Palo Alto Unable to Download Software Updates

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Palo Alto Unable to Download Software Updates

L3 Networker

Hi All,

 

Any advice on a possible solution or workaround? All traffic passes through the proxy server. We have already checked the KB below; however, we cannot change the DNS settings because the proxy server is being used as the DNS server.

https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClEpCAK

 

Model: PA - 3410

Software Version: 11.1.10-h1

Issue: Can't Download Dynamic Update to the current setup 

Temporary solution: Manual Dynamic Update using CSP.  

 

Current Setup:
Palo Alto Networks (Management Port) → Proxy Server → (Trust Port) PA → (Untrust Port) → Internet

 

 

6 REPLIES 6

Cyber Elite

How is DNS involved in your issue?

Does proxy perform SSL decryption?

Does proxy require authentication?

Principal Architect @ Cloud Carib Ltd
Palo Alto Networks certified from 2011

Reviewing the traffic logs, where we can find verbose system logs on why palo alto sent rst for update session when download is triggered?

GUI system shows connection is successful.PA-3410.pngSystem.png

 

-How is DNS involved in the issue?

[GS] DNS resolution on proxy. 

-Does the proxy require authentication?

[GS] No authentication required to proxy.

Cyber Elite

Error states that certificate validation fails.

Most likely DNS works and paloaltonetworks.com FQDNs get resolved but proxy performs ssl decryption and connection fails due Palo not trusting proxy certificate.

 

Can you bypass Palo mgmt IP accessing *.paloaltonetworks.com from decryption?

Principal Architect @ Cloud Carib Ltd
Palo Alto Networks certified from 2011

We are not using the decryption. 

Cyber Elite

Error clearly points to certificate validation issue.

So re-check proxy config if it is altering certificate.

 

Raido_Rattameister_0-1767878267160.png

 

Principal Architect @ Cloud Carib Ltd
Palo Alto Networks certified from 2011
  • 438 Views
  • 6 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!