The error "CURL ERROR: OpenSSL SSL_connect: SSL_ERROR_SYSCALL in connection to s0000.urlcloud.paloaltonetworks.com:443" was happened with IP address 65.154.226.123

The error "CURL ERROR: OpenSSL SSL_connect: SSL_ERROR_SYSCALL in connection to s0000.urlcloud.paloaltonetworks.com:443" was happened with IP address 65.154.226.123

8142
Created On 02/17/25 08:38 AM - Last Modified 02/18/25 22:28 PM


Symptom


  • Firewall reports intermittent errors, such as "CURL ERROR: OpenSSL SSL_connect: SSL_ERROR_SYSCALL" and "PAN-DB cloud list loading failed (ERROR:SSL connect error)", during attempts to connect to the PAN-DB cloud.
  • After the errors,  the firewall is able to connect to PAN-DB cloud with another FQDN such as serverlist3.urlcloud.paloaltonetworks.com.
  • The errors are seen  intermittently.
  • The affected IP address is  "65.154.226.123".
  • System logs report the following error
high     url-filtering                    url-download-failur       0  PAN-DB cloud list loading failed (ERROR:SSL connect error).
high     url-filtering                    url-cloud-connectio       0  CURL ERROR: OpenSSL SSL_connect: SSL_ERROR_SYSCALL in connection to s0000.urlcloud.paloaltonetworks.com:443
  • Devsrvr.log report the following error when connecting to 65.154.226.123
URL https://s0000.urlcloud.paloaltonetworks.com/urlcloud_list IP 65.154.226.123 <<<---!!!
Source IP XXX.XXX.XXX.XXX
name lookup time 0.000019 second
connect time 0.153759 second
ssl connect time 0.000000 second
total time 0.305831 second
server certificate chain: 0 certinfo(s)
curl error: OpenSSL SSL_connect: SSL_ERROR_SYSCALL in connection to s0000.urlcloud.paloaltonetworks.com:443

 



Environment


  • Palo Alto Firewalls
  • Supported PAN-OS
  • PAN-DB url filtering


Cause


  • The root cause of the issue was a problem with the cloud server's IP address, specifically "65.154.226.123".
  • Our Engineering teams have acknowledged this issue and have addressed the same by removing this failed IP address from the DNS record for "s0000.urlcloud.paloaltonetworks.com".


Resolution


  1. The root cause was addressed by removing the problematic IP address from the DNS record for "s0000.urlcloud.paloaltonetworks.com" around 2/10.
  2. This permanently eliminates recurring errors related to this specific server.


Additional Information


N/A

Actions
  • Print
  • Copy Link

    https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u000000PRDtCAO&lang=en_US&refURL=http%3A%2F%2Fknowledgebase.paloaltonetworks.com%2FKCSArticleDetail

Choose Language