the customer firewall pa3220,version :10.2.1, the mgt interface could not access internet,so that firewall could not upgrade the url database.
but the system log dispaly some high log:url-cloud-connect-failure,the customer want don't see these log.
first solution：delete the PAN_DB_URL_Filtering key
Are there any good other solutions？
Hey @Felixcao ,
Out of curiosity, but why your customer don't consider using the URL filtering license that he already have paid for?
Does the firewall have Internet access through any of the dataplane interfaces - if yes you can use it for reaching the URL DB cloud with service routes = https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/networking/service-routes
PAN FW support enabling proxy for traffic to Palo cloud, it may be an option if the mgmt does not have direct internet access.
If you remove the URL filtering license, but still use URL filtering profile anywhere in the policy you may start receive warning messages when committing the policy - which are a lot more annoying.
Another question - does your customer don't want to see those logs forwarded to his external log collector or he does not want them on the firewall at all.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!