Panorama Dynamic Updates SSL Connect Error

Reply
L0 Member

Panorama Dynamic Updates SSL Connect Error

After upgrading some of our firewall and Panorama to PAN OS 8.x, we cannot push out dynamic updates from Panorama anymore.  We are still able to push out dynamic updates to firewalls running anything below PAN OS 8.x, but nothing within the PAN OS 8.x range.

 

We verified and are not blocking port 28443 anywhere, but are getting an error when trying to manually push out dynamic updates from Panorama to firewalls running PAN OS 8.x

 

See screenshot.  Any thoughts?

 

Dynamic Updates Palo Alto.jpg

Community Manager

Re: Panorama Dynamic Updates SSL Connect Error

Hi @Elijah.Putnam

 

could it be you have secure client communication / Check Server Identity enabled on these devices?

secure client communication.png

 


Help the community: Like helpful comments and mark solutions
Reaper out
L0 Member

Re: Panorama Dynamic Updates SSL Connect Error

Negative. We do not have this feature enabled on Panorama or the firewalls.

L1 Bithead

Re: Panorama Dynamic Updates SSL Connect Error

We have same issue with PanOS 8.1.2 

L1 Bithead

Re: Panorama Dynamic Updates SSL Connect Error

Devices with Pan OS 8.x.x use new application for dynamic updates (paloalto-updates  tcp 28443).

L0 Member

Re: Panorama Dynamic Updates SSL Connect Error

Did this get solved?  If so could you share the solution please?

 

Nevermind...I've just figured out that the above post regarding the new application and port number is the correct answer. Thanks folks.

Highlighted
L1 Bithead

Re: Panorama Dynamic Updates SSL Connect Error

Yes, paloalto-updates app solved the issue.

 

Thanks.

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!

The Live Community thanks you for your participation!