Enhanced Security Measures in Place:   To ensure a safer experience, we’ve implemented additional, temporary security measures for all users.

FQDN refresh failed

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

FQDN refresh failed

L0 Member

We have 4 PaloAlto clusters and a FQDN refresh works on 3 of the clusters but not the 4th. All objects are shared on the 4 clusters. I have tried:

 

Scheduled refresh of FQDN fails

Manual refresh of FQDN fails

Changed the FQDN refresh time.

I can ping the DNS server from the Management Interface.

If i ping a DNS it resolves.

If I create a FQDN object it resolves.

but when I run request system fqdn show it states that no objects were resolved.

I have checked the logs (output below):

 

2019-03-12 11:46:25.988 +0000 dnscfgmod: FQDN Refresh: Periodic Force Refresh
2019-03-12 11:46:25.989 +0000 dnscfgmod: Main refresh function: (Force Refresh)
2019-03-12 11:46:25.989 +0000 dnscfgmod:Fqdn refresh job 496 scheduled
2019-03-12 11:46:25.989 +0000 FqdnRefresh job started processing. Dequeue time=2019/03/12 11:46:25
2019-03-12 11:46:30.863 +0000 dnscfgmod: Resolving fqdns took 5 secs
2019-03-12 11:46:30.863 +0000 Fqdn refresher thread device requested last config
2019-03-12 11:46:43.052 +0000 Error: pan_cfg_dnscfg_refresh_fqdns(pan_cfg_dnscfg.c:4340): Failed to refresh the fqdn.
2019-03-12 11:46:43.122 +0000 Error: pan_jobmgr_process_job(pan_job_mgr.c:2904): Fqdn Refresh job failed

 

 Can anyone help?

2 REPLIES 2

Cyber Elite
Cyber Elite

Hello,

Verify the service route to make sure that interface has access to the requested DNS servers. If you have not changed them the default is the management interface. Is there a PAN or security policy between the MGMT interface and the DNS servers? If yes, check the logs to see if/where it is getting blocked.

 

Hope that helps.

I checked all the settings again and they are set exactly the same for all 4 clusters we have. On Monday morning the FQDN refresh job worked successfully and has continued to work since. I do not know why it was not working or how it was fixed as no changes were made. hay-ho I am happy it is working for now.

  • 3851 Views
  • 2 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!