The error "CURL ERROR: OpenSSL SSL_connect: SSL_ERROR_SYSCALL in connection to s0000.urlcloud.paloaltonetworks.com:443" was happened with IP address 65.154.226.123
8142
Created On 02/17/25 08:38 AM - Last Modified 02/18/25 22:28 PM
Symptom
- Firewall reports intermittent errors, such as "CURL ERROR: OpenSSL SSL_connect: SSL_ERROR_SYSCALL" and "PAN-DB cloud list loading failed (ERROR:SSL connect error)", during attempts to connect to the PAN-DB cloud.
- After the errors, the firewall is able to connect to PAN-DB cloud with another FQDN such as serverlist3.urlcloud.paloaltonetworks.com.
- The errors are seen intermittently.
- The affected IP address is "65.154.226.123".
- System logs report the following error
high url-filtering url-download-failur 0 PAN-DB cloud list loading failed (ERROR:SSL connect error).
high url-filtering url-cloud-connectio 0 CURL ERROR: OpenSSL SSL_connect: SSL_ERROR_SYSCALL in connection to s0000.urlcloud.paloaltonetworks.com:443
- Devsrvr.log report the following error when connecting to 65.154.226.123
URL https://s0000.urlcloud.paloaltonetworks.com/urlcloud_list IP 65.154.226.123 <<<---!!!
Source IP XXX.XXX.XXX.XXX
name lookup time 0.000019 second
connect time 0.153759 second
ssl connect time 0.000000 second
total time 0.305831 second
server certificate chain: 0 certinfo(s)
curl error: OpenSSL SSL_connect: SSL_ERROR_SYSCALL in connection to s0000.urlcloud.paloaltonetworks.com:443
Environment
- Palo Alto Firewalls
- Supported PAN-OS
- PAN-DB url filtering
Cause
- The root cause of the issue was a problem with the cloud server's IP address, specifically "65.154.226.123".
- Our Engineering teams have acknowledged this issue and have addressed the same by removing this failed IP address from the DNS record for "s0000.urlcloud.paloaltonetworks.com".
Resolution
- The root cause was addressed by removing the problematic IP address from the DNS record for "s0000.urlcloud.paloaltonetworks.com" around 2/10.
- This permanently eliminates recurring errors related to this specific server.
Additional Information
N/A