<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Software Update Issue in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/software-update-issue/m-p/6491#M4741</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Moe,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do you have asymmetric flow in your environment.&amp;nbsp; There has been couple of changes in the way firewall handles Asymmetric traffic with 6.0.5-h3. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Before upgrading again, run following commands to ensure continuity:&lt;/P&gt;&lt;P&gt;set deviceconfig setting tcp asymmetric-path bypass&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you also have zone protection, run following commands as well :&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; font-size: 12.7272720336914px;"&gt;set network profiles zone-protection-profile &amp;lt;profile-name&amp;gt; asymmetric-path [bypass | global]&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; font-size: 12.7272720336914px;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; font-size: 12.7272720336914px;"&gt;Hope this helps. Thank you.&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 13 Oct 2014 13:17:14 GMT</pubDate>
    <dc:creator>ssharma</dc:creator>
    <dc:date>2014-10-13T13:17:14Z</dc:date>
    <item>
      <title>Software Update Issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/software-update-issue/m-p/6490#M4740</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Last month I upgraded to 6.0.4 with no issues.&amp;nbsp; I upgraded my primary, then upgraded the secondary five days later. Again, no problems.&lt;/P&gt;&lt;P&gt;When I upgraded to 6.0.5 h3 (this past weekend), the PA would not pass traffic. I returned to 6.0.4 and traffic restored. I then tried 6.0.5 and had the same problem - no traffic.&lt;/P&gt;&lt;P&gt;I followed the same procedures as I did with the upgrade to 6.0.4.&lt;/P&gt;&lt;P&gt;Any ideas?&lt;/P&gt;&lt;P&gt;Thanks as always.&lt;/P&gt;&lt;P&gt;//moe&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 13 Oct 2014 12:44:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/software-update-issue/m-p/6490#M4740</guid>
      <dc:creator>VSU_ITSEC</dc:creator>
      <dc:date>2014-10-13T12:44:05Z</dc:date>
    </item>
    <item>
      <title>Re: Software Update Issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/software-update-issue/m-p/6491#M4741</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Moe,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do you have asymmetric flow in your environment.&amp;nbsp; There has been couple of changes in the way firewall handles Asymmetric traffic with 6.0.5-h3. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Before upgrading again, run following commands to ensure continuity:&lt;/P&gt;&lt;P&gt;set deviceconfig setting tcp asymmetric-path bypass&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you also have zone protection, run following commands as well :&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; font-size: 12.7272720336914px;"&gt;set network profiles zone-protection-profile &amp;lt;profile-name&amp;gt; asymmetric-path [bypass | global]&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; font-size: 12.7272720336914px;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; font-size: 12.7272720336914px;"&gt;Hope this helps. Thank you.&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 13 Oct 2014 13:17:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/software-update-issue/m-p/6491#M4741</guid>
      <dc:creator>ssharma</dc:creator>
      <dc:date>2014-10-13T13:17:14Z</dc:date>
    </item>
    <item>
      <title>Re: Software Update Issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/software-update-issue/m-p/6492#M4742</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;interesting that you have the issue with 6.0.5 also&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 13 Oct 2014 13:21:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/software-update-issue/m-p/6492#M4742</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2014-10-13T13:21:07Z</dc:date>
    </item>
    <item>
      <title>Re: Software Update Issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/software-update-issue/m-p/6493#M4743</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Here is link to Release note:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://downloads.paloaltonetworks.com/software/PAN-OS-6.0.5-h3-RN.pdf?__gda__=1413249439_2154724505c33cce6048c0944661a7d3" title="https://downloads.paloaltonetworks.com/software/PAN-OS-6.0.5-h3-RN.pdf?__gda__=1413249439_2154724505c33cce6048c0944661a7d3"&gt;https://downloads.paloaltonetworks.com/software/PAN-OS-6.0.5-h3-RN.pdf?__gda__=1413249439_2154724505c33cce6048c0944661a7…&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And note mentioning changes in the behavior :&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"&lt;/P&gt;&lt;P&gt;Note If you have asymmetric routes in your network, before upgrading to 6.0.5-h3, use &lt;/P&gt;&lt;P&gt;the following command to ensure session continuity: &lt;/P&gt;&lt;P&gt;set deviceconfig setting tcp asymmetric-path bypass&lt;/P&gt;&lt;P&gt;And, if you have attached a zone protection profile, you must also use the &lt;/P&gt;&lt;P&gt;following command: &lt;/P&gt;&lt;P&gt;set network profiles zone-protection-profile &amp;lt;profile-name&amp;gt; asymmetric-path &lt;/P&gt;&lt;P&gt;[bypass | global]. "&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 13 Oct 2014 13:21:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/software-update-issue/m-p/6493#M4743</guid>
      <dc:creator>ssharma</dc:creator>
      <dc:date>2014-10-13T13:21:15Z</dc:date>
    </item>
    <item>
      <title>Re: Software Update Issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/software-update-issue/m-p/6494#M4744</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We are symetric right now.&amp;nbsp; Will be asymetric in a couple months.&amp;nbsp; &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 13 Oct 2014 15:49:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/software-update-issue/m-p/6494#M4744</guid>
      <dc:creator>VSU_ITSEC</dc:creator>
      <dc:date>2014-10-13T15:49:24Z</dc:date>
    </item>
    <item>
      <title>Re: Software Update Issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/software-update-issue/m-p/6495#M4745</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;In that case you will need to configure those commands prior to upgrade. That should work, if not then you can contact support for further troubleshooting. Thank you.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 13 Oct 2014 15:51:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/software-update-issue/m-p/6495#M4745</guid>
      <dc:creator>ssharma</dc:creator>
      <dc:date>2014-10-13T15:51:23Z</dc:date>
    </item>
    <item>
      <title>Re: Software Update Issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/software-update-issue/m-p/6496#M4746</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;will the command disrupt traffic before the software is updated? What i'm asking is, can I do this now, and upgrade later?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 13 Oct 2014 15:53:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/software-update-issue/m-p/6496#M4746</guid>
      <dc:creator>VSU_ITSEC</dc:creator>
      <dc:date>2014-10-13T15:53:34Z</dc:date>
    </item>
    <item>
      <title>Re: Software Update Issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/software-update-issue/m-p/6497#M4747</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;There should not be any disruption with the command, however I would suggest configuring these command just prior to upgrade. Everything should work as expected until 6.0.5. Above condition only applies if you are on 6.0.5-h3 or above and you have asymmetric traffic in your environment. Thank you.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 13 Oct 2014 16:00:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/software-update-issue/m-p/6497#M4747</guid>
      <dc:creator>ssharma</dc:creator>
      <dc:date>2014-10-13T16:00:49Z</dc:date>
    </item>
    <item>
      <title>Re: Software Update Issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/software-update-issue/m-p/6498#M4748</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;What about for right now?&amp;nbsp; My traffic is symetric, yet I had no traffic. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 13 Oct 2014 19:03:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/software-update-issue/m-p/6498#M4748</guid>
      <dc:creator>VSU_ITSEC</dc:creator>
      <dc:date>2014-10-13T19:03:31Z</dc:date>
    </item>
    <item>
      <title>Re: Software Update Issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/software-update-issue/m-p/6499#M4749</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If you upgrade to 6.0.5-H3 and you did not have asymmetric traffic and it did not work, that would be something not expected. I would suggest opening a case before next upgrade attempt so that a resource can work with you to verify the issue. It would be hard to tell why traffic did not work. If you look at the monitor logs during the upgrade and see both side traffic was seen (Bytes Sent/Bytes received). I believe you did wait until Auto Commit was completed. Were you able to ping inside interface during the incident? Were you able to ping outside sourcing from one&amp;nbsp; of the inside interface. There can be many variables why it caused that, but 6.0.5-h3 alone would not be issues as we have seen successful upgrades as well. Hope this helps. Thank you.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 13 Oct 2014 19:08:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/software-update-issue/m-p/6499#M4749</guid>
      <dc:creator>ssharma</dc:creator>
      <dc:date>2014-10-13T19:08:59Z</dc:date>
    </item>
    <item>
      <title>Re: Software Update Issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/software-update-issue/m-p/6500#M4750</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I was pinging the management interface (didn't consider the inside int) and google.com while the firewall rebooted. The management came back up and i could log back into the device. the ping out to google didn't come back.&amp;nbsp; I have two firewalls in HA active-pasive mode. I was updating the primary. (the secondary's inside/outside interfaces are currently not connected to switch)&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 13 Oct 2014 19:36:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/software-update-issue/m-p/6500#M4750</guid>
      <dc:creator>VSU_ITSEC</dc:creator>
      <dc:date>2014-10-13T19:36:24Z</dc:date>
    </item>
    <item>
      <title>Re: Software Update Issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/software-update-issue/m-p/6501#M4751</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes, management interface will respond. But after reboot, auto commit is happens on the device. During this time all dataplane ports would not respond or pass any traffic. Depending on the Hardware of the device and amount of configuration it might take time for auto commit to complete. "show jobs all"&amp;nbsp; shows progress for the auto commit. While updating, secondary will take over as active, and since interfaces are not connected to switch the traffic will be basically blackholed. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Next time during the upgrade monitor the auto-commit, and once it is done, make the primary (connected to switch) active device again and see if that resolves the issue. Thank you.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 13 Oct 2014 19:42:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/software-update-issue/m-p/6501#M4751</guid>
      <dc:creator>ssharma</dc:creator>
      <dc:date>2014-10-13T19:42:35Z</dc:date>
    </item>
  </channel>
</rss>

