<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PAN-OS-11.1.2-h3 - No incomming traffic after upgrade in Next-Generation Firewall Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/pan-os-11-1-2-h3-no-incomming-traffic-after-upgrade/m-p/592421#M3433</link>
    <description>&lt;P&gt;Thanks for the update. We hace asked for support from Palo Alto as well. Once i successfully upgrade our 11.0 image to 11.1 image, will keep you updated on the procedure.&lt;/P&gt;</description>
    <pubDate>Thu, 18 Jul 2024 09:40:15 GMT</pubDate>
    <dc:creator>Harikrishnan.P</dc:creator>
    <dc:date>2024-07-18T09:40:15Z</dc:date>
    <item>
      <title>PAN-OS-11.1.2-h3 - No incomming traffic after upgrade</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/pan-os-11-1-2-h3-no-incomming-traffic-after-upgrade/m-p/592302#M3423</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We recently upgraded our Palo Alto 1410 Firewall to&amp;nbsp;PAN-OS-11.1.2-h3 from PAN-OS-11.0.4-h1.&lt;/P&gt;
&lt;P&gt;After Upgrade there was no incoming traffic from external networks. There were no hits or logs showing incoming traffic.&lt;/P&gt;
&lt;P&gt;Internet Outbound traffic was going through normally.&lt;/P&gt;
&lt;P&gt;IPSEC VPN tunnels were working normally.&lt;/P&gt;
&lt;P&gt;Support team checked and wanted us to downgrade to the previous version.&lt;/P&gt;
&lt;P&gt;Is this a bug in PAN-OS 11.1 ?&lt;/P&gt;
&lt;P&gt;Has anyone ever faced this issue after PAN-OS upgrades ?&lt;/P&gt;
&lt;P&gt;Should we install the base image for 11.1 before we upgrade to 11.1.2-h3?&lt;/P&gt;
&lt;P&gt;Any ideas and suggestiions are welcome.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;
&lt;P&gt;Hari&lt;/P&gt;</description>
      <pubDate>Wed, 17 Jul 2024 09:49:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/pan-os-11-1-2-h3-no-incomming-traffic-after-upgrade/m-p/592302#M3423</guid>
      <dc:creator>Harikrishnan.P</dc:creator>
      <dc:date>2024-07-17T09:49:56Z</dc:date>
    </item>
    <item>
      <title>Re: PAN-OS-11.1.2-h3 - No incomming traffic after upgrade</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/pan-os-11-1-2-h3-no-incomming-traffic-after-upgrade/m-p/592410#M3431</link>
      <description>&lt;P&gt;Can't say i've encountered this issue before due to a bug, but have seen similar things happen due to ARP issues. have you checked upstream MAC and ARP tables, are arp requests for the public IP of the firewall being replied to when inbound packets arrive, are tables updated accordingly?&lt;/P&gt;
&lt;P&gt;you could set up packetcapture and follow global counters to see what is happening on the firewall side, also packewt capture the upstream device and see what's going on&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;in regards to upgrading: you don't need to install the base image, it just needs to be downloaded for you to be able to install maintenance packages&lt;/P&gt;</description>
      <pubDate>Thu, 18 Jul 2024 08:42:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/pan-os-11-1-2-h3-no-incomming-traffic-after-upgrade/m-p/592410#M3431</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2024-07-18T08:42:10Z</dc:date>
    </item>
    <item>
      <title>Re: PAN-OS-11.1.2-h3 - No incomming traffic after upgrade</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/pan-os-11-1-2-h3-no-incomming-traffic-after-upgrade/m-p/592421#M3433</link>
      <description>&lt;P&gt;Thanks for the update. We hace asked for support from Palo Alto as well. Once i successfully upgrade our 11.0 image to 11.1 image, will keep you updated on the procedure.&lt;/P&gt;</description>
      <pubDate>Thu, 18 Jul 2024 09:40:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/pan-os-11-1-2-h3-no-incomming-traffic-after-upgrade/m-p/592421#M3433</guid>
      <dc:creator>Harikrishnan.P</dc:creator>
      <dc:date>2024-07-18T09:40:15Z</dc:date>
    </item>
    <item>
      <title>Re: PAN-OS-11.1.2-h3 - No incomming traffic after upgrade</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/pan-os-11-1-2-h3-no-incomming-traffic-after-upgrade/m-p/592563#M3453</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please have the support team open a ticket with engineering to have them take a look into the issue and obtain the next steps from them. Also as mentioned earlier, base image only needs to be downloaded during the upgrade process.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;</description>
      <pubDate>Fri, 19 Jul 2024 16:06:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/pan-os-11-1-2-h3-no-incomming-traffic-after-upgrade/m-p/592563#M3453</guid>
      <dc:creator>zahmed01</dc:creator>
      <dc:date>2024-07-19T16:06:47Z</dc:date>
    </item>
    <item>
      <title>Re: PAN-OS-11.1.2-h3 - No incomming traffic after upgrade</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/pan-os-11-1-2-h3-no-incomming-traffic-after-upgrade/m-p/593265#M3495</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;No incoming traffic after trying to upgrade 3 different versions of PAN-OS with PA1410 firewall.&lt;BR /&gt;On all the 3 occassions we had to revert back to the version which was running on the firewall.&lt;BR /&gt;There were no log hits on the "Monitor" showing incoming traffic.&lt;BR /&gt;We did see some icmp traffic but not http / https traffic.&lt;/P&gt;
&lt;P&gt;From PANOS 11.0.2-h2 to PANOS 11.1.0 - no incomming traffic after upgrade&lt;BR /&gt;From PANOS 11.0.4-h1 to PANOS 11.1.2-h3 - no incomming traffic after upgrade&lt;BR /&gt;From PANOS 11.0.4-h1 to PANOS 11.0.5 - no incomming traffic after upgrade&lt;/P&gt;
&lt;P&gt;We were able to upgrade a version inbetween from 11.0.2 to 11.04 without any issues.&lt;/P&gt;
&lt;P&gt;Palo Alto support is still working on the issue.&lt;/P&gt;
&lt;P&gt;Any ideas ?&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Thanks&lt;BR /&gt;Hari&lt;/P&gt;</description>
      <pubDate>Mon, 29 Jul 2024 05:27:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/pan-os-11-1-2-h3-no-incomming-traffic-after-upgrade/m-p/593265#M3495</guid>
      <dc:creator>Harikrishnan.P</dc:creator>
      <dc:date>2024-07-29T05:27:46Z</dc:date>
    </item>
    <item>
      <title>Re: PAN-OS-11.1.2-h3 - No incomming traffic after upgrade</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/pan-os-11-1-2-h3-no-incomming-traffic-after-upgrade/m-p/595794#M3628</link>
      <description>&lt;P&gt;I have the exact same issue on a PA-1410 HA pair. ARP is not updating. If you are in a HA pair, clear the arp manually and see that the arp table is no longer populated after the upgrade.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I've upgraded from 11.0.4-h1 to 11.0.5 (no arp), same for 11.0.4-h1 to 11.1.4-h1 (no arp). Something is seriously wrong, I guess it's PA-1410 related.&lt;/P&gt;</description>
      <pubDate>Fri, 23 Aug 2024 18:44:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/pan-os-11-1-2-h3-no-incomming-traffic-after-upgrade/m-p/595794#M3628</guid>
      <dc:creator>leonnl</dc:creator>
      <dc:date>2024-08-23T18:44:04Z</dc:date>
    </item>
    <item>
      <title>Re: PAN-OS-11.1.2-h3 - No incomming traffic after upgrade</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/pan-os-11-1-2-h3-no-incomming-traffic-after-upgrade/m-p/596214#M3651</link>
      <description>&lt;P&gt;this issue has been fixed in 11.1.2-h9 release.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-release-notes/pan-os-11-1-2-known-and-addressed-issues/pan-os-11-1-2-h9-addressed-issues" target="_blank"&gt;https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-release-notes/pan-os-11-1-2-known-and-addressed-issues/pan-os-11-1-2-h9-addressed-issues&lt;/A&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'm running 11.1.2-H3, traffic is available with no issues.&lt;/P&gt;</description>
      <pubDate>Wed, 28 Aug 2024 17:37:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/pan-os-11-1-2-h3-no-incomming-traffic-after-upgrade/m-p/596214#M3651</guid>
      <dc:creator>Z.Boussaid</dc:creator>
      <dc:date>2024-08-28T17:37:31Z</dc:date>
    </item>
    <item>
      <title>Re: PAN-OS-11.1.2-h3 - No incomming traffic after upgrade</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/pan-os-11-1-2-h3-no-incomming-traffic-after-upgrade/m-p/596771#M3683</link>
      <description>&lt;P&gt;I'm running 11.1.2-h3, and I see no logs in my Panorama instance. We did try to upgrade to 11.1.2-h9, and we got an error:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Failed to install 11.1.2-h9 with the following errors.&lt;/LI&gt;
&lt;LI&gt;SW version is 11.1.2-h9&lt;/LI&gt;
&lt;LI&gt;Nothing pending to cancel&lt;/LI&gt;
&lt;LI&gt;Error: Traceback (most recent call last):&lt;/LI&gt;
&lt;LI&gt;File "/opt/panrepo/releases/11.1.2-h9/validate", line 340, in &amp;lt;module&amp;gt;&lt;/LI&gt;
&lt;LI&gt;inds = check_for_old_indices()&lt;/LI&gt;
&lt;LI&gt;File "/opt/panrepo/releases/11.1.2-h9/validate", line 146, in check_for_old_indices&lt;/LI&gt;
&lt;LI&gt;check_dir_for_es_ind(in_dir)&lt;/LI&gt;
&lt;LI&gt;File "/opt/panrepo/releases/11.1.2-h9/validate", line 125, in check_dir_for_es_ind&lt;/LI&gt;
&lt;LI&gt;(name, ver, cdate) = get_es_ver_cdate_of_idx(fullpth)&lt;/LI&gt;
&lt;LI&gt;File "/opt/panrepo/releases/11.1.2-h9/validate", line 116, in get_es_ver_cdate_of_idx&lt;/LI&gt;
&lt;LI&gt;return (name, ver, cdate)&lt;/LI&gt;
&lt;LI&gt;UnboundLocalError: local variable 'cdate' referenced before assignment&lt;/LI&gt;
&lt;LI&gt;&amp;nbsp;&lt;/LI&gt;
&lt;LI&gt;Failed to install version 11.1.2-h9 type cms&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;We opened a case with TAC, and they said we need to wait until 11.1.5 comes out.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 04 Sep 2024 15:33:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/pan-os-11-1-2-h3-no-incomming-traffic-after-upgrade/m-p/596771#M3683</guid>
      <dc:creator>JamieEnglish</dc:creator>
      <dc:date>2024-09-04T15:33:35Z</dc:date>
    </item>
    <item>
      <title>Re: PAN-OS-11.1.2-h3 - No incomming traffic after upgrade</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/pan-os-11-1-2-h3-no-incomming-traffic-after-upgrade/m-p/596777#M3684</link>
      <description>&lt;P&gt;The error message you’re encountering during the installation of PAN-OS 11.1.2-h9 on your Palo Alto firewall points to a problem in the validation script, specifically an UnboundLocalError caused by a variable cdate being referenced before it's assigned. try this:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Verify Compatibility&lt;BR /&gt;Ensure that PAN-OS 11.1.2-h9 is compatible with your firewall model. Check the Palo Alto Networks documentation for any compatibility notes or prerequisites.&lt;/LI&gt;
&lt;LI&gt;Clear Previous Installation Attempts&lt;BR /&gt;Sometimes, remnants from previous installation attempts can cause issues. Ensure that there are no partial installations or residual files. You might need to clear out old files or directories related to previous installations.&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;Cancel Pending Jobs: Even though you mentioned nothing pending, double-check that there are no pending jobs or incomplete installations.&lt;/P&gt;
&lt;P&gt;Check and Clean Installation Directory: If applicable, look for and clean up old installation directories or files in /opt/panrepo/releases/.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;Update or Re-download the Software Image&lt;BR /&gt;The image you downloaded might be corrupted. Try downloading the PAN-OS 11.1.2-h9 image again from the Palo Alto Networks support site.&lt;/LI&gt;
&lt;LI&gt;File System Check&lt;BR /&gt;Ensure there is enough free space on the firewall’s file system. Lack of space can sometimes lead to incomplete installations and script errors.&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;i'm running the 11.1.2-H9 on my new 1420 in HA with traffic flowing.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 04 Sep 2024 16:03:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/pan-os-11-1-2-h3-no-incomming-traffic-after-upgrade/m-p/596777#M3684</guid>
      <dc:creator>Z.Boussaid</dc:creator>
      <dc:date>2024-09-04T16:03:49Z</dc:date>
    </item>
    <item>
      <title>Re: PAN-OS-11.1.2-h3 - No incomming traffic after upgrade</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/pan-os-11-1-2-h3-no-incomming-traffic-after-upgrade/m-p/596780#M3685</link>
      <description>&lt;P&gt;Thanks!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;On Step 2 and 3, do you have a list of commands to run for those?&lt;/P&gt;</description>
      <pubDate>Wed, 04 Sep 2024 16:18:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/pan-os-11-1-2-h3-no-incomming-traffic-after-upgrade/m-p/596780#M3685</guid>
      <dc:creator>JamieEnglish</dc:creator>
      <dc:date>2024-09-04T16:18:15Z</dc:date>
    </item>
    <item>
      <title>Re: PAN-OS-11.1.2-h3 - No incomming traffic after upgrade</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/pan-os-11-1-2-h3-no-incomming-traffic-after-upgrade/m-p/596782#M3686</link>
      <description>&lt;P&gt;&lt;STRONG&gt;Step 2:&lt;/STRONG&gt;&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;To cancel pending jobs or incomplete installations on a Palo Alto firewall, you can use the following CLI commands:
&lt;OL&gt;
&lt;LI&gt;Check for Pending Jobs:&amp;nbsp;&lt;EM&gt;&lt;STRONG&gt;show job all&amp;nbsp;&lt;/STRONG&gt; &amp;nbsp;-&amp;nbsp;This will display all jobs, including their status. Look for jobs with statuses like &lt;CODE&gt;pending&lt;/CODE&gt;, &lt;CODE&gt;running&lt;/CODE&gt;, or &lt;CODE&gt;stalled&lt;/CODE&gt;.&lt;/EM&gt;&lt;/LI&gt;
&lt;LI&gt;Cancel a Specific Job:&amp;nbsp;If you find any jobs that are stuck or you want to cancel, note the job ID from the output of the previous command. Then use the following command to cancel the specific job:&lt;STRONG&gt; &lt;EM&gt;request job cancel &amp;lt;job-id&amp;gt;&amp;nbsp;&lt;/EM&gt;&lt;/STRONG&gt;&lt;/LI&gt;
&lt;LI&gt;Cancel all jobs:&amp;nbsp;&lt;EM&gt;&lt;STRONG&gt;request job cancel all&lt;/STRONG&gt;.&lt;/EM&gt;&amp;nbsp;Be cautious with this command as it will cancel all ongoing or pending jobs.&lt;/LI&gt;
&lt;LI&gt;Check System and Installation Status:&amp;nbsp;To ensure the system is in a stable state and to check if any installation is in progress, you can use:&amp;nbsp;&lt;EM&gt;&lt;STRONG&gt;show system info&lt;/STRONG&gt; .&lt;/EM&gt;This command provides an overview of the system status, including current software version and installation status.&lt;/LI&gt;
&lt;/OL&gt;
&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&lt;STRONG&gt;Step 3:&lt;/STRONG&gt;&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;
&lt;P&gt;&lt;STRONG&gt;List Directory Contents:&lt;/STRONG&gt;&lt;/P&gt;
&lt;DIV class="dark bg-gray-950 contain-inline-size rounded-md border-[0.5px] border-token-border-medium"&gt;
&lt;DIV class="overflow-y-auto p-4" dir="ltr"&gt;&lt;CODE class="!whitespace-pre hljs language-bash"&gt;&lt;SPAN class="hljs-built_in"&gt;ls&lt;/SPAN&gt; /opt/panrepo/releases/
&lt;/CODE&gt;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;&lt;STRONG&gt;Check Disk Space:&lt;/STRONG&gt;&lt;/P&gt;
&lt;DIV class="dark bg-gray-950 contain-inline-size rounded-md border-[0.5px] border-token-border-medium"&gt;
&lt;DIV class="overflow-y-auto p-4" dir="ltr"&gt;&lt;CODE class="!whitespace-pre hljs language-bash"&gt;show system disk-space
&lt;/CODE&gt;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;&lt;STRONG&gt;Remove Old Files (Be Cautious):&lt;/STRONG&gt;&lt;/P&gt;
&lt;DIV class="dark bg-gray-950 contain-inline-size rounded-md border-[0.5px] border-token-border-medium"&gt;
&lt;DIV class="overflow-y-auto p-4" dir="ltr"&gt;&lt;CODE class="!whitespace-pre hljs language-bash"&gt;&lt;SPAN class="hljs-built_in"&gt;rm&lt;/SPAN&gt; -rf /opt/panrepo/releases/old-version-directory
&lt;/CODE&gt;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;&lt;STRONG&gt;Verify Current Software Version:&lt;/STRONG&gt;&lt;/P&gt;
&lt;DIV class="dark bg-gray-950 contain-inline-size rounded-md border-[0.5px] border-token-border-medium"&gt;
&lt;DIV class="overflow-y-auto p-4" dir="ltr"&gt;&lt;CODE class="!whitespace-pre hljs language-bash"&gt;show system info
&lt;/CODE&gt;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;&lt;STRONG&gt;Check for Ongoing Jobs:&lt;/STRONG&gt;&lt;/P&gt;
&lt;DIV class="dark bg-gray-950 contain-inline-size rounded-md border-[0.5px] border-token-border-medium"&gt;
&lt;DIV class="overflow-y-auto p-4" dir="ltr"&gt;&lt;CODE class="!whitespace-pre hljs language-bash"&gt;show job all
&lt;/CODE&gt;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;Always be cautious when using &lt;CODE&gt;rm -rf&lt;/CODE&gt; as it can permanently delete files and directories. Ensure you only remove files or directories that are no longer needed and not required for current operations. If in doubt, consult Palo Alto Networks support or documentation. good luck&lt;/P&gt;
&lt;OL&gt;
&lt;LI style="list-style-type: none;"&gt;&amp;nbsp;&lt;/LI&gt;
&lt;/OL&gt;</description>
      <pubDate>Wed, 04 Sep 2024 16:46:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/pan-os-11-1-2-h3-no-incomming-traffic-after-upgrade/m-p/596782#M3686</guid>
      <dc:creator>Z.Boussaid</dc:creator>
      <dc:date>2024-09-04T16:46:38Z</dc:date>
    </item>
    <item>
      <title>Re: PAN-OS-11.1.2-h3 - No incomming traffic after upgrade</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/pan-os-11-1-2-h3-no-incomming-traffic-after-upgrade/m-p/596785#M3687</link>
      <description>&lt;P&gt;I appreciate it. Looks like Step 2 is squared away. However, when running any ls commands, I get this:&lt;BR /&gt;admin@PAN-01&amp;gt; ls&lt;BR /&gt;Unknown command: ls&lt;BR /&gt;admin@PAN-01&amp;gt; &lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 04 Sep 2024 17:09:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/pan-os-11-1-2-h3-no-incomming-traffic-after-upgrade/m-p/596785#M3687</guid>
      <dc:creator>JamieEnglish</dc:creator>
      <dc:date>2024-09-04T17:09:53Z</dc:date>
    </item>
    <item>
      <title>Re: PAN-OS-11.1.2-h3 - No incomming traffic after upgrade</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/pan-os-11-1-2-h3-no-incomming-traffic-after-upgrade/m-p/596789#M3688</link>
      <description>&lt;DIV class="dark bg-gray-950 contain-inline-size rounded-md border-[0.5px] border-token-border-medium"&gt;
&lt;DIV class="overflow-y-auto p-4" dir="ltr"&gt;
&lt;P&gt;i think the ls command is accessed on the Shell level on PA, which is disabled and only TAC can have access to it.. this to prevent the rm -rf commands from being executed. i think if you need the list you might need to have TAC check on it for you. the PAs can be rooted, but it will void your warranty and support which I'm sure you don't want. so if the command did not work it is because of the root access limitation.&amp;nbsp;&lt;/P&gt;
&lt;CODE class="!whitespace-pre hljs language-bash"&gt;&lt;/CODE&gt;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 04 Sep 2024 17:48:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/pan-os-11-1-2-h3-no-incomming-traffic-after-upgrade/m-p/596789#M3688</guid>
      <dc:creator>Z.Boussaid</dc:creator>
      <dc:date>2024-09-04T17:48:22Z</dc:date>
    </item>
    <item>
      <title>Re: PAN-OS-11.1.2-h3 - No incomming traffic after upgrade</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/pan-os-11-1-2-h3-no-incomming-traffic-after-upgrade/m-p/598537#M3787</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;i am also experiencing a similar issue:&lt;BR /&gt;Our panorama is on 11.0.5. When we want to upgrade, we are receiving the following error message:&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;Failed to install 11.1.4-h1 with the following errors.&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;SW version is 11.1.4-h1&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;Nothing pending to cancel&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;Error: Traceback (most recent call last):&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;File "/opt/panrepo/releases/11.1.4-h1/validate", line 359, in &amp;lt;module&amp;gt;&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;(min([dts['min'] for dts in log_type_intv_dir.values() if dts['min']]).strftime('%Y-%m-%d'),&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;ValueError: min() arg is an empty sequence&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;Failed to install version 11.1.4-h1 type cms&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Any ideas? I also opened a TAC case. Unfortunately they did not found a solution yet.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 23 Sep 2024 12:07:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/pan-os-11-1-2-h3-no-incomming-traffic-after-upgrade/m-p/598537#M3787</guid>
      <dc:creator>Marco_DiFrancesco</dc:creator>
      <dc:date>2024-09-23T12:07:27Z</dc:date>
    </item>
    <item>
      <title>Re: PAN-OS-11.1.2-h3 - No incomming traffic after upgrade</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/pan-os-11-1-2-h3-no-incomming-traffic-after-upgrade/m-p/598539#M3788</link>
      <description>&lt;P&gt;i think you need to download 11.1.0 before you jump from 11.0.5 to 11.1.4-h1. do you have 11.1.0 downloaded in Panorama.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 23 Sep 2024 12:14:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/pan-os-11-1-2-h3-no-incomming-traffic-after-upgrade/m-p/598539#M3788</guid>
      <dc:creator>Z.Boussaid</dc:creator>
      <dc:date>2024-09-23T12:14:54Z</dc:date>
    </item>
    <item>
      <title>Re: PAN-OS-11.1.2-h3 - No incomming traffic after upgrade</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/pan-os-11-1-2-h3-no-incomming-traffic-after-upgrade/m-p/598541#M3789</link>
      <description>&lt;P&gt;Yes the base image is downloaded.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="SCALTEL_0-1727094145208.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/62358iDACC6E10C0625049/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="SCALTEL_0-1727094145208.png" alt="SCALTEL_0-1727094145208.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 23 Sep 2024 12:22:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/pan-os-11-1-2-h3-no-incomming-traffic-after-upgrade/m-p/598541#M3789</guid>
      <dc:creator>Marco_DiFrancesco</dc:creator>
      <dc:date>2024-09-23T12:22:33Z</dc:date>
    </item>
    <item>
      <title>Re: PAN-OS-11.1.2-h3 - No incomming traffic after upgrade</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/pan-os-11-1-2-h3-no-incomming-traffic-after-upgrade/m-p/599161#M3830</link>
      <description>&lt;P&gt;Same here.&lt;/P&gt;
&lt;P&gt;Panorama upgrade fails in install after a few seconds.&lt;/P&gt;
&lt;P&gt;11.0.3-h5 -&amp;gt; 11.1.4-h1 fails.&lt;/P&gt;
&lt;P&gt;11.1.0 -&amp;gt; 11.1.4-h1 fails&lt;/P&gt;
&lt;P&gt;11.1.0 -&amp;gt; 11.1.3-h6 fails&lt;/P&gt;
&lt;P&gt;The error message are the same.&lt;/P&gt;
&lt;P&gt;Still waiting for an analysis from our partner.&lt;/P&gt;</description>
      <pubDate>Tue, 01 Oct 2024 09:09:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/pan-os-11-1-2-h3-no-incomming-traffic-after-upgrade/m-p/599161#M3830</guid>
      <dc:creator>ttsws</dc:creator>
      <dc:date>2024-10-01T09:09:22Z</dc:date>
    </item>
    <item>
      <title>Re: PAN-OS-11.1.2-h3 - No incomming traffic after upgrade</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/pan-os-11-1-2-h3-no-incomming-traffic-after-upgrade/m-p/599300#M3833</link>
      <description>&lt;P&gt;Any news on the TAC case?&lt;BR /&gt;We are experiencing the same problem.&lt;/P&gt;</description>
      <pubDate>Wed, 02 Oct 2024 07:36:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/pan-os-11-1-2-h3-no-incomming-traffic-after-upgrade/m-p/599300#M3833</guid>
      <dc:creator>Tobi</dc:creator>
      <dc:date>2024-10-02T07:36:20Z</dc:date>
    </item>
    <item>
      <title>Re: PAN-OS-11.1.2-h3 - No incomming traffic after upgrade</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/pan-os-11-1-2-h3-no-incomming-traffic-after-upgrade/m-p/599311#M3834</link>
      <description>&lt;P&gt;ASC TAC says. they found similar issues. The solution was to delete all software images and redownload the required ones.&lt;/P&gt;
&lt;P&gt;This did not help in our case.&lt;/P&gt;
&lt;P&gt;Recommendation was to upgrade via CLI to get more error output, but in our case the output was the same which is displayed by the GUI.&lt;/P&gt;
&lt;P&gt;I hope, they will escalate this to PAN TAC.&lt;/P&gt;</description>
      <pubDate>Wed, 02 Oct 2024 11:13:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/pan-os-11-1-2-h3-no-incomming-traffic-after-upgrade/m-p/599311#M3834</guid>
      <dc:creator>ttsws</dc:creator>
      <dc:date>2024-10-02T11:13:37Z</dc:date>
    </item>
    <item>
      <title>Re: PAN-OS-11.1.2-h3 - No incomming traffic after upgrade</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/pan-os-11-1-2-h3-no-incomming-traffic-after-upgrade/m-p/607546#M3908</link>
      <description>&lt;P&gt;Had a session with Palo TAC. root level access at the beginning of the week. Expected solution did not work. Next solution: reinitialize Elastic Search, losing all logs. Not an option. Palo engineer wanted to check with colleagues for other workarounds. Yesterday I got new suggestions, which I have not tested, yet: Upgrade to 11.0.5 or 11.06 and then to 11.1.4 or go directly to 11.1.5 which fixes&amp;nbsp;PAN-258757.&lt;/P&gt;</description>
      <pubDate>Sat, 19 Oct 2024 19:08:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/pan-os-11-1-2-h3-no-incomming-traffic-after-upgrade/m-p/607546#M3908</guid>
      <dc:creator>ttsws</dc:creator>
      <dc:date>2024-10-19T19:08:18Z</dc:date>
    </item>
  </channel>
</rss>

