PCNSE · Question #425
An administrator's device-group commit push is failing due to a new URL category. How should the administrator correct this issue?
The correct answer is A. update the Firewall Apps and Threat version to match the version of Panorama. When a new URL category is introduced in a content update, Panorama adopts it first. If the managed firewalls are running an older Apps and Threats content version that does not yet include that category, a commit push from Panorama will fail because the firewall does not recogni
Question
An administrator's device-group commit push is failing due to a new URL category. How should the administrator correct this issue?
Options
- Aupdate the Firewall Apps and Threat version to match the version of Panorama
- Bchange the new category action to "alert" and push the configuration again
- Censure that the firewall can communicate with the URL cloud
- Dverity that the URL seed tile has been downloaded and activated on the firewall
How the community answered
(54 responses)- A83% (45)
- B9% (5)
- C4% (2)
- D4% (2)
Explanation
When a new URL category is introduced in a content update, Panorama adopts it first. If the managed firewalls are running an older Apps and Threats content version that does not yet include that category, a commit push from Panorama will fail because the firewall does not recognize the category name referenced in the pushed policy. The fix is to update the firewall's Apps and Threats content version to match or exceed the version on Panorama (A), so the firewall can resolve the new category. Changing the action to 'alert' (B) is a workaround that avoids the failure but does not fix the root cause. Firewall-to-URL-cloud communication (C) and the URL seed file (D) relate to URL lookups at runtime, not to content version mismatches during commit.
Topics
Community Discussion
No community discussion yet for this question.