<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: [BUG?] EDL using wrong Service Route in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/bug-edl-using-wrong-service-route/m-p/290322#M77108</link>
    <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/70618"&gt;@husetech&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As workaround you can try to set service route based on destination:&lt;/P&gt;&lt;P&gt;- Revert EDL and URL filtering service route to default&lt;/P&gt;&lt;P&gt;- In Setup &amp;gt; Services &amp;gt; Service route &amp;gt; Destination put the ip address of the server that you are using in your EDL and select the desired interface&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It is important that the service route for the service (EDL, URL filtering etc) to be set on default in order for the destination service route to work.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 27 Sep 2019 14:29:06 GMT</pubDate>
    <dc:creator>aleksandar.astardzhiev</dc:creator>
    <dc:date>2019-09-27T14:29:06Z</dc:date>
    <item>
      <title>[BUG] EDL using wrong Service Route</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/bug-edl-using-wrong-service-route/m-p/290276#M77099</link>
      <description>&lt;P&gt;Hello everybody!&lt;/P&gt;&lt;P&gt;PAN OS build&amp;nbsp;&lt;STRONG&gt;9.0.3-h3.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;According to the PAN documentation the "External Dynamic Lists" (Object-&amp;gt; External Dynamic Lists) )are supposed to use "External Dynamic Lists Service Route" (Device-&amp;gt; Setup -&amp;gt; Services -&amp;gt; 'Service Route Configuration').&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="PA_ServiceRoute_EDL.PNG" style="width: 642px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/21567i599ED686327D8E51/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="PA_ServiceRoute_EDL.PNG" alt="PA_ServiceRoute_EDL.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This doen't seem to be the case since any changes in that area have no effect for EDL.&lt;/P&gt;&lt;P&gt;It seems that 'URLS Updates' Service Route is responsible for any entry withing an EDL.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="PA_ServiceRoute_URL_Updates.PNG" style="width: 647px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/21568i189D1067C310FDBD/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="PA_ServiceRoute_URL_Updates.PNG" alt="PA_ServiceRoute_URL_Updates.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Changing that specific Route does fix our problem but breaks the native PAN melicoious/high risk/ bulletproof IP fetching system. Which is not the way to go.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="PA_ExternalListsO365.PNG" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/21569i04D20F0D2FFF1BEC/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="PA_ExternalListsO365.PNG" alt="PA_ExternalListsO365.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Our EDL needs to access an internal only host. Keeping the default settings, it tries to use an external route to access the specific host. We need to change the Route to use the internal interface but without breaking the native PAN Dynamic IP Lists.&lt;/P&gt;</description>
      <pubDate>Fri, 27 Sep 2019 12:35:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/bug-edl-using-wrong-service-route/m-p/290276#M77099</guid>
      <dc:creator>husetech</dc:creator>
      <dc:date>2019-09-27T12:35:10Z</dc:date>
    </item>
    <item>
      <title>Re: [BUG] EDL using wrong Service Route</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/bug-edl-using-wrong-service-route/m-p/290293#M77103</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/70618"&gt;@husetech&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Was this bug confirmed by TAC ?&lt;/P&gt;
&lt;P&gt;Can you confirm the PAN-OS version you're currently running ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Cheers !&lt;/P&gt;
&lt;P&gt;-Kiwi.&lt;/P&gt;
&lt;DIV id="ConnectiveDocSignExtentionInstalled" data-extension-version="1.0.4"&gt;&amp;nbsp;&lt;/DIV&gt;</description>
      <pubDate>Fri, 27 Sep 2019 11:05:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/bug-edl-using-wrong-service-route/m-p/290293#M77103</guid>
      <dc:creator>kiwi</dc:creator>
      <dc:date>2019-09-27T11:05:39Z</dc:date>
    </item>
    <item>
      <title>Re: [BUG?] EDL using wrong Service Route</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/bug-edl-using-wrong-service-route/m-p/290295#M77104</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/11943"&gt;@kiwi&lt;/a&gt;,,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;no TAC has not approved this issue as BUG. I have not yet contacted TAC, What is TAC?&lt;/P&gt;&lt;P&gt;And I am very sorry to not have mentioned the version we are using.&lt;/P&gt;&lt;P&gt;We are using the latest PAN OS build&amp;nbsp;&lt;STRONG&gt;9.0.3-h3.&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 27 Sep 2019 12:36:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/bug-edl-using-wrong-service-route/m-p/290295#M77104</guid>
      <dc:creator>husetech</dc:creator>
      <dc:date>2019-09-27T12:36:17Z</dc:date>
    </item>
    <item>
      <title>Re: [BUG?] EDL using wrong Service Route</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/bug-edl-using-wrong-service-route/m-p/290322#M77108</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/70618"&gt;@husetech&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As workaround you can try to set service route based on destination:&lt;/P&gt;&lt;P&gt;- Revert EDL and URL filtering service route to default&lt;/P&gt;&lt;P&gt;- In Setup &amp;gt; Services &amp;gt; Service route &amp;gt; Destination put the ip address of the server that you are using in your EDL and select the desired interface&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It is important that the service route for the service (EDL, URL filtering etc) to be set on default in order for the destination service route to work.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 27 Sep 2019 14:29:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/bug-edl-using-wrong-service-route/m-p/290322#M77108</guid>
      <dc:creator>aleksandar.astardzhiev</dc:creator>
      <dc:date>2019-09-27T14:29:06Z</dc:date>
    </item>
    <item>
      <title>Re: [BUG?] EDL using wrong Service Route</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/bug-edl-using-wrong-service-route/m-p/290544#M77139</link>
      <description>&lt;P&gt;Worked perfectly, thank you!&lt;/P&gt;&lt;P&gt;So I guess it's not a bug after all but intendet to work like this..&lt;/P&gt;&lt;P&gt;Appriciate the help.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Best regards&lt;/P&gt;&lt;P&gt;husetech&lt;/P&gt;</description>
      <pubDate>Mon, 30 Sep 2019 07:02:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/bug-edl-using-wrong-service-route/m-p/290544#M77139</guid>
      <dc:creator>husetech</dc:creator>
      <dc:date>2019-09-30T07:02:43Z</dc:date>
    </item>
    <item>
      <title>Re: [BUG?] EDL using wrong Service Route</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/bug-edl-using-wrong-service-route/m-p/291404#M77272</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/70618"&gt;@husetech&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Well it still sounds like a bug for me. It doesn't make sense to have separate service route for EDL if it using the URL filtering route.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Me personally prefer to define any service route using the destination tab. It is bit more flexible - for example when you define two different LDAP servers reachable via different interfaces&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 04 Oct 2019 14:46:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/bug-edl-using-wrong-service-route/m-p/291404#M77272</guid>
      <dc:creator>aleksandar.astardzhiev</dc:creator>
      <dc:date>2019-10-04T14:46:02Z</dc:date>
    </item>
  </channel>
</rss>

