<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Upgrade to 5.x - the good, the bad, the ugly? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/upgrade-to-5-x-the-good-the-bad-the-ugly/m-p/17328#M12651</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Major pain point for us: In 5.0.4, DHCP Relay, and possibly all UDP proxying, is broken for VLAN sub-interfaces (both L2 and L3). Worked around by running DHCP on the firewall itself, but since PAN-OS can't run a DHCP server on a L2 interface, I had to re-architect the network to change all L2 interfaces to L3. Support also suggested rolling back to 4.1 or 5.0.2, but wouldn't guarantee that it would work.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sat, 11 May 2013 02:11:55 GMT</pubDate>
    <dc:creator>rgraves</dc:creator>
    <dc:date>2013-05-11T02:11:55Z</dc:date>
    <item>
      <title>Upgrade to 5.x - the good, the bad, the ugly?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/upgrade-to-5-x-the-good-the-bad-the-ugly/m-p/17326#M12649</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;OK, one for you guys who have upgraded to the 5.x stream.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Ignoring the steady furore over the UserID agent and CPU issues, what are the advantages/disadvantages of upgrading from 4.1.x to 5.0.x?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a single HA pair, no Panorama, no Wildfire subscription, using both IPSec and SSL/Global protect VPN's.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Anyone willing to comment?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 19 Mar 2013 00:43:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/upgrade-to-5-x-the-good-the-bad-the-ugly/m-p/17326#M12649</guid>
      <dc:creator>darren_g</dc:creator>
      <dc:date>2013-03-19T00:43:48Z</dc:date>
    </item>
    <item>
      <title>Re: Upgrade to 5.x - the good, the bad, the ugly?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/upgrade-to-5-x-the-good-the-bad-the-ugly/m-p/17327#M12650</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;These are the main drivers for us to upgrade to 5.x&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1. the return to sender for policy based routing.&lt;/P&gt;&lt;P&gt;2. application dependency &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Ernest&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 19 Mar 2013 02:04:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/upgrade-to-5-x-the-good-the-bad-the-ugly/m-p/17327#M12650</guid>
      <dc:creator>nextgenhappines</dc:creator>
      <dc:date>2013-03-19T02:04:05Z</dc:date>
    </item>
    <item>
      <title>Re: Upgrade to 5.x - the good, the bad, the ugly?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/upgrade-to-5-x-the-good-the-bad-the-ugly/m-p/17328#M12651</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Major pain point for us: In 5.0.4, DHCP Relay, and possibly all UDP proxying, is broken for VLAN sub-interfaces (both L2 and L3). Worked around by running DHCP on the firewall itself, but since PAN-OS can't run a DHCP server on a L2 interface, I had to re-architect the network to change all L2 interfaces to L3. Support also suggested rolling back to 4.1 or 5.0.2, but wouldn't guarantee that it would work.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 11 May 2013 02:11:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/upgrade-to-5-x-the-good-the-bad-the-ugly/m-p/17328#M12651</guid>
      <dc:creator>rgraves</dc:creator>
      <dc:date>2013-05-11T02:11:55Z</dc:date>
    </item>
    <item>
      <title>Re: Upgrade to 5.x - the good, the bad, the ugly?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/upgrade-to-5-x-the-good-the-bad-the-ugly/m-p/17329#M12652</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;As a sidenote, did this feature work in 5.0.3? And do you have a bugid available for this case?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 11 May 2013 04:04:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/upgrade-to-5-x-the-good-the-bad-the-ugly/m-p/17329#M12652</guid>
      <dc:creator>mikand</dc:creator>
      <dc:date>2013-05-11T04:04:46Z</dc:date>
    </item>
    <item>
      <title>Re: Upgrade to 5.x - the good, the bad, the ugly?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/upgrade-to-5-x-the-good-the-bad-the-ugly/m-p/17330#M12653</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Regarding running DHCP server on an L3 interface vs. L2 interface, you might not need to completely change all L2 interfaces to L3.&amp;nbsp; You could instead just add one L3 interface (if you have any extra), configure DHCP server on it, and physically plug it in to your existing L2 network without affecting the current L2 config.&amp;nbsp; You may even be able to do this with an L3 VLAN logical interface connected to the L2 VLAN forwarding object depending on your configuration.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kelly&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 11 May 2013 06:03:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/upgrade-to-5-x-the-good-the-bad-the-ugly/m-p/17330#M12653</guid>
      <dc:creator>kbrazil</dc:creator>
      <dc:date>2013-05-11T06:03:57Z</dc:date>
    </item>
    <item>
      <title>Re: Upgrade to 5.x - the good, the bad, the ugly?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/upgrade-to-5-x-the-good-the-bad-the-ugly/m-p/17331#M12654</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I upgraded directly from 4.1 to 5.0.4. (First tier) tech support said that level 2/3 tech support had seen the problem starting in 5.0.3, but did not volunteer a bugid.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;@kbrazil: Yes, I could have saved myself the tedious and error-prone L2-to-L3 interface conversion in a couple different ways. But the original reason for going L2 had passed anyway.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 14 May 2013 02:23:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/upgrade-to-5-x-the-good-the-bad-the-ugly/m-p/17331#M12654</guid>
      <dc:creator>rgraves</dc:creator>
      <dc:date>2013-05-14T02:23:10Z</dc:date>
    </item>
  </channel>
</rss>

