<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Basic setup- PAN8.0 + Minemeld issues in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/basic-setup-pan8-0-minemeld-issues/m-p/249153#M97154</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/98042"&gt;@dpocoroba&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;the GoDaddy certificate is useful only if your MineMeld has a certificate signed by GoDaddy.&amp;nbsp;In that specific article, the GoDaddy certificate is used because the Autofocus/MineMeld certificate is signed by GoDaddy. On private instance this could not apply.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Did you configure PAN-OS with a certificate profile? If you disable the certificate profile is the connection successful?&lt;/P&gt;
&lt;P&gt;Be aware that to properly test the connectivity to an EDL you should configure the EDL, use it in a policy in the firewall and commit. Please don't trust the "Test URL" button on the EDL config dialog.&lt;/P&gt;</description>
    <pubDate>Thu, 07 Feb 2019 08:06:56 GMT</pubDate>
    <dc:creator>lmori</dc:creator>
    <dc:date>2019-02-07T08:06:56Z</dc:date>
    <item>
      <title>Basic setup- PAN8.0 + Minemeld issues</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/basic-setup-pan8-0-minemeld-issues/m-p/248626#M97153</link>
      <description>&lt;P&gt;Hello All,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Having a problem getting a basic setup running feel I am missing something simple.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;- Fresh install of MM on AWS. Built using Ubuntu and the&lt;/P&gt;
&lt;P&gt;following link:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/MineMeld-Articles/Manually-install-MineMeld-on-Ubuntu-Server-14-04/ta-p/98454" target="_blank"&gt;https://live.paloaltonetworks.com/t5/MineMeld-Articles/Manually-install-MineMeld-on-Ubuntu-Server-14-04/ta-p/98454&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;-Everything worked fine&lt;/P&gt;
&lt;P&gt;-Installed the O365 lists as this is what I am trying to feed into PAN&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Followed this link:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/MineMeld-Articles/How-to-Safely-Enable-access-to-Office-365-using-MineMeld-Updated/ta-p/224148" target="_blank"&gt;https://live.paloaltonetworks.com/t5/MineMeld-Articles/How-to-Safely-Enable-access-to-Office-365-using-MineMeld-Updated/ta-p/224148&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Was able to see the lists, miners and feeds no problem.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I installed the GoDaddy root cert as outlined in&lt;/P&gt;
&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/MineMeld-Articles/Connecting-PAN-OS-to-MineMeld-using-External-Dynamic-Lists/ta-p/190414" target="_blank"&gt;https://live.paloaltonetworks.com/t5/MineMeld-Articles/Connecting-PAN-OS-to-MineMeld-using-External-Dynamic-Lists/ta-p/190414&lt;/A&gt; Step 2&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The issue I am having is getting the EDL to poll from the feed&lt;/P&gt;
&lt;P&gt;I can CURL the list from my PC but have to use the " -k " option to ignore the certificate error&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tried following to install a new cert on MM&lt;/P&gt;
&lt;P&gt;following this link:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://gist.github.com/jtschichold/f0977e5c1ec09b3ec7d66bf80687d9da&amp;nbsp;" target="_blank"&gt;https://gist.github.com/jtschichold/f0977e5c1ec09b3ec7d66bf80687d9da&amp;nbsp;&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Then exporting the CA.crt into a pem file and importing it into the PAN&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;No matter what I do on the PAN I cant get the EDL to actually load and import the IP's. I am sure its related to the certs causing the issue.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Any help is appreciated&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;-DP&lt;/P&gt;</description>
      <pubDate>Sun, 03 Feb 2019 01:40:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/basic-setup-pan8-0-minemeld-issues/m-p/248626#M97153</guid>
      <dc:creator>dpocoroba</dc:creator>
      <dc:date>2019-02-03T01:40:02Z</dc:date>
    </item>
    <item>
      <title>Re: Basic setup- PAN8.0 + Minemeld issues</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/basic-setup-pan8-0-minemeld-issues/m-p/249153#M97154</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/98042"&gt;@dpocoroba&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;the GoDaddy certificate is useful only if your MineMeld has a certificate signed by GoDaddy.&amp;nbsp;In that specific article, the GoDaddy certificate is used because the Autofocus/MineMeld certificate is signed by GoDaddy. On private instance this could not apply.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Did you configure PAN-OS with a certificate profile? If you disable the certificate profile is the connection successful?&lt;/P&gt;
&lt;P&gt;Be aware that to properly test the connectivity to an EDL you should configure the EDL, use it in a policy in the firewall and commit. Please don't trust the "Test URL" button on the EDL config dialog.&lt;/P&gt;</description>
      <pubDate>Thu, 07 Feb 2019 08:06:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/basic-setup-pan8-0-minemeld-issues/m-p/249153#M97154</guid>
      <dc:creator>lmori</dc:creator>
      <dc:date>2019-02-07T08:06:56Z</dc:date>
    </item>
  </channel>
</rss>

