<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Are EDLs updating from passive device? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/are-edls-updating-from-passive-device/m-p/374011#M88995</link>
    <description>&lt;P&gt;Are you seeing the "Unable to fetch external dynamic list. Couldn't connect to server. Using old copy for refresh." only on the passive device, and does the MGMT IP of the passive device have connectivity to your Minemeld URL?&lt;/P&gt;&lt;P&gt;As you're stating that manually forcing an update I'm assuming that it does, however I might be interpreting your scenario sketch wrongly. &amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What we've seen with some of our customers is that the error "Unable to fetch external dynamic list. Couldn't connect to server. Using old copy for refresh." at times is shown on the active device when there are no new or removed IP addresses on the EDL instead of a "Succesfully connected, no changes to the list were detected, using old copy" message.&lt;/P&gt;&lt;P&gt;With a manual refresh you force out the old EDL information and it would be expected to see that it updated successfully.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Could be a simple issue of wrong error code shown but still might be worth making a case with TAC to confirm this is the case.&lt;/P&gt;</description>
    <pubDate>Sat, 12 Dec 2020 14:13:05 GMT</pubDate>
    <dc:creator>Retired Member</dc:creator>
    <dc:date>2020-12-12T14:13:05Z</dc:date>
    <item>
      <title>Are EDLs updating from passive device?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/are-edls-updating-from-passive-device/m-p/373673#M88947</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Dear community,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;We´ve configured a couple of external dynamic list (IP and URL) on a local minemeld server and the passive device fails to fetch those lists. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Error obtained is:&amp;nbsp;"Unable to fetch external dynamic list. Couldn't connect to server. Using old copy for refresh."&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Manually forcing the firewall to download the list then it works ok.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Service route for External Dynamic Lists&amp;nbsp;and&amp;nbsp;Palo Alto Networks Services&amp;nbsp;service routes&amp;nbsp;are not set, then use MGT interface to fetch the EDLs.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When device becomes active then EDL refresh job completes without issues.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;+ Question: Do you know whehter it´s expected behavior the passive device not fetching EDLs?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you!&lt;/P&gt;</description>
      <pubDate>Thu, 10 Dec 2020 22:37:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/are-edls-updating-from-passive-device/m-p/373673#M88947</guid>
      <dc:creator>Carracido</dc:creator>
      <dc:date>2020-12-10T22:37:52Z</dc:date>
    </item>
    <item>
      <title>Re: Are EDLs updating from passive device?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/are-edls-updating-from-passive-device/m-p/373754#M88958</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/24977"&gt;@Carracido&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;They should be as long as you aren't using a service route, which you aren't. You should still be seeing EDL Fetch job done and Refresh job success messages in your system log for your EDLs even when the device is in Passive state.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 11 Dec 2020 04:00:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/are-edls-updating-from-passive-device/m-p/373754#M88958</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2020-12-11T04:00:48Z</dc:date>
    </item>
    <item>
      <title>Re: Are EDLs updating from passive device?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/are-edls-updating-from-passive-device/m-p/374011#M88995</link>
      <description>&lt;P&gt;Are you seeing the "Unable to fetch external dynamic list. Couldn't connect to server. Using old copy for refresh." only on the passive device, and does the MGMT IP of the passive device have connectivity to your Minemeld URL?&lt;/P&gt;&lt;P&gt;As you're stating that manually forcing an update I'm assuming that it does, however I might be interpreting your scenario sketch wrongly. &amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What we've seen with some of our customers is that the error "Unable to fetch external dynamic list. Couldn't connect to server. Using old copy for refresh." at times is shown on the active device when there are no new or removed IP addresses on the EDL instead of a "Succesfully connected, no changes to the list were detected, using old copy" message.&lt;/P&gt;&lt;P&gt;With a manual refresh you force out the old EDL information and it would be expected to see that it updated successfully.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Could be a simple issue of wrong error code shown but still might be worth making a case with TAC to confirm this is the case.&lt;/P&gt;</description>
      <pubDate>Sat, 12 Dec 2020 14:13:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/are-edls-updating-from-passive-device/m-p/374011#M88995</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2020-12-12T14:13:05Z</dc:date>
    </item>
  </channel>
</rss>

