<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Firewall rules for palo alto to update the content (anti-virus,signatur in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/firewall-rules-for-palo-alto-to-update-the-content-anti-virus/m-p/346222#M86477</link>
    <description>&lt;P&gt;if you've upgraded to 9.1 or later, you can leverage the palo alto tag in an application filter to dynamically allow all connections needed by your firewalls.&lt;/P&gt;&lt;P&gt;using this filter in a security rule will allow outbound connections and if ever a new service is added, or an existing one is changed, the filter will account for these automatically&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2020-09-01_13-00-06.jpg" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/27579iA8B70FC495635D16/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="2020-09-01_13-00-06.jpg" alt="2020-09-01_13-00-06.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2020-09-01_13-04-53.jpg" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/27580iB10B6CD29DC1AD63/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="2020-09-01_13-04-53.jpg" alt="2020-09-01_13-04-53.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 01 Sep 2020 11:07:29 GMT</pubDate>
    <dc:creator>reaper</dc:creator>
    <dc:date>2020-09-01T11:07:29Z</dc:date>
    <item>
      <title>Firewall rules for palo alto to update the content (anti-virus,signature...</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/firewall-rules-for-palo-alto-to-update-the-content-anti-virus/m-p/346185#M86467</link>
      <description>&lt;P&gt;Hi, anyone can advise how to configure the firewall rule for palo alto to update its contents? Thanks in advance.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 01 Sep 2020 06:24:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/firewall-rules-for-palo-alto-to-update-the-content-anti-virus/m-p/346185#M86467</guid>
      <dc:creator>herman2018</dc:creator>
      <dc:date>2020-09-01T06:24:09Z</dc:date>
    </item>
    <item>
      <title>Re: Firewall rules for palo alto to update the content (anti-virus,signatur</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/firewall-rules-for-palo-alto-to-update-the-content-anti-virus/m-p/346222#M86477</link>
      <description>&lt;P&gt;if you've upgraded to 9.1 or later, you can leverage the palo alto tag in an application filter to dynamically allow all connections needed by your firewalls.&lt;/P&gt;&lt;P&gt;using this filter in a security rule will allow outbound connections and if ever a new service is added, or an existing one is changed, the filter will account for these automatically&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2020-09-01_13-00-06.jpg" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/27579iA8B70FC495635D16/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="2020-09-01_13-00-06.jpg" alt="2020-09-01_13-00-06.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2020-09-01_13-04-53.jpg" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/27580iB10B6CD29DC1AD63/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="2020-09-01_13-04-53.jpg" alt="2020-09-01_13-04-53.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 01 Sep 2020 11:07:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/firewall-rules-for-palo-alto-to-update-the-content-anti-virus/m-p/346222#M86477</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2020-09-01T11:07:29Z</dc:date>
    </item>
    <item>
      <title>Re: Firewall rules for palo alto to update the content (anti-virus,signatur</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/firewall-rules-for-palo-alto-to-update-the-content-anti-virus/m-p/346237#M86484</link>
      <description>&lt;P&gt;Thanks for the reply&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/7608"&gt;@reaper&lt;/a&gt;&amp;nbsp;. But not only for application update, also for other update (anti-virus, IPS...). Out PA the management interface is connected to internal network , so how should create a firewall rule for PA update? I tried to create a rule to let management subnet outgoing traffic, but when click downloading under Dynamic update , it still shows failed. Can you please what firewall rules need for palo alto update? thanks&lt;/P&gt;</description>
      <pubDate>Tue, 01 Sep 2020 12:12:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/firewall-rules-for-palo-alto-to-update-the-content-anti-virus/m-p/346237#M86484</guid>
      <dc:creator>herman2018</dc:creator>
      <dc:date>2020-09-01T12:12:54Z</dc:date>
    </item>
    <item>
      <title>Re: Firewall rules for palo alto to update the content (anti-virus,signatur</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/firewall-rules-for-palo-alto-to-update-the-content-anti-virus/m-p/346241#M86486</link>
      <description>&lt;P&gt;All of the services and updates are included in that application filter, the only exception is when your firewall is not using your internal DNS and needs to reach out to an internet DNS, in which case you need to also allow outbound DNS, and possibly ntp and ping to sync time and troubleshoot&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2020-09-01_14-17-53.jpg" style="width: 827px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/27582i6845F3FB6417FA11/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="2020-09-01_14-17-53.jpg" alt="2020-09-01_14-17-53.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;if you do not have access to the application filter TAG, you will need the following applications for basic services, more may be required depending on your deployment)&lt;/P&gt;&lt;P&gt;- paloalto-dns-security&lt;/P&gt;&lt;P&gt;- paloalto-updates&lt;/P&gt;&lt;P&gt;- paloalto-wildfire-cloud&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 01 Sep 2020 12:25:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/firewall-rules-for-palo-alto-to-update-the-content-anti-virus/m-p/346241#M86486</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2020-09-01T12:25:07Z</dc:date>
    </item>
    <item>
      <title>Re: Firewall rules for palo alto to update the content (anti-virus,signatur</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/firewall-rules-for-palo-alto-to-update-the-content-anti-virus/m-p/346243#M86488</link>
      <description>&lt;P&gt;Thanks&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/7608"&gt;@reaper&lt;/a&gt;&amp;nbsp;. PA will use management IP or external IP address to download the updates?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 01 Sep 2020 12:29:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/firewall-rules-for-palo-alto-to-update-the-content-anti-virus/m-p/346243#M86488</guid>
      <dc:creator>herman2018</dc:creator>
      <dc:date>2020-09-01T12:29:19Z</dc:date>
    </item>
    <item>
      <title>Re: Firewall rules for palo alto to update the content (anti-virus,signatur</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/firewall-rules-for-palo-alto-to-update-the-content-anti-virus/m-p/346245#M86489</link>
      <description>&lt;P&gt;by default all connections come out of the management interface, but you can change the egress interface via service routes:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2020-09-01_14-32-23.jpg" style="width: 970px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/27583iA77F2256100CF682/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="2020-09-01_14-32-23.jpg" alt="2020-09-01_14-32-23.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 01 Sep 2020 12:37:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/firewall-rules-for-palo-alto-to-update-the-content-anti-virus/m-p/346245#M86489</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2020-09-01T12:37:13Z</dc:date>
    </item>
    <item>
      <title>Re: Firewall rules for palo alto to update the content (anti-virus,signatur</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/firewall-rules-for-palo-alto-to-update-the-content-anti-virus/m-p/389418#M90620</link>
      <description>&lt;P&gt;Nice, I'll give it a try with this filter.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for the recommendation!&lt;/P&gt;</description>
      <pubDate>Fri, 05 Mar 2021 15:37:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/firewall-rules-for-palo-alto-to-update-the-content-anti-virus/m-p/389418#M90620</guid>
      <dc:creator>AlexandroDelAngel</dc:creator>
      <dc:date>2021-03-05T15:37:03Z</dc:date>
    </item>
    <item>
      <title>Re: Firewall rules for palo alto to update the content (anti-virus,signatur</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/firewall-rules-for-palo-alto-to-update-the-content-anti-virus/m-p/389425#M90621</link>
      <description>&lt;P&gt;Do you think it would be ok if I lock it down to destination FQDN Object&amp;nbsp;updates.paloaltonetworks.com ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Fri, 05 Mar 2021 15:40:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/firewall-rules-for-palo-alto-to-update-the-content-anti-virus/m-p/389425#M90621</guid>
      <dc:creator>AlexandroDelAngel</dc:creator>
      <dc:date>2021-03-05T15:40:39Z</dc:date>
    </item>
  </channel>
</rss>

