Enhanced Security Measures in Place:   To ensure a safer experience, we’ve implemented additional, temporary security measures for all users.

All sites registering as "unknown"

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

All sites registering as "unknown"

L1 Bithead

Came in today with users screaming that they were getting blocked on all websites.  Finally extracted enough information from them that the category was coming up as “unknown” for all sites…even Google.  Decided it had to be an issue in the URL filtering…updated to latest Brightcloud…no change.

Thought URL cache or dynamic URL cache might be the issue.  SSH-ed into the firewall and issued a clear url-cache all.  That fixed it.  Seems that the URL cache was corrupted.  BTW…I am running 5.0.3 on my PA.

Just thought I would pass that bit of information around in case you encounter that issue, too.

Has anyone else seen this before?

Not Inigo Montoya...you are safe, with or without 6 fingers.
34 REPLIES 34

egearhart,

The main issue was the result of a bug in our code - we've added fixes to PAN-OS (5.0.4) as well as content, to resolve this issue.  Version 363 of content contained most of the fixes, but devices would still exhibit some of the behavior mentioned here until a device server restart.  Having the PAN-OS fix in 5.0.4 will prevent this from happening at all.  Since 5.0.4 has yet to be released, it is recommended that any customer who runs into this issue should follow the above steps.

--Doris

L0 Member

Now that PAN-OS 5.0.4 has been released, has anyone actually installed it and confirmed that this is no longer an issue?

l

We have installed the code, and initially we still were seeing some sites stilmisrepresented as unknown. Today, it appears the sites are identified correctly, matching Brightcloud/Webroot. Once this is verified i'll reinstate policies..

Since I have installed 5.0.4, I have not seen anymore issues with the "unknown" sites.

Not Inigo Montoya...you are safe, with or without 6 fingers.

Not applicable

We have a 2020 pair running 5.0.1 and a 5020 pair running 5.0.3 URL 4092 also affected by the bug.  The below commands worked. I'll have to schedule an upgrade to 5.0.4 soon.

clear url-cache all

delete dynamic-url host all

debug software restart device-server

configure

set deviceconfig setting url dynamic-url yes

commit

  • 13946 Views
  • 34 replies
  • 1 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!