- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
Content translations are temporarily unavailable due to site maintenance. We apologize for any inconvenience.
03-15-2019 03:32 AM
Hi,
not sure if I to stupid to find it, but after upgrading to PAN-SO 9.0 there is no more option under Licenses URL DB to download the URL DB manually.
In an Active/Passive Cluster the Active Firewall downloads the URL DB every few hours, but the passive one sits there with no URL DB. Just a cosmetic thing as the URL DB gets downloaded once you swap active/passive Firewalls.
Regards
Marc
03-15-2019 07:08 AM
The pandb is not a true database, but rather a prepopulation of your cache so you don't start off with an empty cache which could lead to a massive amount of network traffic doing all the 'new' lookups once an 'empty' system needs to start learning all new urls
Eventually your cache will weed out the unnecessary urls from the db and replace them with your network's "signature" popular urls
07-16-2020 06:47 AM - edited 07-16-2020 06:48 AM
@reaper---awesome reply. Best I've seen yet on this behavior.
So is this a "wait and populate" type of thing then? we noticed that after a DC failover a ton of our google-base searches come back as 'not-resolved' for the first 5-10 minutes, and then the exact same searches come back normally and work.
Anyway around this, like a manual push to get them to update or something?
The employees will be restless for 10 minutes, while we reply to him with a "just wait, it's loading" feature....
07-20-2020 01:27 AM
Yes, you're basically brute forcing the lookup mechanism because the DB needs to start populating.
I'm not entirely sure manually loading the database could help (> request url-filtering upgrade) as the command is still there but it doesn't appear to do much.
You can still save the current cache on the failover DC ( > request url-filtering save ) and then load it the next time you need to fail over ( > request url-filtering install pandb-database )
In PAN-OS 10.0 there's a new HA feature that allows clustering over multiple clusters, this could help sync your runtime stuff more smoothly
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!