Failed to download dynamic update file with error "Failed to download due to protocol error"

Failed to download dynamic update file with error "Failed to download due to protocol error"

35609
Created On 03/11/22 22:32 PM - Last Modified 03/11/22 23:16 PM


Symptom


Firewall is able to connect to Update server but failed to download dynamic update files

 
  •  Firewall system log indicating connection to updates.paloaltonetworks.com is successful 
2022/03/11 12:38:05 info     general        general 0  Connection to Update server: updates.paloaltonetworks.com completed successfully, initiated by xx.xx.xx.xx

 
  • However, the download job FAIL with "protocol error" message.
PA-5020> show jobs id 10
Enqueued              Dequeued           ID                              Type                         Status Result Completed 
------------------------------------------------------------------------------------------------------------------------------
2022/03/11 12:40:05   12:40:05           10                            Downld                            FIN   FAIL 12:40:28  
Warnings:
Details:Failed to download due to protocol error. Please try again later.
Failed to download file



failed-download.png


Environment


Firewall  
Panorama
Content update (Antivirus, Application and Threats, Wildfire)


Cause


Firewall communication (tcp/443) to download server(s) (ie: proditpdownloads.paloaltonetworks.com or downloads.paloaltonetworks.com) is being denied by firewall rule between source IP and download server(s). 

Note: If session logging is enabled on relevant firewall policy, it would show the attempted session to proditpdownloads.paloaltonetworks.com or downloads.paloaltonetworks.com server is being denied by firewall rule. 


policy-deny.png


Resolution


To download dynamic update files, firewall needs to be able to establish (tcp/443) connections to following destination servers (URLs)
  • updates.paloaltonetworks.com
  • proditpdownloads.paloaltonetworks.com
  • downloads.paloaltonetworks.com

If the communication between firewall to update server is going through a firewall security policy with limited access, please include following Destination FQDNs or URLs on the relevant security policy to be allowed.
  • updates.paloaltonetworks.com
  • proditpdownloads.paloaltonetworks.com
  • downloads.paloaltonetworks.com

update-fqdns.png
 


Additional Information


Please refer to following "Content Delivery Network Infrastructure" documentation for additional information. 
  • Content Delivery Network Infrastructure
https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/software-and-content-updates/content-delivery-network-infrastructure-for-dynamic-updates.html


Actions
  • Print
  • Copy Link

    https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u0000004NaGCAU&refURL=http%3A%2F%2Fknowledgebase.paloaltonetworks.com%2FKCSArticleDetail&refURL=http%3A%2F%2Fknowledgebase.paloaltonetworks.com%2FKCSArticleDetail

Choose Language