<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PA3020 upgrade failure from 8.0.11-h1 to 8.1.9-h4 - FIPS  failure error in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/pa3020-upgrade-failure-from-8-0-11-h1-to-8-1-9-h4-fips-failure/m-p/298960#M78295</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/16592"&gt;@Remo&lt;/a&gt;&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&amp;nbsp; guys we tried your suggestion for the upgrade path.&lt;/P&gt;&lt;P&gt;we downloaded and installed 8.0.20 and rebooted. successfully upgrade to 8.0.20&lt;/P&gt;&lt;P&gt;downloaded and installed 8.1.0 and rebooted. successfullyupgraded to 8.1.0&lt;/P&gt;&lt;P&gt;downloaded and installed 8.1.10 and rebooted ---&amp;gt; failed to upgrade to 8.1.10 and went to maintenance mode.&lt;/P&gt;&lt;P&gt;we were able to revert back to 8.1.0 and we are now back online with 8.1.0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;we have already submitted the tech support file to TAC and waiting for their advice.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;in the meantime, do you guys have any idea or experience with this kind of scenario? we are stuck in 8.1.0&lt;/P&gt;</description>
    <pubDate>Sat, 16 Nov 2019 15:12:52 GMT</pubDate>
    <dc:creator>Egghead_Systems</dc:creator>
    <dc:date>2019-11-16T15:12:52Z</dc:date>
    <item>
      <title>PA3020 upgrade failure from 8.0.11-h1 to 8.1.9-h4 - FIPS  failure error</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa3020-upgrade-failure-from-8-0-11-h1-to-8-1-9-h4-fips-failure/m-p/297512#M78073</link>
      <description>&lt;DIV class="lia-quilt-column lia-quilt-column-18 lia-quilt-column-left lia-quilt-column-main-left"&gt;&lt;DIV class="lia-quilt-column-alley lia-quilt-column-alley-left"&gt;&lt;DIV class="lia-message-body lia-component-message-view-widget-body lia-component-body-signature-highlight-escalation lia-component-message-view-widget-body-signature-highlight-escalation"&gt;&lt;DIV class="lia-message-body-content"&gt;&lt;P&gt;We are experiencing an upgrade error/failure when we try to upgrade PA3020 from 8.0.11-h1 to 8.1.9-h4.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When our customer tried to upgrade from 8.0.11-h1 to 8.1.9-h4; their PA3020 went to Maintenance Mode after installing and rebooting .&lt;/P&gt;&lt;P&gt;The Maintenance Mode simply stated that there is a "FIPS failure".&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The upgrade steps that we followed are:&lt;/P&gt;&lt;P&gt;a) Download 8.1.0 (base) , without installing&lt;/P&gt;&lt;P&gt;b) Download and Install 8.1.9-h4&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;After we did step b above the PA3020 rebooted and went straight to maintenance mode with error "FIPS failure"&lt;/P&gt;&lt;P&gt;Luckily, we were able to revert back again to 8.0.11-h1. But , we still need to upgrade to 8.1.x, becuase 8.0.x is already EOL.&lt;/P&gt;&lt;P&gt;We have already contacted palo alto TAC and are now waiting for their reply.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;While we are waiting for pan tac reply, has anybody ever experienced a FIPS failure upgrade error like ours? if so, How did you guys resolve the FIPS failure error?&lt;/P&gt;&lt;P&gt;any feedback would be great, thanks&lt;/P&gt;&lt;P&gt;glenn&lt;/P&gt;&lt;P&gt;egghead systems&lt;/P&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class="lia-quilt-column lia-quilt-column-06 lia-quilt-column-right lia-quilt-column-main-right"&gt;&lt;DIV class="lia-quilt-column-alley lia-quilt-column-alley-right"&gt;&lt;DIV class="lia-panel lia-panel-standard MessageTagsTaplet Chrome lia-component-message-view-widget-tags"&gt;&lt;DIV class="lia-decoration-border"&gt;&lt;DIV class="lia-decoration-border-top"&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class="lia-decoration-border-content"&gt;&lt;DIV&gt;&lt;DIV class="lia-panel-heading-bar-wrapper"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;</description>
      <pubDate>Sun, 10 Nov 2019 11:26:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa3020-upgrade-failure-from-8-0-11-h1-to-8-1-9-h4-fips-failure/m-p/297512#M78073</guid>
      <dc:creator>Egghead_Systems</dc:creator>
      <dc:date>2019-11-10T11:26:49Z</dc:date>
    </item>
    <item>
      <title>Re: PA3020 upgrade failure from 8.0.11-h1 to 8.1.9-h4 - FIPS  failure error</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa3020-upgrade-failure-from-8-0-11-h1-to-8-1-9-h4-fips-failure/m-p/297532#M78079</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/19471"&gt;@Egghead_Systems&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;What was your actual upgrade path. If you followed recommendation you should have installed the latest maintenance release prior to installing 8.1.0 and attempting to boot into your targeted maintenance release.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also just to point out, 8.1.10 is the preferred release at the moment.&lt;/P&gt;</description>
      <pubDate>Sun, 10 Nov 2019 17:36:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa3020-upgrade-failure-from-8-0-11-h1-to-8-1-9-h4-fips-failure/m-p/297532#M78079</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2019-11-10T17:36:23Z</dc:date>
    </item>
    <item>
      <title>Re: PA3020 upgrade failure from 8.0.11-h1 to 8.1.9-h4 - FIPS  failure error</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa3020-upgrade-failure-from-8-0-11-h1-to-8-1-9-h4-fips-failure/m-p/297533#M78080</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/19471"&gt;@Egghead_Systems&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When upgrading firewalls - specially the older hardware from paloalto like the 3000 series - you should follow the official recommendation for this. For you this means:&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Download and install the latest maintenance release (8.0.20)&lt;/LI&gt;&lt;LI&gt;Download and &lt;STRONG&gt;install&lt;/STRONG&gt; the base image 8.1.0&lt;/LI&gt;&lt;LI&gt;Download and install the target release. In your case 8.1.9-h4&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;This way you shouldn't have any problems and to be eveen more sure try a reboot prior to even installing the latest maintenance release as 8.0.11 sounds like your firewall is already running with this quite a while.&lt;/P&gt;</description>
      <pubDate>Sun, 10 Nov 2019 17:36:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa3020-upgrade-failure-from-8-0-11-h1-to-8-1-9-h4-fips-failure/m-p/297533#M78080</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2019-11-10T17:36:40Z</dc:date>
    </item>
    <item>
      <title>Re: PA3020 upgrade failure from 8.0.11-h1 to 8.1.9-h4 - FIPS  failure error</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa3020-upgrade-failure-from-8-0-11-h1-to-8-1-9-h4-fips-failure/m-p/298960#M78295</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/16592"&gt;@Remo&lt;/a&gt;&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&amp;nbsp; guys we tried your suggestion for the upgrade path.&lt;/P&gt;&lt;P&gt;we downloaded and installed 8.0.20 and rebooted. successfully upgrade to 8.0.20&lt;/P&gt;&lt;P&gt;downloaded and installed 8.1.0 and rebooted. successfullyupgraded to 8.1.0&lt;/P&gt;&lt;P&gt;downloaded and installed 8.1.10 and rebooted ---&amp;gt; failed to upgrade to 8.1.10 and went to maintenance mode.&lt;/P&gt;&lt;P&gt;we were able to revert back to 8.1.0 and we are now back online with 8.1.0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;we have already submitted the tech support file to TAC and waiting for their advice.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;in the meantime, do you guys have any idea or experience with this kind of scenario? we are stuck in 8.1.0&lt;/P&gt;</description>
      <pubDate>Sat, 16 Nov 2019 15:12:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa3020-upgrade-failure-from-8-0-11-h1-to-8-1-9-h4-fips-failure/m-p/298960#M78295</guid>
      <dc:creator>Egghead_Systems</dc:creator>
      <dc:date>2019-11-16T15:12:52Z</dc:date>
    </item>
    <item>
      <title>Re: PA3020 upgrade failure from 8.0.11-h1 to 8.1.9-h4 - FIPS  failure error</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa3020-upgrade-failure-from-8-0-11-h1-to-8-1-9-h4-fips-failure/m-p/298970#M78298</link>
      <description>&lt;P&gt;Let us know what tech finds out?&lt;/P&gt;</description>
      <pubDate>Sat, 16 Nov 2019 17:39:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa3020-upgrade-failure-from-8-0-11-h1-to-8-1-9-h4-fips-failure/m-p/298970#M78298</guid>
      <dc:creator>MP18</dc:creator>
      <dc:date>2019-11-16T17:39:20Z</dc:date>
    </item>
    <item>
      <title>Re: PA3020 upgrade failure from 8.0.11-h1 to 8.1.9-h4 - FIPS  failure error</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa3020-upgrade-failure-from-8-0-11-h1-to-8-1-9-h4-fips-failure/m-p/299135#M78331</link>
      <description>&lt;P&gt;Strange situarion. I don't have experience with this szenario, but what I would try in this case is a factory reset of the firewall, re-import the config and then give it another try &lt;span class="lia-unicode-emoji" title=":face_with_tongue:"&gt;😛&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 18 Nov 2019 16:32:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa3020-upgrade-failure-from-8-0-11-h1-to-8-1-9-h4-fips-failure/m-p/299135#M78331</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2019-11-18T16:32:18Z</dc:date>
    </item>
    <item>
      <title>Re: PA3020 upgrade failure from 8.0.11-h1 to 8.1.9-h4 - FIPS  failure error</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa3020-upgrade-failure-from-8-0-11-h1-to-8-1-9-h4-fips-failure/m-p/299214#M78343</link>
      <description>&lt;P&gt;I like this idea.&lt;/P&gt;</description>
      <pubDate>Mon, 18 Nov 2019 20:53:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa3020-upgrade-failure-from-8-0-11-h1-to-8-1-9-h4-fips-failure/m-p/299214#M78343</guid>
      <dc:creator>MP18</dc:creator>
      <dc:date>2019-11-18T20:53:53Z</dc:date>
    </item>
    <item>
      <title>Re: PA3020 upgrade failure from 8.0.11-h1 to 8.1.9-h4 - FIPS  failure error</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa3020-upgrade-failure-from-8-0-11-h1-to-8-1-9-h4-fips-failure/m-p/299449#M78360</link>
      <description>&lt;P&gt;Not sure where you actually see step 2 as the official recommendation.&amp;nbsp; Palo's upgrade articles specifically say to just download a feature release, and then download &amp;amp; install your target release.&amp;nbsp; So for instance from 8.0.11 to 8.1.9 would be:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;- Download and install latest 8.0 (8.0.20)&lt;/P&gt;&lt;P&gt;- Download 8.1&lt;/P&gt;&lt;P&gt;- Download &amp;amp; install 8.1.9&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;" In most cases, the recommended path when moving from one feature release to the next is to download the base image for the next feature release version and then download and install your target maintenance release version. "&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/9-0/pan-os-new-features/upgrade-to-pan-os-90/upgrade-the-firewall-to-pan-os-90/determine-pan-os-upgrade-path.html" target="_blank"&gt;https://docs.paloaltonetworks.com/pan-os/9-0/pan-os-new-features/upgrade-to-pan-os-90/upgrade-the-firewall-to-pan-os-90/determine-pan-os-upgrade-path.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 19 Nov 2019 13:43:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa3020-upgrade-failure-from-8-0-11-h1-to-8-1-9-h4-fips-failure/m-p/299449#M78360</guid>
      <dc:creator>OGMaverick</dc:creator>
      <dc:date>2019-11-19T13:43:04Z</dc:date>
    </item>
    <item>
      <title>Re: PA3020 upgrade failure from 8.0.11-h1 to 8.1.9-h4 - FIPS  failure error</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa3020-upgrade-failure-from-8-0-11-h1-to-8-1-9-h4-fips-failure/m-p/299658#M78390</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/84842"&gt;@OGMaverick&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;On older series hardware (200, 500, 3000) the official recommendation was modified so that you download&amp;nbsp;&lt;STRONG&gt;and install&lt;/STRONG&gt; the base image with the release of 8.1 specifically due to a number of issues that was being caused on these older platforms due to disk limitations. When you simply download the base image and directly install the target maintenance image the firewall needs to explode both images and build a functional install image from both images.&lt;/P&gt;&lt;P&gt;Newer platforms the increase in size of PAN-OS was properly accounted for and they can handle needing to build that new image. I would still personally recommend installing the base image before installing the maintenance image even on there platforms as you generally have less of an issue with the firewall not properly updating system files and running into update issues.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 20 Nov 2019 03:17:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa3020-upgrade-failure-from-8-0-11-h1-to-8-1-9-h4-fips-failure/m-p/299658#M78390</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2019-11-20T03:17:10Z</dc:date>
    </item>
    <item>
      <title>Re: PA3020 upgrade failure from 8.0.11-h1 to 8.1.9-h4 - FIPS  failure error</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa3020-upgrade-failure-from-8-0-11-h1-to-8-1-9-h4-fips-failure/m-p/301318#M78659</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/75039"&gt;@MP18&lt;/a&gt;&amp;nbsp;the solution of TAC was to do an RMA. We received a replacement unit of PA3020 with OS of version 7.1.x.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;we had to upgrade all the way to 8.1.11&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;glenn&lt;/P&gt;</description>
      <pubDate>Fri, 29 Nov 2019 03:07:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa3020-upgrade-failure-from-8-0-11-h1-to-8-1-9-h4-fips-failure/m-p/301318#M78659</guid>
      <dc:creator>Egghead_Systems</dc:creator>
      <dc:date>2019-11-29T03:07:02Z</dc:date>
    </item>
    <item>
      <title>Re: PA3020 upgrade failure from 8.0.11-h1 to 8.1.9-h4 - FIPS  failure error</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa3020-upgrade-failure-from-8-0-11-h1-to-8-1-9-h4-fips-failure/m-p/301331#M78660</link>
      <description>&lt;P&gt;Many Thanks for replying to the post.&lt;/P&gt;&lt;P&gt;Much Appreciated !&lt;/P&gt;</description>
      <pubDate>Fri, 29 Nov 2019 06:00:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa3020-upgrade-failure-from-8-0-11-h1-to-8-1-9-h4-fips-failure/m-p/301331#M78660</guid>
      <dc:creator>MP18</dc:creator>
      <dc:date>2019-11-29T06:00:31Z</dc:date>
    </item>
  </channel>
</rss>

