cache usage after licence expire

Reply
Highlighted
L4 Transporter

cache usage after licence expire

Hi Community,

 

What happens if URL and Threat licence expire in paloalto?. From PA kb ( https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000CloiCAC ) , i am able to understand that the cache will be used until it expires, but what is the cache timeout duration for URl and threat ?.

 

I am able to see the local db category information of particular URL, but in traffic log, it shows as licence-expired. Does this mean PA is no longer uses this catogary information and cache is already timed out?

Highlighted
L7 Applicator

Re: cache usage after licence expire

When threat license expires you will no longer get threat updates, but the old signatures will keep getting enforced (there is no cache for threats)

 

you can see how a URL is categorized in cache by running > test url <url>

 

 

reaper - PANgurus.com
I drink and I know things
Highlighted
L4 Transporter

Re: cache usage after licence expire

Hi @reaper
Usually how long PA will use url category cache?. I hope even after cache timeout happens, it won't be removed from db.
When I do test url, I am able to see category, but it shows cache expires in 0 seconds. Does it means cache is timed out, and PA won't be using this category information ?
Highlighted
L7 Applicator

Re: cache usage after licence expire

A cache entry stays for 1800 seconds and can get refreshed by a new request
Once the cache timeout is expired, the record can get replaced by a newer request
If you still see it, it is not replaced yet and policy cmwill apply its category
reaper - PANgurus.com
I drink and I know things
Highlighted
L4 Transporter

Re: cache usage after licence expire

Hi @reaper ,

 

In my case, the licence is expired, so after the 1800 seconds, it cannot have a new request to cloud and get updates,so it will expire soon right?.

for example,

if i put test facebook.com, it gives me following output.

 

facebook.com social-networking (Base db) expires in 0 seconds
facebook.com cloud-unavailable (Cloud db)

 

And i feel PA if not considering this cache, even if had a profile to block social networking catogary, it bypasses. So does that mean that 'expires in 0 seconds' indicates it expired already and it is stale, but it is not removed ?

 

Thanks in advance

 

Highlighted
L4 Transporter

Re: cache usage after licence expire

Thanks@reaper , 

 

I have seen below KB as well,

https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClXoCAK

 

So it looks like the cache is timed out but not removed.

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!

The Live Community thanks you for your participation!