Unable to download updates

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

Unable to download updates

L4 Transporter

Hello,

When i download the PAN-OS or content update getting below error:-

 

Jafar_Hussain_0-1595613938290.png

Troubleshooting performed from my side:-

  • I can see all the services are running via the management plane.
  • I checked the connectivity between the management interface and the internet it was working fine.
  • I checked the traceroute from the firewall towards the update server of Paloalto, it was working perfectly.
  • Then I put ip address instead of the URL in the update server. But still, the issue persists.
  • We tried to download the dynamic updates but the same issue is happening.
  • In the last, we restarted the management server.

Can Any one suggest on this what i need to check.

 

1 accepted solution

Accepted Solutions

@MP18 

Thank you.

Once i uncheck the verify server identity and delete previous PAN-OS version after that i can able to download software.

View solution in original post

5 REPLIES 5

L7 Applicator

Hi @Jafar_Hussain 

How did you check the connectivity between the mgmt interface and the internet? Is the connection traversing another firewall where may be tls decryption is enabled? Did this suddenly stop working or was it never working? Do you have a dns server configured? If there is another firewall or even the same make sure the traffic is allowed and either tls decryption disabled or then the checkbox at "check update server identity".

@RemoPlease find the answer below:-

 

How did you check the connectivity between the mgmt interface and the internet?- I can able to ping google.com and 8.8.8.8 through management interface.

Is the connection traversing another firewall where may be tls decryption is enabled? - No decryption policy is configured.

Did this suddenly stop working or was it never working? - I think, the last content update downloaded before 8 months.

Do you have a dns server configured?- Yes

If there is another firewall or even the same make sure the traffic is allowed and either tls decryption disabled or then the checkbox at "check update server identity". - Checkbox is checked in verify server identity.

@Jafar_Hussain 

 

As per your info seems all is configured correctly.

This type of error normally comes if any firewall in path is doing ssl decryption and on this PA verify update server identity is checked.

1>>Can you please verify what you have configured under update server?

See if you can ping updates.paloaltonetworks.com

 

2>>Also if you verify and test number 1 then only thing i can say is uncheck the verify server identity

 

Regards

MAhesh

MP

Help the community: Like helpful comments and mark solutions.

as mentioned above, have you checked if URL filtering is maybe blocking (or presenting a 'continue') your dynamic updates

 

 

this one may sound silly, but have you tried hitting the 'check now'

 

last resort (try the silly one first)

debug swm rebuild-content-db

Tom Piens
PANgurus - Strata specialist; config reviews, policy optimization

@MP18 

Thank you.

Once i uncheck the verify server identity and delete previous PAN-OS version after that i can able to download software.

  • 1 accepted solution
  • 8414 Views
  • 5 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!