Firewall receiving a HTTP 401 error when trying to access the Minemeld server

Reply
L1 Bithead

Firewall receiving a HTTP 401 error when trying to access the Minemeld server

Hi All, 

 

I've configured an external dynamic access list with the relevant account username/password to reach our minemeld server. When I test the connection however using 'test source url' in the external dynamic list configuration, this fails with a URL access error. 

 

On the minemeld server log:

 

127.0.0.1 - - [26/Sep/2019:14:25:45 +0100] "GET /feeds/o365-any-any-url-feed HTTP/1.0" 401 12 "-" "curl/7.60.0"

127.0.0.1 - - [26/Sep/2019:14:26:03 +0100] "GET /feeds/o365-any-any-ipv4-feed HTTP/1.0" 401 12 "-" "curl/7.60.0"

 

So the request is hitting the minemeld server, and I've also configured account on the firewall with the feed user account.  I've imported the certificate as required in this guide:

 

https://live.paloaltonetworks.com/t5/MineMeld-Articles/Connecting-PAN-OS-to-MineMeld-using-External-...

 

Can anyone help with the URL access issue?

 

Thanks

 

L1 Bithead

Re: Firewall receiving a HTTP 401 error when trying to access the Minemeld server

Also, just to add, after doing a tcpdump on the minemeld server I can see the TLS handshake completes with the firewall - with application data being sent. However, within the same second the firewall sends a FIN packet. 

 

Please let me know if you can help!

L1 Bithead

Re: Firewall receiving a HTTP 401 error when trying to access the Minemeld server

cert-error.jpg

 

Turns out I'm getting the above certificate error, but I followed the guide exactly here:

https://live.paloaltonetworks.com/t5/MineMeld-Articles/Connecting-PAN-OS-to-MineMeld-using-External-...

 

 

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!

The Live Community thanks you for your participation!