<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: DynDNS client on PANOS 9.0 in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/dyndns-client-on-panos-9-0/m-p/301495#M78677</link>
    <description>&lt;P&gt;Thanks a lot &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/97537"&gt;@MichaelJay&lt;/a&gt; you saved me a huge headaches on my no-ip dyndns situation... I was about to throw my Palo by the windows. Now need to understand why my GP portal wont pop up ... if you have any insight would be nice&lt;/P&gt;</description>
    <pubDate>Sat, 30 Nov 2019 15:55:19 GMT</pubDate>
    <dc:creator>Vincent-Satori</dc:creator>
    <dc:date>2019-11-30T15:55:19Z</dc:date>
    <item>
      <title>DynDNS client on PANOS 9.0</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dyndns-client-on-panos-9-0/m-p/252050#M71668</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm trying to setup DynDNS based on the instructions found at&amp;nbsp;&lt;A href="https://docs.paloaltonetworks.com/pan-os/9-0/pan-os-admin/networking/configure-dynamic-dns-for-firewall-interfaces.html" target="_blank"&gt;https://docs.paloaltonetworks.com/pan-os/9-0/pan-os-admin/networking/configure-dynamic-dns-for-firewall-interfaces.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm using DuckDNS, but I'm stuck at the 'certificate profile' portion.&amp;nbsp; As I understand it correctly I have to import the (public) SSL certificate of DuckDNS, but this is not provided by them.&lt;/P&gt;&lt;P&gt;I don't understand why this is needed since their certificate is signed by Starfield CA, which is already in the list of 'Default Trusted Certificate Authorities' on the Paloalto firewall.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also other DynDNS provides such as DYN don't seem to provide their public certificates for download.&lt;/P&gt;</description>
      <pubDate>Sun, 03 Mar 2019 09:37:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dyndns-client-on-panos-9-0/m-p/252050#M71668</guid>
      <dc:creator>StevenEerdekens</dc:creator>
      <dc:date>2019-03-03T09:37:23Z</dc:date>
    </item>
    <item>
      <title>Re: DynDNS client on PANOS 9.0</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dyndns-client-on-panos-9-0/m-p/252087#M71673</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/14255"&gt;@StevenEerdekens&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The public cert is always public available. It is send in every tls connection that you establish to duckDNS. In your browser you can see the cert also when you check the tls certificate of the website.&lt;/P&gt;&lt;P&gt;The duckDNS cert is this one here:&lt;/P&gt;&lt;PRE&gt;-----BEGIN CERTIFICATE-----&lt;BR /&gt;MIIGYDCCBUigAwIBAgIJAOL5nH5b/py2MA0GCSqGSIb3DQEBCwUAMIHGMQswCQYDVQQGEwJVUzEQ&lt;BR /&gt;MA4GA1UECBMHQXJpem9uYTETMBEGA1UEBxMKU2NvdHRzZGFsZTElMCMGA1UEChMcU3RhcmZpZWxk&lt;BR /&gt;IFRlY2hub2xvZ2llcywgSW5jLjEzMDEGA1UECxMqaHR0cDovL2NlcnRzLnN0YXJmaWVsZHRlY2gu&lt;BR /&gt;Y29tL3JlcG9zaXRvcnkvMTQwMgYDVQQDEytTdGFyZmllbGQgU2VjdXJlIENlcnRpZmljYXRlIEF1&lt;BR /&gt;dGhvcml0eSAtIEcyMB4XDTE4MDUwOTEzNTIxMloXDTE5MDcwODEyNDYwMFowOTEhMB8GA1UECxMY&lt;BR /&gt;RG9tYWluIENvbnRyb2wgVmFsaWRhdGVkMRQwEgYDVQQDEwtkdWNrZG5zLm9yZzCCASIwDQYJKoZI&lt;BR /&gt;hvcNAQEBBQADggEPADCCAQoCggEBAK0nsIS1nfeEHQUaax+kNhAA0bZSQ/xCidcm5Xfbj099EUca&lt;BR /&gt;NbdhdcRHIh9oLa4Sna68Rsfzeyl/sQ5MECjg3dmJ7TvcEXyfEbx2/EAhrMMcisiNIWraGGoA2b24&lt;BR /&gt;3y4MMEMy7MAQaMK2FLfele9+Qq4BMIhmo9xfYd7I7QITtBoHufFfuTwq12uUO687kNWHh8dHa7eL&lt;BR /&gt;REeAgiZaaKfRP5PccfSwZT/LNgHNsk0SjwTVjIChIeWLH4q4wVmSR1NWL5nGsEyLDx0EiB4yDQyI&lt;BR /&gt;FfBCyCW2tm6cVdIsNlr1WCGcQPbg4CGJSRqkEIqtR2WTrJiZm2/HH2YzzoiPYBHqMtkCAwEAAaOC&lt;BR /&gt;AtswggLXMAwGA1UdEwEB/wQCMAAwHQYDVR0lBBYwFAYIKwYBBQUHAwEGCCsGAQUFBwMCMA4GA1Ud&lt;BR /&gt;DwEB/wQEAwIFoDA9BgNVHR8ENjA0MDKgMKAuhixodHRwOi8vY3JsLnN0YXJmaWVsZHRlY2guY29t&lt;BR /&gt;L3NmaWcyczEtMTAxLmNybDBjBgNVHSAEXDBaME4GC2CGSAGG/W4BBxcBMD8wPQYIKwYBBQUHAgEW&lt;BR /&gt;MWh0dHA6Ly9jZXJ0aWZpY2F0ZXMuc3RhcmZpZWxkdGVjaC5jb20vcmVwb3NpdG9yeS8wCAYGZ4EM&lt;BR /&gt;AQIBMIGCBggrBgEFBQcBAQR2MHQwKgYIKwYBBQUHMAGGHmh0dHA6Ly9vY3NwLnN0YXJmaWVsZHRl&lt;BR /&gt;Y2guY29tLzBGBggrBgEFBQcwAoY6aHR0cDovL2NlcnRpZmljYXRlcy5zdGFyZmllbGR0ZWNoLmNv&lt;BR /&gt;bS9yZXBvc2l0b3J5L3NmaWcyLmNydDAfBgNVHSMEGDAWgBQlRYFoUCY4PTstLL7Natm2PbNmYzAn&lt;BR /&gt;BgNVHREEIDAeggtkdWNrZG5zLm9yZ4IPd3d3LmR1Y2tkbnMub3JnMB0GA1UdDgQWBBSfTZVAxuqj&lt;BR /&gt;POjYBMnfDcDzAlhJ2DCCAQQGCisGAQQB1nkCBAIEgfUEgfIA8AB1AKS5CZC0GFgUh7sTosxncAo8&lt;BR /&gt;NZgE+RvfuON3zQ7IDdwQAAABY0UtY2cAAAQDAEYwRAIgbZbBehTwoYb3LSH0lQNU7kSXM3UON+WT&lt;BR /&gt;oJYfI7V4c18CIC2NhgKEtd2n+e+DbFmT7Z0VlUAo4MxuJatcpbAa1nX2AHcAdH7agzGtMxCRIZzO&lt;BR /&gt;JU9CcMK//V5CIAjGNzV55hB7zFYAAAFjRS1kVAAABAMASDBGAiEA6MmBRVoeb1P4r5rxvteyZ6fn&lt;BR /&gt;fWMyZmjiwJCpBVT6tEcCIQDgdzI63ntwUh6YNoQsEXAih9v4702plBTk5RymCDM4pjANBgkqhkiG&lt;BR /&gt;9w0BAQsFAAOCAQEA2engR6oxMC5KxSYoivchGCsvO956hG6VMe70uaavddgvNYtg6hdkf1JUrSmg&lt;BR /&gt;t4EURspzaMuNwq9diN9PQHsQyuS1NGqKlJKWqy/CkYfk4BuwL2P0GP/fhwHbFslk9Ebdb3O7+Zrt&lt;BR /&gt;tbjSVWoxsI+UgD0UfGUEy+5wOnA443QUl9G8lUNZdXdKdBd7s831205nc82KLy8tNuLh3PvXQJff&lt;BR /&gt;IBqHBbJWnHcxz0MJIWoLx7iDhBYEkQ/qRH5m2uvDDybwICDgd/eY3RuCxt/yZE2Fbj6MZbY+hjOd&lt;BR /&gt;57k/kPcAEmUHD8y0i7z3W447+H0gp8IAvkE7u5jB9lNv2PTW5UO5KQ==&lt;BR /&gt;-----END CERTIFICATE----- &lt;/PRE&gt;&lt;P&gt;But for the cert profile you should use the intermediate cert which signed the duckdns cert.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope this helps.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Remo&lt;/P&gt;</description>
      <pubDate>Sun, 03 Mar 2019 21:02:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dyndns-client-on-panos-9-0/m-p/252087#M71673</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2019-03-03T21:02:46Z</dc:date>
    </item>
    <item>
      <title>Re: DynDNS client on PANOS 9.0</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dyndns-client-on-panos-9-0/m-p/252092#M71675</link>
      <description>&lt;P&gt;Hi Remo,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The Duckdns.org cert is signed by Starfield Secure CA GW, so I tried to import the Root G2 and intermediate G2 certificate found on&amp;nbsp;&lt;A href="http://certs.starfieldtech.com/repository/" target="_blank" rel="noopener"&gt;http://certs.starfieldtech.com/repository/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2019-03-03 at 23.05.03.png" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/18938iDAC3EB31EF827C1D/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Screenshot 2019-03-03 at 23.05.03.png" alt="Screenshot 2019-03-03 at 23.05.03.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2019-03-03 at 22.58.34.png" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/18936i9E5E78E3958A34E1/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Screenshot 2019-03-03 at 22.58.34.png" alt="Screenshot 2019-03-03 at 22.58.34.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2019-03-03 at 22.58.44.png" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/18937i1609526691A2BA75/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Screenshot 2019-03-03 at 22.58.44.png" alt="Screenshot 2019-03-03 at 22.58.44.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But I still see the following error in the system log when filtering ddns type entries:&amp;nbsp;Server response: 'Peer certificate cannot be authenticated with given CA certificates'&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any clue?&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Sun, 03 Mar 2019 22:05:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dyndns-client-on-panos-9-0/m-p/252092#M71675</guid>
      <dc:creator>StevenEerdekens</dc:creator>
      <dc:date>2019-03-03T22:05:52Z</dc:date>
    </item>
    <item>
      <title>Re: DynDNS client on PANOS 9.0</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dyndns-client-on-panos-9-0/m-p/252187#M71702</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Install the highest certificate in the chain.&lt;/P&gt;&lt;P&gt;The Starfield Root Certificate.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;See if that helps.&lt;/P&gt;</description>
      <pubDate>Mon, 04 Mar 2019 17:28:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dyndns-client-on-panos-9-0/m-p/252187#M71702</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2019-03-04T17:28:57Z</dc:date>
    </item>
    <item>
      <title>Re: DynDNS client on PANOS 9.0</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dyndns-client-on-panos-9-0/m-p/252314#M71731</link>
      <description>&lt;P&gt;I've got it running now.&lt;/P&gt;&lt;P&gt;The root certificate was already installed, but I had to import a different intermediate bundle:&amp;nbsp;&lt;A href="https://ssl-ccp.secureserver.net/repository/sf_bundle-g2-g1.crt" target="_blank" rel="noopener"&gt;https://ssl-ccp.secureserver.net/repository/sf_bundle-g2-g1.crt&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;BR /&gt;Steven&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2019-03-05 at 14.35.00.png" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/18954iA0771A414086AB60/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Screenshot 2019-03-05 at 14.35.00.png" alt="Screenshot 2019-03-05 at 14.35.00.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2019-03-05 at 14.35.21.png" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/18955i8BDC77E4929584D9/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Screenshot 2019-03-05 at 14.35.21.png" alt="Screenshot 2019-03-05 at 14.35.21.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2019-03-05 at 14.39.40.png" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/18957i02A8A8E775B6FC44/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Screenshot 2019-03-05 at 14.39.40.png" alt="Screenshot 2019-03-05 at 14.39.40.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 05 Mar 2019 13:40:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dyndns-client-on-panos-9-0/m-p/252314#M71731</guid>
      <dc:creator>StevenEerdekens</dc:creator>
      <dc:date>2019-03-05T13:40:03Z</dc:date>
    </item>
    <item>
      <title>Re: DynDNS client on PANOS 9.0</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dyndns-client-on-panos-9-0/m-p/284878#M76361</link>
      <description>&lt;P&gt;I've been having the same issue with DuckDNS DDNS via the Palo Alto and finally got it to work after what seems like hours of downloading certificates from Starfield and trying different combinations... as this was the only post I've been able to find with anything relevant I thought I would add what finally worked for me.&lt;/P&gt;&lt;P&gt;I tried multiple different combinations of intermediate certificates and adjusting other settings.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What finally worked was using Firefox, going to &lt;A href="http://www.duckdns.org" target="_blank" rel="noopener"&gt;www.duckdns.org&lt;/A&gt;, opening the SSL certificate properties and exporting the root certificate and each of the intermediate certificates down the chain in order (I numbered the three of them for simplicity.)&amp;nbsp; I then cleared out other test certificates, imported them in order one by one setting the very top one as a Trusted root CA - but not setting any of the intermediates as trusted root CAs and I did not import the DuckDNS certificate itself.&amp;nbsp; I then created a new Certificate Profile and added each of the certificates to the profile in order, set the Certificate Profile that I created in the dynamic DNS profile and saved it.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Low and behold a test "dns-proxy ddns update interface name vlan" in the CLI finally worked, when I checked the logs under Monitor -&amp;gt; Logs -&amp;gt; System -&amp;gt; ( subtype eq ddns )&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For reference, the Advanced -&amp;gt; DDNS -&amp;gt; Hostname entry was set as the DDNS hostname *without* the .duckdns.org appended.&amp;nbsp; API Host at &lt;A href="http://www.duckdns.org" target="_blank" rel="noopener"&gt;www.duckdns.org&lt;/A&gt;, Base URI at /update, Secret Token pasted in with no spaces or other characters (generally the default DuckDNS v1 settings with my own private key.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hopefully that saves someone some of the same headaches - seems strange that these aren't trusted by default with OEM provided Certificate Profiles for each service in the OEM provided DDNS profiles.&lt;/P&gt;</description>
      <pubDate>Sat, 24 Aug 2019 04:43:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dyndns-client-on-panos-9-0/m-p/284878#M76361</guid>
      <dc:creator>MichaelJay</dc:creator>
      <dc:date>2019-08-24T04:43:11Z</dc:date>
    </item>
    <item>
      <title>Re: DynDNS client on PANOS 9.0</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dyndns-client-on-panos-9-0/m-p/301495#M78677</link>
      <description>&lt;P&gt;Thanks a lot &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/97537"&gt;@MichaelJay&lt;/a&gt; you saved me a huge headaches on my no-ip dyndns situation... I was about to throw my Palo by the windows. Now need to understand why my GP portal wont pop up ... if you have any insight would be nice&lt;/P&gt;</description>
      <pubDate>Sat, 30 Nov 2019 15:55:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dyndns-client-on-panos-9-0/m-p/301495#M78677</guid>
      <dc:creator>Vincent-Satori</dc:creator>
      <dc:date>2019-11-30T15:55:19Z</dc:date>
    </item>
    <item>
      <title>Re: DynDNS client on PANOS 9.0</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dyndns-client-on-panos-9-0/m-p/301913#M78736</link>
      <description>&lt;P&gt;Vincent, very glad to hear that it worked, I wasted way too many hours trying assorted settings!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As far as the GP portal popup, I would probably suggest opening a new conversation on topic and giving a lot more detail on what you're having trouble with.&amp;nbsp; I'm not sure what you mean exactly... As far as the GP VPN client which connects to the portal and then the gateway to establish the VPN, we had to make sure a single certificate was issued to each machine from our CA and trusted by the Palo, and remove all duplicate certificates from the clients.&amp;nbsp; There is a setting to enable prompting for authentication, if it's disabled it won't pop-up an authentication request and will only try to do single sign-on authentication.&amp;nbsp; For SSO you need to make sure that you are signing in to the workstation with the GP "credential provider" in windows (should be a globe icon under "more options" before you login, and only shows up after GP is installed.)&amp;nbsp; We also had issues with pre-logon split tunnel settings not refreshing to per user split tunnels - so had to duplicate the settings to make it work.&amp;nbsp; This was a fairly involved setup with a lot of moving parts and multiple TAC calls to iron things out.&amp;nbsp; If you mean some other aspect, I don't have any tips off hand.&amp;nbsp; Hopefully you get it figured out easily.&lt;/P&gt;</description>
      <pubDate>Tue, 03 Dec 2019 17:17:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dyndns-client-on-panos-9-0/m-p/301913#M78736</guid>
      <dc:creator>MichaelJay</dc:creator>
      <dc:date>2019-12-03T17:17:04Z</dc:date>
    </item>
    <item>
      <title>Re: DynDNS client on PANOS 9.0</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dyndns-client-on-panos-9-0/m-p/304983#M79261</link>
      <description>&lt;P&gt;Weird, i believe i did the same exact thing but it is still not working for me. Do you mind taking some screen shots of certificates and certificate profile?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 26 Dec 2019 21:19:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dyndns-client-on-panos-9-0/m-p/304983#M79261</guid>
      <dc:creator>XaiVang</dc:creator>
      <dc:date>2019-12-26T21:19:29Z</dc:date>
    </item>
    <item>
      <title>Re: DynDNS client on PANOS 9.0</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dyndns-client-on-panos-9-0/m-p/305041#M79267</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/54351"&gt;@XaiVang&lt;/a&gt;, here you are&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="certs.jpg" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/23246iD0C7DE8463B6D1C5/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="certs.jpg" alt="certs.jpg" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="duckdns.jpg" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/23244iE338354E44A67693/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="duckdns.jpg" alt="duckdns.jpg" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2019-12-27 at 09.53.07.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/23245iEB7381BBAD701369/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Screenshot 2019-12-27 at 09.53.07.png" alt="Screenshot 2019-12-27 at 09.53.07.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 27 Dec 2019 08:59:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dyndns-client-on-panos-9-0/m-p/305041#M79267</guid>
      <dc:creator>StevenEerdekens</dc:creator>
      <dc:date>2019-12-27T08:59:36Z</dc:date>
    </item>
    <item>
      <title>Re: DynDNS client on PANOS 9.0</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dyndns-client-on-panos-9-0/m-p/305517#M79391</link>
      <description>&lt;P&gt;Thank you&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/14255"&gt;@StevenEerdekens&lt;/a&gt;!!! Worked like a charm!!! Appreciate your help!&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 03 Jan 2020 03:10:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dyndns-client-on-panos-9-0/m-p/305517#M79391</guid>
      <dc:creator>XaiVang</dc:creator>
      <dc:date>2020-01-03T03:10:48Z</dc:date>
    </item>
    <item>
      <title>Re: DynDNS client on PANOS 9.0</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dyndns-client-on-panos-9-0/m-p/305528#M79394</link>
      <description>&lt;P&gt;Glad to hear!&lt;/P&gt;</description>
      <pubDate>Fri, 03 Jan 2020 09:40:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dyndns-client-on-panos-9-0/m-p/305528#M79394</guid>
      <dc:creator>StevenEerdekens</dc:creator>
      <dc:date>2020-01-03T09:40:08Z</dc:date>
    </item>
    <item>
      <title>Re: DynDNS client on PANOS 9.0</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dyndns-client-on-panos-9-0/m-p/305626#M79428</link>
      <description>&lt;P&gt;Steven,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you very much for taking the time to post this. I feel like the biiggest "rock" in the world right now. I have been trying for two days to download the right files to get this to work. I thought I had them, but it continues to fail according to system logs. Is there any chance you could export the files that worked for you and let me know what order you have listed in the profile? I would be more then greatful and would add you to next years christmas card list &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt; Seriously, and help would be much appreciated. Thanks, Rick&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screen Shot 2020-01-03 at 4.37.40 PM.png" style="width: 998px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/23304i9C5267F7E4748B0D/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Screen Shot 2020-01-03 at 4.37.40 PM.png" alt="Screen Shot 2020-01-03 at 4.37.40 PM.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screen Shot 2020-01-03 at 4.38.25 PM.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/23305i535CB791CCD97C6B/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Screen Shot 2020-01-03 at 4.38.25 PM.png" alt="Screen Shot 2020-01-03 at 4.38.25 PM.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screen Shot 2020-01-03 at 4.39.49 PM.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/23307i343AC652D2D784E1/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Screen Shot 2020-01-03 at 4.39.49 PM.png" alt="Screen Shot 2020-01-03 at 4.39.49 PM.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 03 Jan 2020 21:44:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dyndns-client-on-panos-9-0/m-p/305626#M79428</guid>
      <dc:creator>Rick_Lowery</dc:creator>
      <dc:date>2020-01-03T21:44:24Z</dc:date>
    </item>
    <item>
      <title>Re: DynDNS client on PANOS 9.0</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dyndns-client-on-panos-9-0/m-p/305684#M79447</link>
      <description>&lt;P&gt;I have been working this for days. I'm thinking it is something else. Can anyone please tell me why I would get a Timeout message? Could it be policy related?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;( description contains 'Interface ethernet1/1 DDNS update to DuckDNS v1 unsuccessful for host mybighost with 108.10.11.34 Server response: Timeout was reached' )&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;*Note I changed host and IP for privacy purposes.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 05 Jan 2020 19:31:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dyndns-client-on-panos-9-0/m-p/305684#M79447</guid>
      <dc:creator>Rick_Lowery</dc:creator>
      <dc:date>2020-01-05T19:31:41Z</dc:date>
    </item>
    <item>
      <title>Re: DynDNS client on PANOS 9.0</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dyndns-client-on-panos-9-0/m-p/305695#M79454</link>
      <description>&lt;P&gt;Figured it out. I had to change the service route configuration under /Device/Services/ServiceRouteConfiguration so the traffic would go out the WAN and not the default MGMNT interface.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 05 Jan 2020 21:16:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dyndns-client-on-panos-9-0/m-p/305695#M79454</guid>
      <dc:creator>Rick_Lowery</dc:creator>
      <dc:date>2020-01-05T21:16:33Z</dc:date>
    </item>
    <item>
      <title>Re: DynDNS client on PANOS 9.0</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dyndns-client-on-panos-9-0/m-p/329943#M83698</link>
      <description>&lt;P&gt;Hey Rick.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I've been having a similar problem for while. I solved it by making the URL filtering categories of 'high-risk' and 'dynamic-dns' to alert or allow. Then I imported the certificates I got from a packet capture to that IP. Those certificates were different than what Firefox provided me with. You can find them here:&lt;/P&gt;&lt;P&gt;&lt;A href="https://ssl-ccp.secureserver.net/repository/sf-class2-root.crt" target="_self"&gt;Starfield Class 2 Certification Authority Root Certificate&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://ssl-ccp.secureserver.net/repository/sfroot-g2_cross.crt" target="_self"&gt;Starfield Secure Server Certificate (Cross Intermediate Certificate)&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://ssl-ccp.secureserver.net/repository/sfig2.crt.pem" target="_self"&gt;Starfield Secure Server Certificate (Intermediate Certificate) - G2&lt;/A&gt;&lt;/P&gt;&lt;P&gt;and finally DuckDNS's &lt;A target="_self"&gt;certificate&lt;/A&gt; (note: you will need to save that as a .pem file)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Then I selected all three Starfield certificates in my certificate profile&lt;/P&gt;&lt;P&gt;After commiting I went to the CLI and ran these commands:&lt;/P&gt;&lt;P&gt;test dns-proxy ddns update interface name ethernet1/1&lt;/P&gt;&lt;P&gt;show dns-proxy ddns interface name ethernet1/1&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The return code was good.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope this helps&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 26 May 2020 20:32:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dyndns-client-on-panos-9-0/m-p/329943#M83698</guid>
      <dc:creator>MPipes</dc:creator>
      <dc:date>2020-05-26T20:32:35Z</dc:date>
    </item>
    <item>
      <title>Re: DynDNS client on PANOS 9.0</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dyndns-client-on-panos-9-0/m-p/389190#M90603</link>
      <description>&lt;P&gt;I tried all of the recommendations that were described here. None of them worked. I am currently with a setup and recommendation from MPipes and ddns is not working with DuckDNS service.&amp;nbsp;&lt;/P&gt;&lt;P&gt;error i am getting:&amp;nbsp;&amp;nbsp; 'Interface vlan.10 DDNS registration to DuckDNS v1 unsuccessful for host #####.duckdns.org with 10.xx.xx.4 Server response: Couldn\'t connect to server'&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Certificates imported:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="certs.JPG" style="width: 815px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/30193iF9C8EDDCE09C0808/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="certs.JPG" alt="certs.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Certificate profile setup:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="cert-profile.JPG" style="width: 693px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/30194i0A33F39727732675/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="cert-profile.JPG" alt="cert-profile.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;in my setup I am using vlan that has internet access and setup is as following:&lt;/P&gt;&lt;P&gt;vlan.10 == PA220 == eth1/1 == NAT router = ISP&amp;nbsp; (no security profiles are used in security policy allowing traffic to internet)&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="vlan.JPG" style="width: 962px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/30195iAA0F355E8E3E308D/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="vlan.JPG" alt="vlan.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Anyone with an idea what to do, what to troubleshoot?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I tried all of the previous recommendations and combinations with certificates and i am out of ideas. Any help more than welcome.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 04 Mar 2021 20:44:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dyndns-client-on-panos-9-0/m-p/389190#M90603</guid>
      <dc:creator>RBecirovic</dc:creator>
      <dc:date>2021-03-04T20:44:25Z</dc:date>
    </item>
    <item>
      <title>Re: DynDNS client on PANOS 9.0</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dyndns-client-on-panos-9-0/m-p/389520#M90629</link>
      <description>&lt;P&gt;Make sure you imported the certificates as Trusted Root CA Certificates. I also imported DuckDNS's certificate&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screen Shot 2021-03-05 at 22.47.11.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/30216i0DA82FA15F86D14C/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Screen Shot 2021-03-05 at 22.47.11.png" alt="Screen Shot 2021-03-05 at 22.47.11.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 06 Mar 2021 03:49:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dyndns-client-on-panos-9-0/m-p/389520#M90629</guid>
      <dc:creator>MPipes</dc:creator>
      <dc:date>2021-03-06T03:49:20Z</dc:date>
    </item>
    <item>
      <title>Re: DynDNS client on PANOS 9.0</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dyndns-client-on-panos-9-0/m-p/389695#M90642</link>
      <description>&lt;P&gt;updated certificates as Trusted CA and imported DuckDNS cert too.&amp;nbsp;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="installed-cert.JPG" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/30221i535299DDC8436506/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="installed-cert.JPG" alt="installed-cert.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;DuckDNS cert cannot be imported under cert profile since it is not a&amp;nbsp; CA certificate.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am still getting the same error: "Interface vlan.10 DDNS registration to DuckDNS v1 unsuccessful for host ####.duckdns.org with 10.XX.XX.4 Server response: Couldn't connect to server."&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Systemlog.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/30222i8100F803F546A35C/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Systemlog.png" alt="Systemlog.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;after i checked the traffic logs and url logs, whenever i run the "test dns-proxy ddns update interface name vlan.10"&lt;/P&gt;&lt;P&gt;it only generates logs under system logs, no traffic logs for the source.&amp;nbsp;&lt;/P&gt;&lt;P&gt;also debug dataplane shows no logs:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;duckdns.org is resolved to&amp;nbsp;35.165.107.187.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;having in mind that vlan.10 interface is local firewall interface that has to match fw policy and nat policy in order to reach to internet ran packet-diag:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;admin@PAFW&amp;gt; debug dataplane packet-diag show setting&lt;/P&gt;&lt;P&gt;--------------------------------------------------------------------------------&lt;BR /&gt;Packet diagnosis setting:&lt;BR /&gt;--------------------------------------------------------------------------------&lt;BR /&gt;Packet filter&lt;BR /&gt;Enabled: yes&lt;BR /&gt;Match pre-parsed packet: yes&lt;BR /&gt;Index 1: 10.xx.xx.4/32[0]-&amp;gt;35.165.107.187/32[0], proto 0&lt;BR /&gt;ingress-interface any, egress-interface any, exclude non-IP&lt;BR /&gt;Index 2: 35.165.107.187/32[0]-&amp;gt;10.xx.xx.4/32[0], proto 0&lt;BR /&gt;ingress-interface any, egress-interface any, exclude non-IP&lt;BR /&gt;--------------------------------------------------------------------------------&lt;BR /&gt;Logging&lt;BR /&gt;Enabled: yes&lt;BR /&gt;Log-throttle: no&lt;BR /&gt;Sync-log-by-ticks: yes&lt;BR /&gt;Features:&lt;BR /&gt;flow : basic ager np arp receive ha nd mcast log track cluster pred&lt;BR /&gt;ctd : basic&lt;BR /&gt;ssl : basic&lt;BR /&gt;Counters:&lt;BR /&gt;--------------------------------------------------------------------------------&lt;BR /&gt;Packet capture&lt;BR /&gt;Enabled: yes&lt;BR /&gt;Snaplen: 0&lt;BR /&gt;Username:&lt;BR /&gt;Stage receive : file duck-receive&lt;BR /&gt;Captured: packets - 0 bytes - 0&lt;BR /&gt;Maximum: packets - 0 bytes - 0&lt;BR /&gt;Stage firewall : file duck-firewall&lt;BR /&gt;Captured: packets - 0 bytes - 0&lt;BR /&gt;Maximum: packets - 0 bytes - 0&lt;BR /&gt;Stage transmit : file duck-transmit&lt;BR /&gt;Captured: packets - 0 bytes - 0&lt;BR /&gt;Maximum: packets - 0 bytes - 0&lt;BR /&gt;Stage drop : file duck-drop&lt;BR /&gt;Captured: packets - 0 bytes - 0&lt;BR /&gt;Maximum: packets - 0 bytes - 0&lt;BR /&gt;--------------------------------------------------------------------------------&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;perhaps i might be wrong, but i do think that pa220 is not making requests to duckdns when i run&amp;nbsp;test dns-proxy ddns update interface name vlan.10, and there is no ssl session for that matter to use certificate profiles.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 08 Mar 2021 09:50:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dyndns-client-on-panos-9-0/m-p/389695#M90642</guid>
      <dc:creator>RBecirovic</dc:creator>
      <dc:date>2021-03-08T09:50:44Z</dc:date>
    </item>
    <item>
      <title>Re: DynDNS client on PANOS 9.0</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dyndns-client-on-panos-9-0/m-p/390521#M90715</link>
      <description>&lt;P&gt;Based on my previous update and further digging, the PA was not initiating traffic due to incorrect (default) service route configuration. After changing the setting and placing vlan.10 instead of default value DuckDns started to update properly.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="DuckDns.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/30289iBD3770AABDABFF54/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="DuckDns.png" alt="DuckDns.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 11 Mar 2021 11:20:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dyndns-client-on-panos-9-0/m-p/390521#M90715</guid>
      <dc:creator>RBecirovic</dc:creator>
      <dc:date>2021-03-11T11:20:52Z</dc:date>
    </item>
  </channel>
</rss>

