Network setup: PA3020 E1/2-->E1/1 PA500 E1/2-->Internet. In PA3020, we have configured the service route to paloaltoupdates through e1/2. Then traffic will reach pa500 e1/1 which will be routed to internet via e1/2. PAT configured on e1/2 which will be going to internet.I'm sure route, NAT,security policies are proper. In PA3020, connection to paloalto update server is established. even anti-virus updates download also started. when we check the show session id xxx. its showing lots of bytes exchanged between C2S and S2C. but at last TCP-reset by client ( send by palo alto firewall ). we are using staticupdates.paloaltonetworks.com which is working fine in PA500 but not working in PA3020. Since the PA-3020 deployement, updates are working fine. there is no configuration changes made recently. but suddenly stops working and session end reason is tcp-rst-by-client. we have created app-override on both firewalls to update server IP. but no luck. Please suggest how can we proceed further.
... View more