<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Package manager upgrade failures to certain sites in Next-Generation Firewall Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/package-manager-upgrade-failures-to-certain-sites/m-p/603809#M3890</link>
    <description>&lt;P&gt;Interestingly it looks like we solved our issue this evening.&amp;nbsp;&amp;nbsp;&lt;SPAN&gt;We wanted to try and upgrade the firewalls this evening to 10.2.9-h11. Before upgrading I wanted to reload the firewall first and test again on the off chance a reload fixed it (we had failed the firewalls over before but never reloaded). After reloading the passive and then making it active the problem no longer occurs. If we fail over to the one that hasn't been reloaded the problem comes back. Seems to indicate there is some kind of memory leak or some kind of uptime issue with this code train.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 17 Oct 2024 04:54:42 GMT</pubDate>
    <dc:creator>brianhill88</dc:creator>
    <dc:date>2024-10-17T04:54:42Z</dc:date>
    <item>
      <title>Package manager upgrade failures to certain sites</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/package-manager-upgrade-failures-to-certain-sites/m-p/602692#M3888</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;We have a case open for this that has been turned over to internal dev but I thought I would post this here to see if anyone else was experiencing this issue.&amp;nbsp; This on a 5260 running 10.2.7-h3.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We been tracking down this issue for a long time.&amp;nbsp; &amp;nbsp;It started as Mac build servers that reach out to the Internet using brew to install package upgrades.&amp;nbsp; &amp;nbsp;These would fail periodically but because it was working more than not it wasn't reported at first.&amp;nbsp; The problem was eventually reported and we had both our network team and platform team start looking at it.&amp;nbsp; We conducted numerous packet captures and also worked with our network hardware vendor to make sure the problem wasn't the network itself.&amp;nbsp; &amp;nbsp;When we started focusing on the Palo Alto we noticed missing return packets in the Palo Alto captures on the box.&amp;nbsp; &amp;nbsp;Palo Alto thought that was because the traffic was being offloaded to hardware.&amp;nbsp; So in an effort to find the missing packets we did a session where we turned off hardware offloading.&amp;nbsp; &amp;nbsp;Unexpectedly the package upgrades with brew no longer failed.&amp;nbsp; &amp;nbsp;So it appears there is some kind of issue with the traffic being offloaded to hardware but not conclusive yet.&amp;nbsp; &amp;nbsp;We did notice we do not have the same issue on a 3260 running the same code train.&lt;/P&gt;
&lt;P&gt;Since then we have seen other 443 issues with other package managers.&amp;nbsp; We also wondering if there are other 443 issues just not being reported because they work the majority of the time.&lt;/P&gt;</description>
      <pubDate>Wed, 16 Oct 2024 23:04:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/package-manager-upgrade-failures-to-certain-sites/m-p/602692#M3888</guid>
      <dc:creator>brianhill88</dc:creator>
      <dc:date>2024-10-16T23:04:55Z</dc:date>
    </item>
    <item>
      <title>Re: Package manager upgrade failures to certain sites</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/package-manager-upgrade-failures-to-certain-sites/m-p/603809#M3890</link>
      <description>&lt;P&gt;Interestingly it looks like we solved our issue this evening.&amp;nbsp;&amp;nbsp;&lt;SPAN&gt;We wanted to try and upgrade the firewalls this evening to 10.2.9-h11. Before upgrading I wanted to reload the firewall first and test again on the off chance a reload fixed it (we had failed the firewalls over before but never reloaded). After reloading the passive and then making it active the problem no longer occurs. If we fail over to the one that hasn't been reloaded the problem comes back. Seems to indicate there is some kind of memory leak or some kind of uptime issue with this code train.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 17 Oct 2024 04:54:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/package-manager-upgrade-failures-to-certain-sites/m-p/603809#M3890</guid>
      <dc:creator>brianhill88</dc:creator>
      <dc:date>2024-10-17T04:54:42Z</dc:date>
    </item>
    <item>
      <title>Re: Package manager upgrade failures to certain sites</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/package-manager-upgrade-failures-to-certain-sites/m-p/606924#M3905</link>
      <description>&lt;P&gt;Unfortunately the solution was short lived.&amp;nbsp; Within a day the problem started happening again.&amp;nbsp; Last night we moved forward with upgrading the firewalls to 10.2.9-h11.&amp;nbsp; &amp;nbsp;The problem still persists as of testing this morning.&lt;/P&gt;</description>
      <pubDate>Fri, 18 Oct 2024 18:05:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/package-manager-upgrade-failures-to-certain-sites/m-p/606924#M3905</guid>
      <dc:creator>brianhill88</dc:creator>
      <dc:date>2024-10-18T18:05:24Z</dc:date>
    </item>
    <item>
      <title>Re: Package manager upgrade failures to certain sites</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/package-manager-upgrade-failures-to-certain-sites/m-p/615471#M4912</link>
      <description>&lt;P&gt;Update:&lt;/P&gt;
&lt;P&gt;The update to 10.2.9-h11 actually introduced a new problem where all TLS traffic stopped working after 6 days.&amp;nbsp; This is a known issue and they are releasing a hotfix for it.&amp;nbsp; We ended up rolling back to the a previous version.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Solution:&lt;/P&gt;
&lt;P&gt;PA engineers were able to give us a fix for the original issue we were experiencing.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The solution was to change the LAG flow from type tag to type tuple:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;set session lag-flow-key-type tuple&lt;/P&gt;
&lt;P&gt;show session lag-flow-key-type&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;After setting it to tuple, initial testing shows we are no longer seeing the issue.&amp;nbsp; &amp;nbsp;This appears to keep each unique session on a particular link in a LAG.&lt;/P&gt;</description>
      <pubDate>Mon, 28 Oct 2024 16:50:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/package-manager-upgrade-failures-to-certain-sites/m-p/615471#M4912</guid>
      <dc:creator>brianhill88</dc:creator>
      <dc:date>2024-10-28T16:50:40Z</dc:date>
    </item>
    <item>
      <title>Re: Package manager upgrade failures to certain sites</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/package-manager-upgrade-failures-to-certain-sites/m-p/1226891#M5806</link>
      <description>&lt;P&gt;Thanks for sharing this, Brian. Sounds like you've been doing some serious deep tracking—like trying to find a parcel with a UMAC tracking number that randomly vanishes and reappears! Interesting that disabling hardware offloading fixed it. We've seen similar intermittent failures with package managers, but nothing consistent enough to pin down. Definitely keeping an eye on this thread for updates!&lt;/P&gt;</description>
      <pubDate>Fri, 18 Apr 2025 10:25:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/package-manager-upgrade-failures-to-certain-sites/m-p/1226891#M5806</guid>
      <dc:creator>daniel0021</dc:creator>
      <dc:date>2025-04-18T10:25:18Z</dc:date>
    </item>
  </channel>
</rss>

