255.255.0&lt;/P&gt;&lt;P&gt;Default Gateway: 192.168.123.254&lt;/P&gt;&lt;P&gt;Speed: auto-negotiate&lt;/P&gt;&lt;P&gt;MTU: 1500&lt;/P&gt;&lt;P&gt;Network Connectivity Services: HTTPS, Ping, SSH&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Services set as below:&lt;/P&gt;&lt;P&gt;Primary DNS Server: 8.8.8.8&lt;/P&gt;&lt;P&gt;Secondary DNS Server: 8.8.4.4&lt;/P&gt;&lt;P&gt;Update Server: updates.paloaltonetworks.com&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Security Policy set allow the source zone of management interface to destination zone internet facing interface&lt;/P&gt;&lt;P&gt;Monitor Traffic show source 192.168.123.123 to destination 8.8.8.8, application ping and dns are allow. Use the correct rule too.&lt;/P&gt;</description>
      <pubDate>Thu, 17 Jan 2019 08:02:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/cannot-contact-update-server-from-public-ip-address-interface/m-p/246434#M70176</guid>
      <dc:creator>jeremylo</dc:creator>
      <dc:date>2019-01-17T08:02:59Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot contact update server from public IP address interface</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/cannot-contact-update-server-from-public-ip-address-interface/m-p/246460#M70180</link>
      <description>&lt;P&gt;i have the following settings and it works.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;custom service routes&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;DNS =&amp;nbsp;internet interface/ip address&lt;/P&gt;&lt;P&gt;Updates = internet interface/ip address&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;it works without any additional polices because the default intranet policy is applied.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="serviceroutes.png" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/18320i24AD979FF8D652FF/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="serviceroutes.png" alt="serviceroutes.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 17 Jan 2019 10:27:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/cannot-contact-update-server-from-public-ip-address-interface/m-p/246460#M70180</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2019-01-17T10:27:36Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot contact update server from public IP address interface</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/cannot-contact-update-server-from-public-ip-address-interface/m-p/246540#M70192</link>
      <description>&lt;P&gt;Are you applying NAT to that traffic?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If the source 192.168.123.123 is not getting the public NAT address of your interface, you won't be able to get a reply. You can test if it's got a NAT match with the CLI test command:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;&amp;gt; test nat-policy-match protocol 6 source 192.168.123.123 destination 8.8.8.8 destination-port 443&lt;/PRE&gt;</description>
      <pubDate>Thu, 17 Jan 2019 22:49:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/cannot-contact-update-server-from-public-ip-address-interface/m-p/246540#M70192</guid>
      <dc:creator>gwesson</dc:creator>
      <dc:date>2019-01-17T22:49:13Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot contact update server from public IP address interface</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/cannot-contact-update-server-from-public-ip-address-interface/m-p/246559#M70196</link>
      <description>&lt;P&gt;Manage to make it work. Require "DNS" and "Palo Alto Networks Services" set to use the outgoing interface. I didn't change "DNS" which was use "Use default" before.&lt;/P&gt;&lt;P&gt;Although I can successfully ping (contact) outside from the outgoing interface. I got another problem now. As my PA device has 2 outgoing interface (to 2 modem). The 1 which success is not my preference. The prefer 1 even cannot ping from outside non ping to outside. But I'm sure internal user can use it to access internet.&lt;/P&gt;</description>
      <pubDate>Fri, 18 Jan 2019 02:58:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/cannot-contact-update-server-from-public-ip-address-interface/m-p/246559#M70196</guid>
      <dc:creator>jeremylo</dc:creator>
      <dc:date>2019-01-18T02:58:17Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot contact update server from public IP address interface</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/cannot-contact-update-server-from-public-ip-address-interface/m-p/246590#M70205</link>
      <description>&lt;P&gt;well done Jezza, perhaps you could mark this as resolved and&amp;nbsp;then log a new post for your new issue.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;please include VR details and default gateways as this will help with diagnostics....&lt;/P&gt;</description>
      <pubDate>Fri, 18 Jan 2019 10:26:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/cannot-contact-update-server-from-public-ip-address-interface/m-p/246590#M70205</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2019-01-18T10:26:33Z</dc:date>
    </item>
  </channel>
</rss>

