- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
09-15-2011 07:53 AM
Has anyone ran into issues with PANOS 4.05?
My previous past experience with PANOS 4.0.x was not the greatest.
High CPU utilization, network latency, GUI issues, and logging issues were not
the greatest. The end result was tech support and rollback to PANOS 3.1.x.
09-15-2011 08:32 AM
we are running 4.04 in prod since a while.
We had some issues indeed, but we received workarrounds from the TAC for most of them.
Running 4.05 in lab now.
09-16-2011 09:31 AM
We're about 1 week into using 4.0.5 and have only run into a couple issues, neither of which I consider to be show stoppers.
The first doesn't seem to be specific to 4.0.5 but it's an issue with administrator accounts syncing down from Panorama to the devices and shared authentication profiles not being useable outside of the Panorama context. Here's a link to the thread on that whole discussion:
https://live.paloaltonetworks.com/message/9307#9307
The other issue that we're dealing with concerns ACC and I currently have a support case open for it. In the ACC tab it shows the list of top applications, but when you drill down into each specific application the sections for additional information such as "Top Users" and "Top Destinations" show "No matching records" even though the traffic logs exist and are viewable on the Monitor tab.
Other than those two issues, from a functional standpoint 4.0.5 has been pretty stable for us so far.
09-16-2011 02:39 PM
With the possible exception of an abacus its a fair statement to say no product is without issues. PAN-OS 4.0.5 has been deployed throughout the world in very large to very small, simple to complex networks, in most cases without issue. Of course this isn't to say that we haven't had reports of problems with this code or any past code, rather to point out that we are a responsive developer and if you do encounter a problem PaloAlto Networks is committed to addressing and resolving these issues in a timely efficient fashion. We are a customer driven company and we welcome any input good, bad or indifferent from our customer base.
~Phil
09-19-2011 12:46 PM
Good to know that's only minor issues. I'm 2 days away from deploying it to our 4050. No testlab so it's production device for me.
09-19-2011 01:44 PM
issues i faced on a 4020 HA were:
1. firewall could not communicate with the PANAGENTS correctly resulting in our domain name being truncated. This inturn means that specific rules relying on a users to AD group membership resulted in them being denied access ( show user pan-agent user-IDs ). SSL VPN login denied for example.
2. Certain SSL decryption certs had to be re-imported.
3. Few app dependencies warnings appeared out of nowhere but easy enough to fix
4. SSL VPN custom portal page ( web login page ) was lost and had to be re-imported.
i hope this helps.
09-19-2011 07:28 PM
I'm only a few days into my 4.0.5 upgrade, from 3.1.8 and it was a very smooth upgrade. There were just a few small minor issues and from previous posts, it looks like I wasn't alone. I upgraded 3 HA Systems and each had different minor issues, that were easily fixed.
1. SSL-VPN Authentication Profile had to be removed and recreated along with the RAIUS Profile.
2. SSL-VPN Custom Portal page had to be reselected in the configuration page.
3. NetConnect 1.2.0 clients prompted for the Java Certificate Experation even if the clients had previously choosen to always trust the certificate.
4. Several URL Filter rules were detecting an overlap which caused a commit failure. After removing the unchecking the URL catagory that was in the error message the commit succeded.
5. Same ACC problem when drilling down on first day, but seems to be working properly today. Might have just need time to generate the logs, since the active units were changed after the upgrade.
All systems under 3.1.8 had CPU usage 20 to 50% consistantly, but after the upgrade and the CPU usage now run at under 5%.
09-22-2011 06:32 AM
Well, we've got a major problem with 4.0.5, which appears to be the same issue we were having with 4.0.4 until we rolled back to 4.0.3. The Dataplane restarts occasionaly for no apparent reason! This causes traffic to stop for about 10 minutes. We were told it was a known bug in 4.0.4 and that it would be fixed in 4.0.5. Apparently not. It's happened twice since Sunday. We are probably going to rollback to 4.0.3 yet again.
Anyone else run across this problem??
09-22-2011 07:22 AM
@toddinva: I've run across the same problem. This started happening in 4.0.3, and continued in 4.0.4. I was told it would be fixed in 4.0.5, but the dataplane keeps crashing about once a day on average.
09-22-2011 07:44 AM
Wonderful. 4.0.3 was stable for us though. We've already gotten the issue escalated, but they really need to fix this...
09-23-2011 10:45 AM
i am having the same dataplane crashing issue as well. not every day but it is still there, upgraded from 4.0.4 to 4.0.5 and this issue is not resolved.
Currently escalated to engineering. my boxes are 5020's is active-passive mode.
09-28-2011 11:54 PM
wr tried to update von Version 3.1.8 to 4.0.5 (4.0.1 was downloaeded before).
The update failed, because the autocommit job failed.(per CLI show jobs processed)
After Reboot, we tried to install 4.0.1. Here was the same failure, autocommit job Failed.
Then we activated 3.1.10 , and everything works.
Now, we wait for the support.
Are there any log.files, which show us the failure .
09-29-2011 05:43 AM
They are now telling me a fix will be in 4.0.6 which is due in mid-October. With a bug this significant, you'd think they would have pulled 4.0.4 and 4.0.5 until this was corrected! Very disappointing...
09-29-2011 05:50 AM
Same here, Working with engineering on this and disabled zone protection,DDOS and also any block changes in profiles and it's still an issue. I am sure more tech dumps to follow today.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!