Why paloalto-updates application is SSL now?

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Why paloalto-updates application is SSL now?

L0 Member

Since 03/April/2017 02:00 Firewall detect paloalto-updates application as SSL then firewall can't update new signatures because there is no SSL allow in policy.This problem occur to my 3 customer now.

 

Do anyone have the same problems?

 

Customer 1Customer 1Customer 2Customer 2

3 REPLIES 3

L1 Bithead

Me too. I found pan-update application changed to SSL . It occur in PANOS 6.1.x but PANOS 7.1.8  is show pan-update normally and i add SSL application for work around.

L6 Presenter

The same discussion here but reason is unknown. Works fine with PAN-OS 8.0


@chinitsara wrote:

Me too. I found pan-update application changed to SSL . It occur in PANOS 6.1.x but PANOS 7.1.8  is show pan-update normally and i add SSL application for work around.


 

although this does appear to be a problem and should be addressed as soon as possible, a more elegant solution may be to use an Application Override policy.

Capture.JPG

 

out of curiosity, though. for those that are experiencing the issue, if you go to Objects -> Applications and look up the palo-updates app, does it still say ssl is implicitly used? if not, that would be the problem.

Capture.JPG

 

 ETA: apparently the implicit field isn't shown in 6.x, but hopefully this will work from the command line in configure mode

 

 

# show predefined application paloalto-updates | match implicit

 

 

--
CCNA Security, PCNSE7
  • 2538 Views
  • 3 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!