新部署的VM-FW提交失败,并出现“未知地址”或类似错误

新部署的VM-FW提交失败,并出现“未知地址”或类似错误

3551
Created On 06/14/23 08:36 AM - Last Modified 01/03/25 11:37 AM


Symptom


  • After bootstrapping a new VM Firewall in Azure , the local commit fails with below error:
    rulebase -> security -> rules -> PAN-EDL-From-Blacklist -> source 'panw-bulletproof-ip-list' is not a valid reference
    rulebase -> security -> rules -> PAN-EDL-From-Blacklist -> source is invalid
    Warning: No valid Antivirus content package exists
    Warning: No Valid DNS Security License
    vsys1
    Error: Failed to find address 'panw-bulletproof-ip-list'
    Error: Unknown address 'panw-bulletproof-ip-list'


Environment


  • VM-Series防火墙
  • 支持的 PAN OS
  • 犯罪


Cause


  • 为了使默认EDL 存在于防火墙中并在安全规则中使用,防火墙需要安装抗病毒和内容版本。
  • 系统日志(显示系统日志)显示未安装防病毒软件和内容。
:45 high hw bootstr 0 Invalid image. Failed to get major version, minor version, and digest for file panupv2-all-contents-8700-7994
:45 high hw bootstr 0 Invalid image. Failed to get major version, minor version, and digest for file panup-all-antivirus-4431-4948
:24 medium general general 0 Antivirus package downloaded but installation could not be scheduled <<<<<<<
:24 medium general general 0 Failed to upgrade Antivirus package to version <unknown version> <<<<<<
:31 medium general general 0 Content package downloaded but installation could not be scheduled <<<<<<<
:31 medium general general 0 Failed to upgrade Content package to version <unknown version> <<<<<<<<




Resolution


  1. 将后续版本的动态内容(content/AV 文件)放入 bootstrap 包的 content 文件夹下,并部署VM防火墙。
  2. 示例:在 Azure门户> 存储帐户 -> 文件共享 -> 内容文件夹(添加 AV/内容文件)。


Additional Information




Actions
  • Print
  • Copy Link

    https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u000000bq37CAA&lang=zh_CN&refURL=http%3A%2F%2Fknowledgebase.paloaltonetworks.com%2FKCSArticleDetail

Choose Language