My WF-500 appliance is behind a firewall and is failing registration. What external access is required on my firewall to ensure the device is registered?
I've allowed access to staticupdates.paloaltonetworks.com via 443 for software updates which is OK.
Initially to pass registration I temporarily allowed the device to any external IP address on 443 which passed registration. The device no longer appears registered.
Updates also require that valid DNS be working on the box. And all these communications occur from the mgmt port by default so the routing must be good from that interface.
Check your Service Route Configuration.
Device->Setup->Services->Service Route configuration
Based upon this info. Check the logs to make sure that the traffic is making it out, e.g. source the filter from the interface you configured for that Service. If its using the management interface, use that IP to check for the traffic.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!
The Live Community thanks you for your participation!