<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Palo Alto Updates Issue on Multi VSYS system in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-updates-issue-on-multi-vsys-system/m-p/258561#M73320</link>
    <description>&lt;P&gt;the original update server is cloud-based so the IP tends to skip around&lt;/P&gt;
&lt;P&gt;there may be a routing/peering issue with the ip you're trying to reach via your new route&lt;/P&gt;</description>
    <pubDate>Wed, 24 Apr 2019 11:56:57 GMT</pubDate>
    <dc:creator>reaper</dc:creator>
    <dc:date>2019-04-24T11:56:57Z</dc:date>
    <item>
      <title>Palo Alto Updates Issue on Multi VSYS system</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-updates-issue-on-multi-vsys-system/m-p/258510#M73308</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hoping an answer can be provided to this multi vsys Palo Alto I am deploying.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I enabled the operational status of one of the virtual firewalls I am providing making it fully internet facing with Globalprotect operating on the outside interface. This is operating without issue.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When I enabled this VSYS to an operational status I had to make changes to the inside routing to get all the BGP sessions established - it was left in a test state by a predecessor - but this is all working well.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What seems to have happened is the software and dynamic updates have stopped updating. I have checked from CLI and from the MGT interface I have internet connectivity and it is routing via the working VSYS without issue. I have also confirmed that from CLI I can see the MGT interface from the internal and it routes as expected.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I can see the traffic going out to internet but the update times out and the log shows as application incomplete.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have tried to set the update to use the VSYS outside address as the update path through the Service Route Configuration but this produces the same result. In the Service Route Configuration I have the option of Palo Alto Network Services (no Palo Alto Updates option) which I used.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any ideas? The rule and NAT are there and being used, routing seems to be correct. Things like NTP and DNS are not reporting an issue.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Adrian&lt;/P&gt;</description>
      <pubDate>Wed, 24 Apr 2019 08:51:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-updates-issue-on-multi-vsys-system/m-p/258510#M73308</guid>
      <dc:creator>a.jones</dc:creator>
      <dc:date>2019-04-24T08:51:08Z</dc:date>
    </item>
    <item>
      <title>Re: Palo Alto Updates Issue on Multi VSYS system</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-updates-issue-on-multi-vsys-system/m-p/258518#M73315</link>
      <description>&lt;P&gt;Do you have "Verify Update Server Identity" enabled and are you doing ssldecrypt?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;you could try replacing the updates server with &lt;A href="https://na01.safelinks.protection.outlook.com/?url=http%3A%2F%2Fstaticupdates.paloaltonetworks.com%2F&amp;amp;data=02%7C01%7Cfarzana.mustafa%40arrow.com%7C8b9c9d3efc994bd5dedb08d62fbbdc4e%7C0beb0c359cbb4feb99e5589e415c7944%7C1%7C0%7C636748881236125237&amp;amp;sdata=vu4nqjde8WDG4YhCiyigezaV9tqLrAjZObz6TaZzWr4%3D&amp;amp;reserved=0" target="_blank" rel="nofollow noopener noreferrer"&gt;staticupdates.paloaltonetworks.com&lt;/A&gt; in case you're having issues connecting to the cloud instance&lt;/P&gt;</description>
      <pubDate>Wed, 24 Apr 2019 10:10:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-updates-issue-on-multi-vsys-system/m-p/258518#M73315</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2019-04-24T10:10:33Z</dc:date>
    </item>
    <item>
      <title>Re: Palo Alto Updates Issue on Multi VSYS system</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-updates-issue-on-multi-vsys-system/m-p/258520#M73317</link>
      <description>&lt;P&gt;I have verify Update Server Identity and currently not doing ssldecrypt.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Strangely, staticupdates.paloaltonetworks.com works. Any idea why the original would stop after making the new Vsys live? It originally went through a test Vsys and route before I made the change but this was 2 weeks ago.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Adrian&lt;/P&gt;</description>
      <pubDate>Wed, 24 Apr 2019 10:19:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-updates-issue-on-multi-vsys-system/m-p/258520#M73317</guid>
      <dc:creator>a.jones</dc:creator>
      <dc:date>2019-04-24T10:19:46Z</dc:date>
    </item>
    <item>
      <title>Re: Palo Alto Updates Issue on Multi VSYS system</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-updates-issue-on-multi-vsys-system/m-p/258561#M73320</link>
      <description>&lt;P&gt;the original update server is cloud-based so the IP tends to skip around&lt;/P&gt;
&lt;P&gt;there may be a routing/peering issue with the ip you're trying to reach via your new route&lt;/P&gt;</description>
      <pubDate>Wed, 24 Apr 2019 11:56:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-updates-issue-on-multi-vsys-system/m-p/258561#M73320</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2019-04-24T11:56:57Z</dc:date>
    </item>
    <item>
      <title>Re: Palo Alto Updates Issue on Multi VSYS system</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-updates-issue-on-multi-vsys-system/m-p/258623#M73334</link>
      <description>&lt;P&gt;Thanks. I have escalated to our support people. All internet traffic works except to these particluar cloud servers. Hopefully they can help.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Adrian&lt;/P&gt;</description>
      <pubDate>Wed, 24 Apr 2019 14:29:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-updates-issue-on-multi-vsys-system/m-p/258623#M73334</guid>
      <dc:creator>a.jones</dc:creator>
      <dc:date>2019-04-24T14:29:22Z</dc:date>
    </item>
  </channel>
</rss>

