DAG is not working

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

DAG is not working

L4 Transporter

hey

 

i have started playing arround with MineWeld.

i am testing a solution for a customer to update DynamicObject / Block lists on the PA to be used by the SOC team.

 

i have created a IPv4 List and connected it directly to a DagPusher node.

 

but when i add an indicator to the miner i do not see it on the PA dynamic group.

 

this is what i see on MineWeld

DagPusher.PNG

 

This is the config , i assume here that the TAG is the TAG on the PA that the dynamic group should catch the objects, is it right ? 

DagPusherConfig.PNG

 

this is the configured dynamyc group

PA-Group.PNG

 

admin@PA-LAB> show object dynamic-address-group all


Dynamic address groups in vsys vsys1:
----------------------------------------------------

----------------defined in vsys --------------------
SOC-BlockIPs
filter: 'SOC-BlockIPs'
members: total 0


----------------defined in shared-------------------
O: address object; R: registered ip; 😧 dynamic group; S: static group

 

 

Another question that i have is suppose the PA is not "alive" to get the updates , will MineWeld try to push the updates once ? or it will try again in a loop and wil update the device with the changes when it will be back ?

 

5 REPLIES 5

L7 Applicator

Hi @minow,

have you configured the devices under the output node device list ?

Whe you browse the tags under PAN-OS you should be able to see the tags pushed by MineMeld. By default they the mmld_ prrefix.

thanks,

i was able to solve it somehow.

also the command i use for the cli was wrong , i needed the "registered ip" and not the "dynamic group"

Hi @minow,

thank you for letting us know.

 

Regards,

luigi

Hi Luigi,

 

I'm not able to see the tags pushed by MineMeld on PA firewall

I can see the following default tags: -

'mmld_pushed' and 'mmld_confidence_high'  and 'mmld_direction_unknown' 

I can't find any document related to the "DAGPusher" prototype, it would be great if you could share any document to configure the "DAGPusher" prototype.

 

Thank You

Hi @PrasadDigraskar,

those are the default tags pushed by the output node to the firewall. Which tags would you like to see ?

 

Thanks !

luigi

  • 5870 Views
  • 5 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!