5250's failing to pass traffic after AV software update

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

5250's failing to pass traffic after AV software update

L1 Bithead

 

Hi,

 

We are on the version 8.1.2 and If I upgrade to the latest ‘Applications and Threats’ version,  currently 8044-4859, and then upgrade AV from 2678-3175 to 2683-3180 all rules fail, and traffic drops through the default deny.

 

I do not see any particular logs except "HA peer Anti-Virus set to Unknown".

 

2018-07-25 08:49:54:user:admin,client:Web,cmd:request anti-virus upgrade download file panup-all-antivirus-2683-3180

opcmdhistory.log            

2018-07-25 08:50:13

2018-07-25 08:50:13:user:admin,client:Web,cmd:request anti-virus upgrade info

opcmdhistory.log            

2018-07-25 08:50:43

2018-07-25 08:50:43:user:admin,client:Web,cmd:request anti-virus upgrade install commit yes file panup-all-antivirus-2683-3180.tgz

ha_agent.log    

2018-07-25 08:51:42

2018-07-25 08:51:42.015 +0100 debug: ha_sysd_general_vers_string(src/ha_sysd_version.c:1800): Got new Anti-Virus: 2683-3180; for local value

ha_agent.log    

2018-07-25 08:51:42

2018-07-25 08:51:42.015 +0100 HA peer Anti-Virus set to Unknown

opcmdhistory.log            

2018-07-25 08:56:41

2018-07-25 08:56:41:user:admin,client:Web,cmd:request anti-virus upgrade info

pan_comm_0.log            

2018-07-25 09:15:25

url get-your-anti-virus-checked.com, delete 0 children more

pan_comm_0.log            

2018-07-25 09:15:25

url get-your-anti-virus-checked.com, delete 0 children more

opcmdhistory.log            

2018-07-25 11:26:03

2018-07-25 11:26:03:user:admin,client:Web,cmd:request anti-virus upgrade info

opcmdhistory.log            

2018-07-26 12:41:37

2018-07-26 12:41:37:user:admin,client:Web,cmd:request anti-virus upgrade info

 

Any ideas?

Thanks.

 

Best regards,

Bomi

 

3 REPLIES 3

Cyber Elite
Cyber Elite

@Bomi,

So this has more possibility of being due to the Applications and Threats version then the AV upgrade. When the traffic was failing how was the traffic getting recognized, and did that traffic actually have any rules allowing it to go as the firewall was identifying it? 

 

@BPry The same thing happend when only AV was updated. Applications were showing up as ‘not-applicable’ for services that should have been matched with our rules, but were dropping to the default deny rule.

@Bomi,

Personally I would contact TAC at this point. It sounds like the update is somehow negating your entire <security/> rulebase, either by making the XML malformed or something like that. I've seen this through OS updates, but never through dynamic updates. 

  • 2187 Views
  • 3 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!