i'm having issues updating the URL ,but the threat and content are being updated without problem.
I tried changing dns but see error i get when i force update
May 23 22:54:10 Error: pan_util_lock_process(pan_util.c:1106): Write lock '/tmp/pan_bc_download_lock' failed
May 23 22:54:10 Error: main(pan_bc_download.c:148): Failed to lock process! Maybe another instance is running.
May 23 22:54:22 ip 126.96.36.199 message RT time 4.485
May 23 22:54:23 ip 188.8.131.52 message RT time 0.483
May 23 22:54:26 Best IP for service.brightcloud.com is 184.108.40.206
May 23 22:54:26 Newer update available...
May 23 22:54:40 Best IP for database.brightcloud.com is 0.0.0.0
May 23 22:54:43 Failed to download 'full_bcdb_3.344.bin'
May 23 22:54:43 Error: pan_bc_download(pan_bc_url.c:1198): Failed to perform download and update
May 23 22:54:43 Error downloading latest URL database
The original issue was resolved in 3.1.2. You may need to add a service route to use for DNS requests if you have a layer 3 address on the internet side of the PAN:
Device> Setup> Service Route Configuration
Otherwise, on your internal DNS server you add entries for database.brightcloud.com using the IP’s listed below.
C:\>nslookup database.brightcloud.com 220.127.116.11
Addresses: 18.104.22.168, 22.214.171.124
Please note, BrightCloud changed the IP address for www.brightcloud.com to the above address on 6/17/2010 and it may take up to 30 hours to propegate the change to public DNS servers. 126.96.36.199 has been updated and customers have been successfully able to download the database when changing their DNS server to that.
It still does not work for me with 3.1.2. Our DNS is fine and the IP addresses are correct for service.brightcloud.com, database.brightcloud.com and www.brightcloud.com. I have also tried to use both an L3 interface and management with the same results. The traffic is making it out to the Internet fine, however this is an example of what the PAN device logs.
Jun 24 08:01:08 ip 188.8.131.52 message RT time 0.075
Jun 24 08:01:08 ip 184.108.40.206 message RT time 0.108
Jun 24 08:01:08 Best IP for service.brightcloud.com is 220.127.116.11
Jun 24 08:01:23 Cannot receive data from 'service.brightcloud.com:80' to download BrightCloud URL database
Jun 24 08:01:23 Error downloading latest URL database
I recently had a very similar issue. It turned out to be because my update traffic was passing through the a captive portal on another PAN box. I was using redirect on the CP and for some reason that was causing a problem with the URL updates. I added a rule to my CP policy that exempted the other PAN box and the update went fine after that. The other updates (software & content) went through the CP fine. I haven't looked into this any further to determine exactly what was going on, but I did notice that the other updates use only SSL while the URL update uses HTTP first and then SSL for the actual download. I hope this helps.
Currently having the same problem, it may appear that there is an upstream "Transparent Proxy" that your ISP is using.
You may want to try this link to see if there is one in place and investigate with your ISP
This is the current situation I think I have and am waiting on the ISP to see if there is a way we can bypass it all together for the brightcloud servers.
Will keep you posted.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!