Unable to download updates

Reply
Highlighted
L4 Transporter

Unable to download updates

Hello,

When i download the PAN-OS or content update getting below error:-

 

Jafar_Hussain_0-1595613938290.png

Troubleshooting performed from my side:-

  • I can see all the services are running via the management plane.
  • I checked the connectivity between the management interface and the internet it was working fine.
  • I checked the traceroute from the firewall towards the update server of Paloalto, it was working perfectly.
  • Then I put ip address instead of the URL in the update server. But still, the issue persists.
  • We tried to download the dynamic updates but the same issue is happening.
  • In the last, we restarted the management server.

Can Any one suggest on this what i need to check.

 


Accepted Solutions
Highlighted
L4 Transporter

@MP18 

Thank you.

Once i uncheck the verify server identity and delete previous PAN-OS version after that i can able to download software.

View solution in original post


All Replies
Highlighted
Cyber Elite

Hi @Jafar_Hussain 

How did you check the connectivity between the mgmt interface and the internet? Is the connection traversing another firewall where may be tls decryption is enabled? Did this suddenly stop working or was it never working? Do you have a dns server configured? If there is another firewall or even the same make sure the traffic is allowed and either tls decryption disabled or then the checkbox at "check update server identity".

Highlighted
L4 Transporter

@vsys_remoPlease find the answer below:-

 

How did you check the connectivity between the mgmt interface and the internet?- I can able to ping google.com and 8.8.8.8 through management interface.

Is the connection traversing another firewall where may be tls decryption is enabled? - No decryption policy is configured.

Did this suddenly stop working or was it never working? - I think, the last content update downloaded before 8 months.

Do you have a dns server configured?- Yes

If there is another firewall or even the same make sure the traffic is allowed and either tls decryption disabled or then the checkbox at "check update server identity". - Checkbox is checked in verify server identity.

Highlighted
Cyber Elite

@Jafar_Hussain 

 

As per your info seems all is configured correctly.

This type of error normally comes if any firewall in path is doing ssl decryption and on this PA verify update server identity is checked.

1>>Can you please verify what you have configured under update server?

See if you can ping updates.paloaltonetworks.com

 

2>>Also if you verify and test number 1 then only thing i can say is uncheck the verify server identity

 

Regards

MAhesh

MP
Highlighted
L7 Applicator

as mentioned above, have you checked if URL filtering is maybe blocking (or presenting a 'continue') your dynamic updates

 

 

this one may sound silly, but have you tried hitting the 'check now'

 

last resort (try the silly one first)

debug swm rebuild-content-db

Tom Piens - PANgurus.com
Find my book at amazon.com/dp/1789956374
Highlighted
L4 Transporter

@MP18 

Thank you.

Once i uncheck the verify server identity and delete previous PAN-OS version after that i can able to download software.

View solution in original post

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!

The Live Community thanks you for your participation!