- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
11-14-2023 02:16 AM
Hello,
The management interface from our PA-3260 suddenly tries to connect to 192.124.249.36 on port 80 web-browsing. 192.124.249.36 seems to be part of a CDN registered to Sucuri.net. Is this expected behavior, what service is this for?
11-14-2023 06:20 AM
Hi @adminglu ,
Looking at Reverse IP lookup for 192.124.249.36 - SecurityTrails
it looks like this is a CRL/OCSP URL for GoDaddy.
It is expected firewall to make connections to public CRL and OCSP URLs to validate the status of public certificates. I can think of few reason from top of my head:
- Lots of Palo Alto cloud services are using GoDaddy certificates, like update servers, telemetry servers (for AIOps), Data Lake logging
- Decryption rule (no matter if decrypt or no-decrypt) applying decryption profile, which block connection when server cert is revoked.
- Syslog Server using syslog over TLS.
11-14-2023 06:20 AM
Hi @adminglu ,
Looking at Reverse IP lookup for 192.124.249.36 - SecurityTrails
it looks like this is a CRL/OCSP URL for GoDaddy.
It is expected firewall to make connections to public CRL and OCSP URLs to validate the status of public certificates. I can think of few reason from top of my head:
- Lots of Palo Alto cloud services are using GoDaddy certificates, like update servers, telemetry servers (for AIOps), Data Lake logging
- Decryption rule (no matter if decrypt or no-decrypt) applying decryption profile, which block connection when server cert is revoked.
- Syslog Server using syslog over TLS.
11-14-2023 07:49 AM
Thank you for your response. One thing that might be related is that we recently installed a device certificate from Palo Alto following their recent advisory: https://live.paloaltonetworks.com/t5/customer-advisories/emergency-update-required-pan-os-root-and-d...
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!