I recently added a "URL Table (IPs)" alias to the configuration of this firewall cluster.
What I realized: when I configure the table's URL in the GUI the request is being sent via the configured proxy. The hourly refetch of the URL is not done via the proxy at all: the proxy log is empty and I verified in a packet capture that the firewall retrieves the file directly. The log on the standby firewall (that does not have Internet access in the setup) has following log entry that also points in that direction:
I had a quick look into iter_addresses source code (alias/uri.py) and it looks as though no proxy is being set there?
What I realized: when I configure the table's URL in the GUI the request is being sent via the configured proxy. The hourly refetch of the URL is not done via the proxy at all: the proxy log is empty and I verified in a packet capture that the firewall retrieves the file directly. The log on the standby firewall (that does not have Internet access in the setup) has following log entry that also points in that direction:
Code Select
(Caused by NewConnectionError("HTTPSConnection(host='<hostname>', port=443): Failed to establish a new connection: [Errno 65] No route to host")))
I had a quick look into iter_addresses source code (alias/uri.py) and it looks as though no proxy is being set there?
"