Failed to connect to Brightcloud update server, Best IP for is 0.0.0.0

Failed to connect to Brightcloud update server, Best IP for is 0.0.0.0

0
Created On 09/25/18 19:49 PM - Last Modified 07/19/22 23:07 PM


Symptom


Symptoms

Getting these alerts every second under system logs 

 

System logs

2016/03/04 14:18:43 medium url-fil connect 0 Failed to connect to Brightcloud update server , initiated by 10.1.253.243
2016/03/04 14:18:42 medium url-fil connect 0 Failed to connect to Brightcloud update server , initiated by 10.1.253.243
2016/03/04 14:18:42 medium url-fil connect 0 Failed to connect to Brightcloud update server , initiated by 10.1.253.243
2016/03/04 14:18:42 medium url-fil connect 0 Failed to connect to Brightcloud update server , initiated by 10.1.253.243
2016/03/04 14:18:41 medium url-fil connect 0 Failed to connect to Brightcloud update server , initiated by 10.1.253.243
2016/03/04 14:18:40 medium url-fil connect 0 Failed to connect to Brightcloud update server , initiated by 10.1.253.243
2016/03/04 14:18:35 medium url-fil connect 0 Failed to connect to Brightcloud update server , initiated by 10.1.253.243

Diagnosis

Confimred all the configurations are correct, but

‘service.brightcloud.com’ was not reachable at some time and firewall seems to cache this state forever.



Resolution


admin@admin> tail follow yes mp-log devsrv.log 


2016-03-04 14:17:09.391 -0600 Best IP for is 0.0.0.0 Firewall unable to reaolve ip as 0.0.0.0 for brightcloud service
2016-03-04 14:17:09.391 -0600 Error: Failed to connect to ':80'
2016-03-04 14:17:09.401 -0600 Best IP for is 0.0.0.0
2016-03-04 14:17:09.401 -0600 Error: Failed to connect to ':80'
2016-03-04 14:17:09.424 -0600 Best IP for is 0.0.0.0
2016-03-04 14:17:09.425 -0600 Error: Failed to connect to ':80'
2016-03-04 14:17:09.434 -0600 Best IP for is 0.0.0.0
2016-03-04 14:17:09.434 -0600 Error: Failed to connect to ':80'
2016-03-04 14:17:09.445 -0600 Best IP for is 0.0.0.0
2016-03-04 14:17:09.445 -0600 Error: Failed to connect to ':80'
2016-03-04 14:17:11.684 -0600 Best IP for is 0.0.0.0
2016-03-04 14:17:11.684 -0600 Error: Failed to connect to ':80'

 

system logs

 

2016/03/04 14:18:35 medium url-fil connect 0 Failed to connect to Brightcloud update server , initiated by 10.1.253.243

 

If you have created any email profile for medium severity the situation may become critical as you may be getting emails too frequently

 

Confirmed In the above case, all the things from configuration point of view are correct


>DNS resolutions were working properly
>ping host updates.paloaltonetwotks.com
you will be getting response with an IP address (for updates.paloaltonetwotks.com ping may not work as ping is disabled on the servers end)  you have to check if you are getting an ip address in response with ping command or not
>Time was accurate
>Able to download dynamic/software updates
if the situation is similar

 

The problem seems to start when at one stage ‘service.brightcloud.com’ is truly not reachable and firewall caches this state.

 

Restarting the below daemon should address the issue

 

admin@admin> debug software restart process device-server

 



Actions
  • Print
  • Copy Link

    https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000CleJCAS&refURL=http%3A%2F%2Fknowledgebase.paloaltonetworks.com%2FKCSArticleDetail