新部署的VM-FW提交失败,并出现“未知地址”或类似错误
3551
Created On 06/14/23 08:36 AM - Last Modified 01/03/25 11:37 AM
Symptom
- After bootstrapping a new VM Firewall in Azure , the local commit fails with below error:
rulebase -> security -> rules -> PAN-EDL-From-Blacklist -> source 'panw-bulletproof-ip-list' is not a valid reference rulebase -> security -> rules -> PAN-EDL-From-Blacklist -> source is invalid Warning: No valid Antivirus content package exists Warning: No Valid DNS Security License vsys1 Error: Failed to find address 'panw-bulletproof-ip-list' Error: Unknown address 'panw-bulletproof-ip-list'
Environment
- VM-Series防火墙
- 支持的 PAN OS
- 犯罪
Cause
- 为了使默认EDL 存在于防火墙中并在安全规则中使用,防火墙需要安装抗病毒和内容版本。
- 系统日志(显示系统日志)显示未安装防病毒软件和内容。
:45 high hw bootstr 0 Invalid image. Failed to get major version, minor version, and digest for file panupv2-all-contents-8700-7994
:45 high hw bootstr 0 Invalid image. Failed to get major version, minor version, and digest for file panup-all-antivirus-4431-4948
:24 medium general general 0 Antivirus package downloaded but installation could not be scheduled <<<<<<<
:24 medium general general 0 Failed to upgrade Antivirus package to version <unknown version> <<<<<<
:31 medium general general 0 Content package downloaded but installation could not be scheduled <<<<<<<
:31 medium general general 0 Failed to upgrade Content package to version <unknown version> <<<<<<<<
Resolution
- 将后续版本的动态内容(content/AV 文件)放入 bootstrap 包的 content 文件夹下,并部署VM防火墙。
- 示例:在 Azure门户> 存储帐户 -> 文件共享 -> 内容文件夹(添加 AV/内容文件)。