<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Quick Note on 8.1.0 Deployments in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/quick-note-on-8-1-0-deployments/m-p/205231#M60281</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/47963"&gt;@CaviumKeith&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;I really wish spellcheck on Live was automatic like most other message boards. I've sent the original post through Word, so hopefully the spelling is at least somewhat correct. Honestly though, I don't think many management personnel are visiting the Live forums.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 13 Mar 2018 19:45:33 GMT</pubDate>
    <dc:creator>BPry</dc:creator>
    <dc:date>2018-03-13T19:45:33Z</dc:date>
    <item>
      <title>Quick Note on 8.1.0 Deployments</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/quick-note-on-8-1-0-deployments/m-p/204736#M60197</link>
      <description>&lt;P&gt;Since its release we've seen an uptick in folks deploying 8.1.0 to their firewalls, and that's a great thing. I just want to throw out a word of caution before doing so however; while 8.1.0 is one of the most stable base releases Palo Alto Networks has published, you need to do your homework before deploying this in any environment.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;LAB Devices:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;If you have access to any sort of LAB equipment, this is where you should be installing 8.1.0. Start testing your configuration in a LAB environment so that you can have a knowledgeable estimate of when you feel comfortable deploying 8.1 to your production equipment.&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you happen to utilize your LAB equipment in a Change Management process, take note that you are running a different version of PAN-OS when you actually test changes. Something that didn't work in your 8.1.0 LAB may work perfectly fine on 8.0.8 that you have running on your production equipment. On the other hand, something that works out perfectly fine on 8.1.0, may not function on 8.0.8 due to a bug being patched between versions.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Production Devices:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;If you do not have access to LAB equipment to verify that your production configuration will actually fully function on 8.1.0, I would personally&amp;nbsp;&lt;EM&gt;highly&lt;/EM&gt;&amp;nbsp;advise you to keep 8.1.0 off your production equipment.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Limitations of 8.1.0 are fairly small, however there are 13 pages of known issues within 8.1.0 along with 3 known issues specific to a WF-500 appliance. Before you contend with loading 8.1.0 on production equipment you should take the time to go through all of these known issues and decide if your environment would actually experience them and if you can work around them until they are patched in future maintenance releases. Causing an outage because you want to utilize the awesome SSL Decryption Broker, or the awesome new hit counters, is likely not going to go well.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Generally this boils down to following Palo Alto's recommended upgrade procedure and just doing your own due diligence before upgrading to 8.1. I think there are a few people that are getting wrapped up in the truly amazing feature improvements of 8.1, and throwing best practices out the window. If you don't have LAB equipment to properly test things out, let those of us that do find all of the bugs before causing an outage due to wanting a new software upgrade quickly.&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you truly want 8.1 and just simply can't wait to upgrade, I'd at least make a post here about what your configuration looks like prior to upgrading. We have a lot of people within these forums that have been running 8.1.0 since the beta was released on LAB equipment and home deployments that can likely take a glance at what you are doing and at least give you some real-world experience on what you should expect.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 13 Mar 2018 19:43:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/quick-note-on-8-1-0-deployments/m-p/204736#M60197</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2018-03-13T19:43:19Z</dc:date>
    </item>
    <item>
      <title>Re: Quick Note on 8.1.0 Deployments</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/quick-note-on-8-1-0-deployments/m-p/205230#M60280</link>
      <description>&lt;P&gt;Great Advice of course.&amp;nbsp; Management at my company is chomping at the bit for a more secure Linux deployment of Global Protect.&amp;nbsp; My test device has it working well, removing the need for the X-Auth PSK and implementing a Public Certificate authentication mechanism was key.&amp;nbsp; Unfortunately, that part isn't supported on the pre 8.1 OS as "Linux" isn't a valid OS option on the Portal Config.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;PS, use spell check!&amp;nbsp; Some people in management see misspelling and the author's credibility is instantly diminished regardless of the years of experience.&lt;/P&gt;</description>
      <pubDate>Tue, 13 Mar 2018 19:41:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/quick-note-on-8-1-0-deployments/m-p/205230#M60280</guid>
      <dc:creator>CaviumKeith</dc:creator>
      <dc:date>2018-03-13T19:41:23Z</dc:date>
    </item>
    <item>
      <title>Re: Quick Note on 8.1.0 Deployments</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/quick-note-on-8-1-0-deployments/m-p/205231#M60281</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/47963"&gt;@CaviumKeith&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;I really wish spellcheck on Live was automatic like most other message boards. I've sent the original post through Word, so hopefully the spelling is at least somewhat correct. Honestly though, I don't think many management personnel are visiting the Live forums.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 13 Mar 2018 19:45:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/quick-note-on-8-1-0-deployments/m-p/205231#M60281</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2018-03-13T19:45:33Z</dc:date>
    </item>
    <item>
      <title>Re: Quick Note on 8.1.0 Deployments</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/quick-note-on-8-1-0-deployments/m-p/205237#M60283</link>
      <description>&lt;P&gt;I've been playing with PAN-OS 8.1 on a PA-200 and a PA-220 of which there is a site-to-site VPN tunnel between them.&amp;nbsp; The upgrade went well overall (from 8.0.8 to 8.1.0) however I have run into two things, one more troubling than the other:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;LDAP - After the&amp;nbsp;update&amp;nbsp;to 8.1 my the LDAP attribute is required and if empty LDAP authentication will fail.&amp;nbsp; In our case I needed to add &lt;EM&gt;sAMAccountName&lt;/EM&gt; to complete one phase of authentication for my Global Protect clients.&lt;BR /&gt;&lt;BR /&gt;&lt;/LI&gt;&lt;LI&gt;Site-to-Site VPN - After the update to 8.1, traffic accross the IPSec site-to-site VPN is sluggish and simple functions such as logging into Active Directory no longer work as it did before.&amp;nbsp; I have even went as far as to create a special rule to disable server response inspection for SMB traffic yet no dice.&amp;nbsp; Other protocols such as HTTPS, RDP, SSH all seem to run fine yet Microsoft workstations have issues logging into the domain.&amp;nbsp; Overall it seems to be a bit slower than before as well.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;[Update] As of today they can read from shares but cannot write to them.&amp;nbsp; The intersting thing is that this seems to only affect Microsoft SMB shares via the domain controller.&amp;nbsp; SMB shares on other devices (such as QNAP which I think uses Samba) work without issue.&amp;nbsp; Time to open a support case.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;There are the two issues that I have expereince so far.&amp;nbsp; The VPN issue is troubling and I may have to revert to 8.0.8 if i cant figure this one out.&amp;nbsp; If anyone has any ideas, I would gladly listen to them.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;-Matt&lt;/P&gt;</description>
      <pubDate>Wed, 14 Mar 2018 19:39:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/quick-note-on-8-1-0-deployments/m-p/205237#M60283</guid>
      <dc:creator>mlinsemier</dc:creator>
      <dc:date>2018-03-14T19:39:04Z</dc:date>
    </item>
    <item>
      <title>Re: Quick Note on 8.1.0 Deployments</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/quick-note-on-8-1-0-deployments/m-p/205815#M60409</link>
      <description>&lt;P&gt;Did you get any specific details from support on the SMB issue?&amp;nbsp; Perhaps a way to work around it without downgrade?&lt;/P&gt;</description>
      <pubDate>Fri, 16 Mar 2018 00:30:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/quick-note-on-8-1-0-deployments/m-p/205815#M60409</guid>
      <dc:creator>evanm01</dc:creator>
      <dc:date>2018-03-16T00:30:31Z</dc:date>
    </item>
    <item>
      <title>Re: Quick Note on 8.1.0 Deployments</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/quick-note-on-8-1-0-deployments/m-p/205941#M60448</link>
      <description>&lt;P&gt;After talking to support there were several other cases open against the same SMB issues.&amp;nbsp; Myself and others tried many workarounds, including application override, which did not to resolve the issue.&amp;nbsp; I ended up downgrading to PAN OS 8.0.8 and the issue was resolved.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;While I know this is the initial release of a new version, it seems that a bug in something as widely used as SMB would be caught early on in internal and beta testing.&amp;nbsp; Most people using 8.1 as an edge firewall (where SMB is not used) or are not using a VPN would probably have no issues with this release.&amp;nbsp; I still feel like Palo Alto should pull this, it's a pretty big issue in my opinion.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;- Matt&lt;/P&gt;</description>
      <pubDate>Fri, 16 Mar 2018 14:15:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/quick-note-on-8-1-0-deployments/m-p/205941#M60448</guid>
      <dc:creator>mlinsemier</dc:creator>
      <dc:date>2018-03-16T14:15:04Z</dc:date>
    </item>
    <item>
      <title>Re: Quick Note on 8.1.0 Deployments</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/quick-note-on-8-1-0-deployments/m-p/205943#M60449</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/7143"&gt;@mlinsemier&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;It's a noted issue and those that discuss upgrading to 8.1.0&amp;nbsp;&lt;EM&gt;should&lt;/EM&gt; be alerted to this issue if the SE is decent. This actually has been kicking around in the Beta forums for a while now, so it was a known issue that for some reason doesn't appear to have been documented in the release documentation.&amp;nbsp;&lt;/P&gt;&lt;P&gt;It's important to note here that Palo Alto Networks&amp;nbsp;&lt;EM&gt;&lt;STRONG&gt;isn't&lt;/STRONG&gt;&lt;/EM&gt; recommending people actually upgrade to 8.1.0; that's an important aspect that I think people need to be more mindful of. It is currently &lt;STRONG&gt;not&amp;nbsp;&lt;/STRONG&gt;a recommended release.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 16 Mar 2018 14:20:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/quick-note-on-8-1-0-deployments/m-p/205943#M60449</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2018-03-16T14:20:42Z</dc:date>
    </item>
    <item>
      <title>Re: Quick Note on 8.1.0 Deployments</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/quick-note-on-8-1-0-deployments/m-p/205945#M60451</link>
      <description>&lt;P&gt;The fact that this isn't in the Known Issues is a huge problem, especially if it was brought up in beta discussions, "recommended release" or not.&lt;/P&gt;</description>
      <pubDate>Fri, 16 Mar 2018 14:22:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/quick-note-on-8-1-0-deployments/m-p/205945#M60451</guid>
      <dc:creator>evanm01</dc:creator>
      <dc:date>2018-03-16T14:22:48Z</dc:date>
    </item>
    <item>
      <title>Re: Quick Note on 8.1.0 Deployments</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/quick-note-on-8-1-0-deployments/m-p/205957#M60457</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&lt;/P&gt;&lt;P&gt;I 100% agree with what you are saying that customers should engage their SE and be cautious with brand new releases, but on the flip side Palo Alto themselves are equally responsible for media blasting "NEW PAN-OS 8.1... GET IT NOW!" and "LOOK AT THESE NEW FEATURES" in which I there aren't a bunch of caution signs displayed.&amp;nbsp; It's almost like Palo Alto is doing the "LOOK AT US, WE ARE BETTER THEN OUR COMPETITION" but then in small fine print it says "... but really don't install this until 8.1.3".&amp;nbsp; &amp;nbsp;Don't get me wrong, I love our Palo Alto products and woulnd't recommend anything else, but maybe they should adopt an early development title or something.&lt;/P&gt;</description>
      <pubDate>Fri, 16 Mar 2018 14:59:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/quick-note-on-8-1-0-deployments/m-p/205957#M60457</guid>
      <dc:creator>mlinsemier</dc:creator>
      <dc:date>2018-03-16T14:59:03Z</dc:date>
    </item>
    <item>
      <title>Re: Quick Note on 8.1.0 Deployments</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/quick-note-on-8-1-0-deployments/m-p/205968#M60460</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/7143"&gt;@mlinsemier&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Yup. Marketing and Sales are pretty heavy hitting departments in any company though, and they generally like to push NEW.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 16 Mar 2018 15:03:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/quick-note-on-8-1-0-deployments/m-p/205968#M60460</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2018-03-16T15:03:00Z</dc:date>
    </item>
    <item>
      <title>Re: Quick Note on 8.1.0 Deployments</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/quick-note-on-8-1-0-deployments/m-p/206180#M60516</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I agree. I have the same issues after upgrading to 8.1.0. Then I have to downgrade too. Thanks.&lt;/P&gt;</description>
      <pubDate>Sun, 18 Mar 2018 15:01:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/quick-note-on-8-1-0-deployments/m-p/206180#M60516</guid>
      <dc:creator>Aiace</dc:creator>
      <dc:date>2018-03-18T15:01:38Z</dc:date>
    </item>
    <item>
      <title>Re: Quick Note on 8.1.0 Deployments</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/quick-note-on-8-1-0-deployments/m-p/206706#M60648</link>
      <description>&lt;P&gt;Had the same issues with 8.1.0 and went back to 8.0.8.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We experienced slow/non-working domain logons and SMB/CIFS/DFS Shares.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If I ran "&lt;EM&gt;&lt;STRONG&gt;show session all filter state discard application ms-ds-smbv3&lt;/STRONG&gt;&lt;/EM&gt;" I had lots of sessions discarded. If I looked in detail on one of those sessions with &lt;EM&gt;&lt;STRONG&gt;show session id [session-id]&lt;/STRONG&gt;&lt;/EM&gt; I could see that they were discarded due to "resources-unavailable".&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Some users report that 'Application Override' might be a way forward until the issue is fixed.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/General-Topics/PAN-OS-8-1-0-SMB-Issues/m-p/205760" target="_blank"&gt;https://live.paloaltonetworks.com/t5/General-Topics/PAN-OS-8-1-0-SMB-Issues/m-p/205760&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 21 Mar 2018 16:03:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/quick-note-on-8-1-0-deployments/m-p/206706#M60648</guid>
      <dc:creator>teoder</dc:creator>
      <dc:date>2018-03-21T16:03:53Z</dc:date>
    </item>
    <item>
      <title>Re: Quick Note on 8.1.0 Deployments</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/quick-note-on-8-1-0-deployments/m-p/210989#M61576</link>
      <description>&lt;P&gt;The 8.1.0 Interface is terribly buggy.&amp;nbsp; I would advise EVERYONE to not use it until they at least patch it once.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;NAT and Security rules do not highlight correctly at intervals, and it has already cost us production time as we were attempting to modify one NAT rule (after highlighting it) and having it return a different one.&amp;nbsp; All browsers show this issue too.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Its a bad release, and I wish PA would have done a better job of QC'ing it instead of expecting the rest of us to "Fix the airplane before it hits the ground".&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Ususally PA is good about this.&amp;nbsp; But this one is a clear miss, and the release should be pulled.&lt;/P&gt;</description>
      <pubDate>Thu, 19 Apr 2018 16:23:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/quick-note-on-8-1-0-deployments/m-p/210989#M61576</guid>
      <dc:creator>ITSysEng</dc:creator>
      <dc:date>2018-04-19T16:23:29Z</dc:date>
    </item>
    <item>
      <title>Re: Quick Note on 8.1.0 Deployments</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/quick-note-on-8-1-0-deployments/m-p/211369#M61664</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/87171"&gt;@ITSysEng&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Its a bad release, and I wish PA would have done a better job of QC'ing it instead of expecting the rest of us to "Fix the airplane before it hits the ground".&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Ususally PA is good about this.&amp;nbsp; But this one is a clear miss, and the release should be pulled.&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Then there was 7.0.0 which was totally deferred...I think 7.0.0 still wins this "contest" haha&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Totally agree I've always thought the major releases process could use a bit of improvement.&amp;nbsp; No doubt there's push to deploy new capabilities from Palo, but like has already been mentioned; if as admins of a service, in this case a company's edge/firewall environment&amp;nbsp;the onus is on US as firewall admins to do the due diligence&amp;nbsp;to ensure the code version is stable and appropriate.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This includes dev/qa testing if need be.&amp;nbsp; If an admin wants to risk their career&amp;nbsp;because a new software release is out that's on you.&amp;nbsp; Not Palo IMO.&lt;/P&gt;</description>
      <pubDate>Mon, 23 Apr 2018 16:25:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/quick-note-on-8-1-0-deployments/m-p/211369#M61664</guid>
      <dc:creator>Brandon_Wertz</dc:creator>
      <dc:date>2018-04-23T16:25:36Z</dc:date>
    </item>
    <item>
      <title>Re: Quick Note on 8.1.0 Deployments</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/quick-note-on-8-1-0-deployments/m-p/211370#M61665</link>
      <description>&lt;P&gt;I'm hearing a target of early May for 8.1.1 roll out, so just a couple more weeks.&lt;/P&gt;</description>
      <pubDate>Mon, 23 Apr 2018 16:30:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/quick-note-on-8-1-0-deployments/m-p/211370#M61665</guid>
      <dc:creator>CaviumKeith</dc:creator>
      <dc:date>2018-04-23T16:30:09Z</dc:date>
    </item>
    <item>
      <title>Re: Quick Note on 8.1.0 Deployments</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/quick-note-on-8-1-0-deployments/m-p/211373#M61666</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/5300"&gt;@Brandon_Wertz&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I think you nailed my reaction on all of these "PAN-OS 8.1.0 is real bad; Palo should pull the release; this killed my production network". Palo Alto did not come on premise and force you to upgrade to 8.1.0, Palo Alto didn't stop supplying updates to other software versions, they didn't release hardware that only runs 8.1.0 (unlike 8.0), and Palo Alto didn't automatically install 8.1.0 to anyone's firewall.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I agree that Palo Alto should, and could, tone down the marketing around 8.1.0 until its actually hit recommended status. There are defiantly&amp;nbsp;mistakes that they've made in that regard. There shouldn't have been as much noise surrounding&amp;nbsp;the 8.1.0 release, the SMB over VPN issues experianced by users of the Beta channel should have been included in the release notes, as it was already noticed by the time 8.1.0 was offically released, and it should have been clear in all communication that it wasn't recommended you actually install it on production equipment.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In the end though it comes down to the decision that&amp;nbsp;&lt;STRONG&gt;you&lt;/STRONG&gt; made as an admin.&amp;nbsp;&lt;STRONG&gt;You&lt;/STRONG&gt; choose to run 8.1.0,&amp;nbsp;&lt;STRONG&gt;you&lt;/STRONG&gt; made the decision to run new code,&amp;nbsp;&lt;STRONG&gt;you&lt;/STRONG&gt; made the decision to prioritize&amp;nbsp;features over stability,&amp;nbsp;&lt;STRONG&gt;you&lt;/STRONG&gt; failed to QA&amp;nbsp;the code with your configuration to verify it didn't effect&amp;nbsp;&lt;STRONG&gt;your&lt;/STRONG&gt; production network.&amp;nbsp;&lt;STRONG&gt;YOU&lt;/STRONG&gt; caused an outage or a degradation&amp;nbsp;of services because&amp;nbsp;&lt;STRONG&gt;you&lt;/STRONG&gt; installed 8.1.0 on&amp;nbsp;&lt;STRONG&gt;your&lt;/STRONG&gt; production equipment without validating it worked for&amp;nbsp;&lt;STRONG&gt;you&amp;nbsp;&lt;/STRONG&gt;and&amp;nbsp;&lt;STRONG&gt;your&lt;/STRONG&gt; company.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 23 Apr 2018 17:32:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/quick-note-on-8-1-0-deployments/m-p/211373#M61666</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2018-04-23T17:32:03Z</dc:date>
    </item>
  </channel>
</rss>

