What happens if URL and Threat licence expire in paloalto?. From PA kb ( https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000CloiCAC ) , i am able to understand that the cache will be used until it expires, but what is the cache timeout duration for URl and threat ?.
I am able to see the local db category information of particular URL, but in traffic log, it shows as licence-expired. Does this mean PA is no longer uses this catogary information and cache is already timed out?
When threat license expires you will no longer get threat updates, but the old signatures will keep getting enforced (there is no cache for threats)
you can see how a URL is categorized in cache by running > test url <url>
Hi @reaper ,
In my case, the licence is expired, so after the 1800 seconds, it cannot have a new request to cloud and get updates,so it will expire soon right?.
if i put test facebook.com, it gives me following output.
facebook.com social-networking (Base db) expires in 0 seconds
facebook.com cloud-unavailable (Cloud db)
And i feel PA if not considering this cache, even if had a profile to block social networking catogary, it bypasses. So does that mean that 'expires in 0 seconds' indicates it expired already and it is stale, but it is not removed ?
Thanks in advance
I have seen below KB as well,
So it looks like the cache is timed out but not removed.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!