PAN-OS 9.0 URL DB manual Download not available

Reply
L0 Member

PAN-OS 9.0 URL DB manual Download not available

Hi,

 

not sure if I to stupid to find it, but after upgrading to PAN-SO 9.0 there is no more option under Licenses URL DB to download the URL DB manually. 

 

In an Active/Passive Cluster the Active Firewall downloads the URL DB every few hours, but the passive one sits there with no URL DB. Just a cosmetic thing as the URL DB gets downloaded once you swap active/passive Firewalls.

 

Regards

Marc

 

L7 Applicator

The pandb is not a true database, but rather a prepopulation of your cache so you don't start off with an empty cache which could lead to a massive amount of network traffic doing all the 'new' lookups once an 'empty' system needs to start learning all new urls

 

Eventually your cache will weed out the unnecessary urls from the db and replace them with your network's "signature" popular urls

Tom Piens - PANgurus.com
Like my answer? check out my book! amazon.com/dp/1789956374
L4 Transporter

@reaper---awesome reply.   Best I've seen yet on this behavior.

 

So is this a "wait and populate"  type of thing then?   we noticed that after a DC failover a ton of our google-base searches come back as 'not-resolved' for the first 5-10 minutes, and then the exact same searches come back normally and work.   

 

Anyway around this, like a manual push to get them to update or something?   

 

The employees will be restless for 10 minutes, while we reply to him with a "just wait, it's loading"  feature....

L7 Applicator

Yes, you're basically brute forcing the lookup mechanism because the DB needs to start populating.

I'm not entirely sure manually loading the database could help (> request url-filtering upgrade) as the command is still there but it doesn't appear to do much.

You can still save the current cache on the failover DC ( > request url-filtering save ) and then load it the next time you need to fail over ( > request url-filtering install pandb-database )

 

In PAN-OS 10.0 there's a new HA feature that allows clustering over multiple clusters, this could help sync your runtime stuff more smoothly

 

 

 

Tom Piens - PANgurus.com
Like my answer? check out my book! amazon.com/dp/1789956374
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!