Newly deployed VM-FW commit fails with "Unknown address" or similar errors
3555
Created On 06/14/23 08:36 AM - Last Modified 10/30/24 21:33 PM
Symptom
- After bootstrapping a new VM Firewall in Azure , the local commit fails with below error:
rulebase -> security -> rules -> PAN-EDL-From-Blacklist -> source 'panw-bulletproof-ip-list' is not a valid reference rulebase -> security -> rules -> PAN-EDL-From-Blacklist -> source is invalid Warning: No valid Antivirus content package exists Warning: No Valid DNS Security License vsys1 Error: Failed to find address 'panw-bulletproof-ip-list' Error: Unknown address 'panw-bulletproof-ip-list'
Environment
- VM-Series Firewall
- Supported PAN-OS
- Commit
Cause
- For the default EDLs to be present in the firewall and used in the security rules, firewall needs to have antivirus and content version installed.
- System logs (show logs system) shows that Antivirus and content are not installed.
:45 high hw bootstr 0 Invalid image. Failed to get major version, minor version, and digest for file panupv2-all-contents-8700-7994
:45 high hw bootstr 0 Invalid image. Failed to get major version, minor version, and digest for file panup-all-antivirus-4431-4948
:24 medium general general 0 Antivirus package downloaded but installation could not be scheduled <<<<<<<
:24 medium general general 0 Failed to upgrade Antivirus package to version <unknown version> <<<<<<
:31 medium general general 0 Content package downloaded but installation could not be scheduled <<<<<<<
:31 medium general general 0 Failed to upgrade Content package to version <unknown version> <<<<<<<<
Resolution
- Include the later version of the dynamic contents ( content /AV files ) under the content folder of bootstrap package and deploy the VM firewall.
- Example: : In Azure portal > storage account -> File share -> Content folder (add the AV/content files).