- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
07-30-2018 07:01 AM
Hi,
We are on the version 8.1.2 and If I upgrade to the latest ‘Applications and Threats’ version, currently 8044-4859, and then upgrade AV from 2678-3175 to 2683-3180 all rules fail, and traffic drops through the default deny.
I do not see any particular logs except "HA peer Anti-Virus set to Unknown".
2018-07-25 08:49:54:user:admin,client:Web,cmd:request anti-virus upgrade download file panup-all-antivirus-2683-3180
opcmdhistory.log
2018-07-25 08:50:13
2018-07-25 08:50:13:user:admin,client:Web,cmd:request anti-virus upgrade info
opcmdhistory.log
2018-07-25 08:50:43
2018-07-25 08:50:43:user:admin,client:Web,cmd:request anti-virus upgrade install commit yes file panup-all-antivirus-2683-3180.tgz
ha_agent.log
2018-07-25 08:51:42
2018-07-25 08:51:42.015 +0100 debug: ha_sysd_general_vers_string(src/ha_sysd_version.c:1800): Got new Anti-Virus: 2683-3180; for local value
ha_agent.log
2018-07-25 08:51:42
2018-07-25 08:51:42.015 +0100 HA peer Anti-Virus set to Unknown
opcmdhistory.log
2018-07-25 08:56:41
2018-07-25 08:56:41:user:admin,client:Web,cmd:request anti-virus upgrade info
pan_comm_0.log
2018-07-25 09:15:25
url get-your-anti-virus-checked.com, delete 0 children more
pan_comm_0.log
2018-07-25 09:15:25
url get-your-anti-virus-checked.com, delete 0 children more
opcmdhistory.log
2018-07-25 11:26:03
2018-07-25 11:26:03:user:admin,client:Web,cmd:request anti-virus upgrade info
opcmdhistory.log
2018-07-26 12:41:37
2018-07-26 12:41:37:user:admin,client:Web,cmd:request anti-virus upgrade info
Any ideas?
Thanks.
Best regards,
Bomi
07-30-2018 02:38 PM
So this has more possibility of being due to the Applications and Threats version then the AV upgrade. When the traffic was failing how was the traffic getting recognized, and did that traffic actually have any rules allowing it to go as the firewall was identifying it?
07-31-2018 03:39 AM
@BPry The same thing happend when only AV was updated. Applications were showing up as ‘not-applicable’ for services that should have been matched with our rules, but were dropping to the default deny rule.
07-31-2018 06:55 AM
Personally I would contact TAC at this point. It sounds like the update is somehow negating your entire <security/> rulebase, either by making the XML malformed or something like that. I've seen this through OS updates, but never through dynamic updates.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!