<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic pandb-database will not install on Pan_OS 9.0.x in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/pandb-database-will-not-install-on-pan-os-9-0-x/m-p/293105#M77497</link>
    <description>&lt;P&gt;I have a couple of firewalls that are running Pan-OS 9.0.3 that I cannot get the&amp;nbsp;pandb-database to install and update. At least I cannot prove that it is downloading and active. Until 9/30/19, the 9.0 docs for this were the same as the 8.1 docs. According to the new docs, it looks like PANDB is active, but when I check the status on 9.0, it shows a DB version of 0000.00.00.000. Below are the results from the command "show url-cloud status" for my 9.0 and 8.1 firewalls.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;9.0&lt;/P&gt;&lt;P&gt;PAN-DB URL Filtering&lt;BR /&gt;License : valid&lt;BR /&gt;Cloud connection : not connected&lt;BR /&gt;URL database version - device : 0000.00.00.000&lt;BR /&gt;URL protocol version - device : pan/0.0.2&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;8.1&lt;/P&gt;&lt;P&gt;PAN-DB URL Filtering&lt;BR /&gt;License : valid&lt;BR /&gt;Cloud connection : not connected&lt;BR /&gt;URL database version - device : 20190909.20113&lt;BR /&gt;URL protocol version - device : pan/0.0.2&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When I look in monitor for the 8.1 firewall, I can see url-categories. On the 9.0 firewall, the only url-categories I get are "any" and "not-resolved". That is another indicator that is showing that I do not have a url-database.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have tried several things, especially when the 9.0 docs were not up to date, including trying to manually install using "request url-filtering install pandb-database", which fails because there is no image uploaded. But, if you try to download the database using the "request url-filtering download" command, you can no longer specify "request url-filtering download paloaltonetworks region North-America", in 9.0 once you get to download in the command, the only options available (just pressing tab) comes out with "request url-filtering download status vendor brightcloud".&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have the exact same issue on two different 9.0 firewalls, so it does not seem to be something with the firewall, and I have tried this with 9.0.3 and currently with 9.0.3-h3, same results.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Unfortunately, I cannot take the firewalls down to 8.1.x and then run the update/download because we are using GRE tunnels on these firewalls, so that is not a viable option.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 15 Oct 2019 21:53:49 GMT</pubDate>
    <dc:creator>BruceBennett</dc:creator>
    <dc:date>2019-10-15T21:53:49Z</dc:date>
    <item>
      <title>pandb-database will not install on Pan_OS 9.0.x</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pandb-database-will-not-install-on-pan-os-9-0-x/m-p/293105#M77497</link>
      <description>&lt;P&gt;I have a couple of firewalls that are running Pan-OS 9.0.3 that I cannot get the&amp;nbsp;pandb-database to install and update. At least I cannot prove that it is downloading and active. Until 9/30/19, the 9.0 docs for this were the same as the 8.1 docs. According to the new docs, it looks like PANDB is active, but when I check the status on 9.0, it shows a DB version of 0000.00.00.000. Below are the results from the command "show url-cloud status" for my 9.0 and 8.1 firewalls.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;9.0&lt;/P&gt;&lt;P&gt;PAN-DB URL Filtering&lt;BR /&gt;License : valid&lt;BR /&gt;Cloud connection : not connected&lt;BR /&gt;URL database version - device : 0000.00.00.000&lt;BR /&gt;URL protocol version - device : pan/0.0.2&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;8.1&lt;/P&gt;&lt;P&gt;PAN-DB URL Filtering&lt;BR /&gt;License : valid&lt;BR /&gt;Cloud connection : not connected&lt;BR /&gt;URL database version - device : 20190909.20113&lt;BR /&gt;URL protocol version - device : pan/0.0.2&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When I look in monitor for the 8.1 firewall, I can see url-categories. On the 9.0 firewall, the only url-categories I get are "any" and "not-resolved". That is another indicator that is showing that I do not have a url-database.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have tried several things, especially when the 9.0 docs were not up to date, including trying to manually install using "request url-filtering install pandb-database", which fails because there is no image uploaded. But, if you try to download the database using the "request url-filtering download" command, you can no longer specify "request url-filtering download paloaltonetworks region North-America", in 9.0 once you get to download in the command, the only options available (just pressing tab) comes out with "request url-filtering download status vendor brightcloud".&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have the exact same issue on two different 9.0 firewalls, so it does not seem to be something with the firewall, and I have tried this with 9.0.3 and currently with 9.0.3-h3, same results.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Unfortunately, I cannot take the firewalls down to 8.1.x and then run the update/download because we are using GRE tunnels on these firewalls, so that is not a viable option.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 15 Oct 2019 21:53:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pandb-database-will-not-install-on-pan-os-9-0-x/m-p/293105#M77497</guid>
      <dc:creator>BruceBennett</dc:creator>
      <dc:date>2019-10-15T21:53:49Z</dc:date>
    </item>
    <item>
      <title>Re: pandb-database will not install on Pan_OS 9.0.x</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pandb-database-will-not-install-on-pan-os-9-0-x/m-p/295419#M77824</link>
      <description>&lt;P&gt;An update for anyone that looks this up later. This is now solved.&lt;/P&gt;&lt;P&gt;We have a mixed environment that is very restrictive, including SSL intercept. In the system logs, we were seeing "CURL ERROR: SSL certificate problem: self signed certificate in certificate chain". In the CLI we were seeing the following with the "tail follow yes mp-log devsrv.log" command:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;2019-10-29 22:42:03.319 +0000 Warning: pan_cloud_agent_get_curl_connection(pan_cloud_agent_connect.c:2609): cannot elect a cloud&lt;BR /&gt;2019-10-29 22:42:03.319 +0000 curl error: SSL certificate problem: self signed certificate in certificate chain&lt;BR /&gt;2019-10-29 22:42:03.320 +0000 Failed to open connection with the cloud after 12360 consecutive tries.&lt;BR /&gt;2019-10-29 22:42:04.420 +0000 CLOUD_ELECTION: in wait_t 0 secs.&lt;BR /&gt;2019-10-29 22:42:04.544 +0000 Error: verify_cb(pan_ssl_curl_utils.c:614): Error with certificate at depth: 2&lt;BR /&gt;2019-10-29 22:42:04.544 +0000 Error: verify_cb(pan_ssl_curl_utils.c:616): Basic Validation of x509 cert Fail ; Code : 19&lt;/P&gt;&lt;P&gt;...&lt;/P&gt;&lt;P&gt;2019-10-29 22:42:04.544 +0000 Error: verify_cb(pan_ssl_curl_utils.c:625): Failed to validate x509 cert from ctx: (19) self signed certificate in certificate chain&lt;BR /&gt;2019-10-29 22:42:04.544 +0000 Warning: pan_cloud_agent_collect_cloud_info_cb(pan_cloud_agent_connect.c:1957): cloud elect connection close&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I found the available docs were not complete for the changes between 8.x and 9.x PanDB process.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In the end, I found that 8.x and 9.x are using different destinations for updates and since 9.x does not use a seed file, it has to reach the destination to get everything going.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here are the destinations that are being used for both:&lt;/P&gt;&lt;P&gt;8.x PanDB - 65.154.226.123 "dl1prod.urlcloud.paloaltonetworks.com"&lt;BR /&gt;9.x PanDB - 65.154.226.124 "&lt;STRIKE&gt;pandb2qa.urlcloud.paloaltonetworks.com&lt;/STRIKE&gt;" See message from Ldemos below for the proper URL.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In the end, it was the SSL intercept that was keeping the access to&amp;nbsp;pandb2qa.urlcloud.paloaltonetworks.com from working. Once SSL intercept was removed everything started working within the next 10 minutes.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;While you can turn off the "verify update server identity" for updates, this does not appear to be an option with the PanDB access,&amp;nbsp;the certificate chain is verified and will not work with an SSL intercept in the middle.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hopefully I put in enough key words for this to be found if someone else is running into this issue.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 02 Dec 2021 14:45:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pandb-database-will-not-install-on-pan-os-9-0-x/m-p/295419#M77824</guid>
      <dc:creator>BruceBennett</dc:creator>
      <dc:date>2021-12-02T14:45:25Z</dc:date>
    </item>
    <item>
      <title>Re: pandb-database will not install on Pan_OS 9.0.x</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pandb-database-will-not-install-on-pan-os-9-0-x/m-p/450950#M101097</link>
      <description>&lt;P&gt;Please avoid using&amp;nbsp;&lt;SPAN&gt;(pandb2qa.urlcloud.paloaltonetworks.com) for PAN-DB URL Filtering cloud server setting.&amp;nbsp; This server was intended for internal testing.&amp;nbsp;&amp;nbsp;&lt;BR /&gt;Customers should NOT be utilizing this server because it's for internal testing, there will be data consistency problems and uptime problems.&amp;nbsp; The server will also be disabled soon.&amp;nbsp; Please use the universal server [serverlist.urlcloud.paloaltonetworks.com].&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Thank You&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 02 Dec 2021 13:51:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pandb-database-will-not-install-on-pan-os-9-0-x/m-p/450950#M101097</guid>
      <dc:creator>ldemos</dc:creator>
      <dc:date>2021-12-02T13:51:31Z</dc:date>
    </item>
    <item>
      <title>Re: pandb-database will not install on Pan_OS 9.0.x</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pandb-database-will-not-install-on-pan-os-9-0-x/m-p/450964#M101098</link>
      <description>&lt;P&gt;I was able to update the post and it now refers to your post.&lt;/P&gt;</description>
      <pubDate>Thu, 02 Dec 2021 14:46:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pandb-database-will-not-install-on-pan-os-9-0-x/m-p/450964#M101098</guid>
      <dc:creator>BruceBennett</dc:creator>
      <dc:date>2021-12-02T14:46:20Z</dc:date>
    </item>
  </channel>
</rss>

