- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
Enhanced Security Measures in Place: To ensure a safer experience, we’ve implemented additional, temporary security measures for all users.
05-16-2022 09:14 AM
the customer firewall pa3220,version :10.2.1, the mgt interface could not access internet,so that firewall could not upgrade the url database.
but the system log dispaly some high log:url-cloud-connect-failure,the customer want don't see these log.
first solution:delete the PAN_DB_URL_Filtering key
Are there any good other solutions?
05-16-2022 12:09 PM
Hey @Felixcao ,
Out of curiosity, but why your customer don't consider using the URL filtering license that he already have paid for?
Does the firewall have Internet access through any of the dataplane interfaces - if yes you can use it for reaching the URL DB cloud with service routes = https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/networking/service-routes
PAN FW support enabling proxy for traffic to Palo cloud, it may be an option if the mgmt does not have direct internet access.
If you remove the URL filtering license, but still use URL filtering profile anywhere in the policy you may start receive warning messages when committing the policy - which are a lot more annoying.
Another question - does your customer don't want to see those logs forwarded to his external log collector or he does not want them on the firewall at all.
05-17-2022 01:08 AM
Hi: on 9.1 version ,the firewall have one follow cli
delete deviceconfig system update-schedule url-database
but on 10.2 version i could not find same cli,Is there no such function, or use other cli ?
10-26-2023 07:02 AM
Hi Felixcao,
Did you find a solution? I have a customer with the same issue.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!