<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic 5200 upgrade from 8.1.5 to 9.0.6 and HA2 won't come up in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/5200-upgrade-from-8-1-5-to-9-0-6-and-ha2-won-t-come-up/m-p/314918#M81180</link>
    <description>&lt;P&gt;Perform an upgrade from 8.1.5 directly to 9.0.6 yesterday on A/P pair of 5250.&amp;nbsp; The HA2 link won't come up on 9.0.6&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This is from TAC,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Check the pan_dha.log in dp0-log and dp1-log for this error,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I&amp;nbsp;was&amp;nbsp;able&amp;nbsp;to&amp;nbsp;see&amp;nbsp;the&amp;nbsp;following&amp;nbsp;errors&amp;nbsp;that&amp;nbsp;explain&amp;nbsp;as&amp;nbsp;to&amp;nbsp;why&amp;nbsp;HA2&amp;nbsp;would&amp;nbsp;not&amp;nbsp;come&amp;nbsp;up:&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;pan_dha.log&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;++++++++++++++&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Error:&amp;nbsp;&amp;nbsp;pan_dha_config_connection_load(pan_dha_config.c:483):&amp;nbsp;invalid&amp;nbsp;peer&amp;nbsp;ha2-ip&amp;nbsp;addres&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;++++++++++++++&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;What&amp;nbsp;might&amp;nbsp;have&amp;nbsp;happened,&amp;nbsp;is&amp;nbsp;that&amp;nbsp;after&amp;nbsp;the&amp;nbsp;reboot&amp;nbsp;once&amp;nbsp;9.0.6&amp;nbsp;was&amp;nbsp;installed,&amp;nbsp;the&amp;nbsp;full&amp;nbsp;configuration&amp;nbsp;might&amp;nbsp;not&amp;nbsp;have&amp;nbsp;been&amp;nbsp;validated,&amp;nbsp;including&amp;nbsp;the&amp;nbsp;HA2&amp;nbsp;config,&amp;nbsp;&amp;nbsp;for&amp;nbsp;one&amp;nbsp;internal&amp;nbsp;reason&amp;nbsp;or&amp;nbsp;another.&amp;nbsp;Physically,&amp;nbsp;the&amp;nbsp;interface&amp;nbsp;port&amp;nbsp;was&amp;nbsp;healthy&amp;nbsp;throughout&amp;nbsp;the&amp;nbsp;upgrade&amp;nbsp;process,&amp;nbsp;but&amp;nbsp;it&amp;nbsp;looks&amp;nbsp;like&amp;nbsp;it&amp;nbsp;was&amp;nbsp;an&amp;nbsp;internal&amp;nbsp;configuration&amp;nbsp;issue.&amp;nbsp;I&amp;nbsp;myself&amp;nbsp;have&amp;nbsp;experienced&amp;nbsp;issues&amp;nbsp;that&amp;nbsp;a&amp;nbsp;commit&amp;nbsp;after&amp;nbsp;upgrading&amp;nbsp;would&amp;nbsp;fix&amp;nbsp;issues&amp;nbsp;that&amp;nbsp;arose&amp;nbsp;after&amp;nbsp;the&amp;nbsp;upgrade&amp;nbsp;reboot.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Hope this helps others.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;E&lt;/P&gt;</description>
    <pubDate>Fri, 06 Mar 2020 14:57:30 GMT</pubDate>
    <dc:creator>nextgenhappines</dc:creator>
    <dc:date>2020-03-06T14:57:30Z</dc:date>
    <item>
      <title>5200 upgrade from 8.1.5 to 9.0.6 and HA2 won't come up</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/5200-upgrade-from-8-1-5-to-9-0-6-and-ha2-won-t-come-up/m-p/314918#M81180</link>
      <description>&lt;P&gt;Perform an upgrade from 8.1.5 directly to 9.0.6 yesterday on A/P pair of 5250.&amp;nbsp; The HA2 link won't come up on 9.0.6&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This is from TAC,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Check the pan_dha.log in dp0-log and dp1-log for this error,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I&amp;nbsp;was&amp;nbsp;able&amp;nbsp;to&amp;nbsp;see&amp;nbsp;the&amp;nbsp;following&amp;nbsp;errors&amp;nbsp;that&amp;nbsp;explain&amp;nbsp;as&amp;nbsp;to&amp;nbsp;why&amp;nbsp;HA2&amp;nbsp;would&amp;nbsp;not&amp;nbsp;come&amp;nbsp;up:&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;pan_dha.log&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;++++++++++++++&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Error:&amp;nbsp;&amp;nbsp;pan_dha_config_connection_load(pan_dha_config.c:483):&amp;nbsp;invalid&amp;nbsp;peer&amp;nbsp;ha2-ip&amp;nbsp;addres&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;++++++++++++++&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;What&amp;nbsp;might&amp;nbsp;have&amp;nbsp;happened,&amp;nbsp;is&amp;nbsp;that&amp;nbsp;after&amp;nbsp;the&amp;nbsp;reboot&amp;nbsp;once&amp;nbsp;9.0.6&amp;nbsp;was&amp;nbsp;installed,&amp;nbsp;the&amp;nbsp;full&amp;nbsp;configuration&amp;nbsp;might&amp;nbsp;not&amp;nbsp;have&amp;nbsp;been&amp;nbsp;validated,&amp;nbsp;including&amp;nbsp;the&amp;nbsp;HA2&amp;nbsp;config,&amp;nbsp;&amp;nbsp;for&amp;nbsp;one&amp;nbsp;internal&amp;nbsp;reason&amp;nbsp;or&amp;nbsp;another.&amp;nbsp;Physically,&amp;nbsp;the&amp;nbsp;interface&amp;nbsp;port&amp;nbsp;was&amp;nbsp;healthy&amp;nbsp;throughout&amp;nbsp;the&amp;nbsp;upgrade&amp;nbsp;process,&amp;nbsp;but&amp;nbsp;it&amp;nbsp;looks&amp;nbsp;like&amp;nbsp;it&amp;nbsp;was&amp;nbsp;an&amp;nbsp;internal&amp;nbsp;configuration&amp;nbsp;issue.&amp;nbsp;I&amp;nbsp;myself&amp;nbsp;have&amp;nbsp;experienced&amp;nbsp;issues&amp;nbsp;that&amp;nbsp;a&amp;nbsp;commit&amp;nbsp;after&amp;nbsp;upgrading&amp;nbsp;would&amp;nbsp;fix&amp;nbsp;issues&amp;nbsp;that&amp;nbsp;arose&amp;nbsp;after&amp;nbsp;the&amp;nbsp;upgrade&amp;nbsp;reboot.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Hope this helps others.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;E&lt;/P&gt;</description>
      <pubDate>Fri, 06 Mar 2020 14:57:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/5200-upgrade-from-8-1-5-to-9-0-6-and-ha2-won-t-come-up/m-p/314918#M81180</guid>
      <dc:creator>nextgenhappines</dc:creator>
      <dc:date>2020-03-06T14:57:30Z</dc:date>
    </item>
    <item>
      <title>Re: 5200 upgrade from 8.1.5 to 9.0.6 and HA2 won't come up</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/5200-upgrade-from-8-1-5-to-9-0-6-and-ha2-won-t-come-up/m-p/315025#M81192</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Check the config on both PAN's and make sure they are correct. If still not working, try changing the HA2 config so you know its not correct, commit the changes and then change them back.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Just some thoughts.&lt;/P&gt;</description>
      <pubDate>Fri, 06 Mar 2020 22:29:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/5200-upgrade-from-8-1-5-to-9-0-6-and-ha2-won-t-come-up/m-p/315025#M81192</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2020-03-06T22:29:10Z</dc:date>
    </item>
    <item>
      <title>Re: 5200 upgrade from 8.1.5 to 9.0.6 and HA2 won't come up</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/5200-upgrade-from-8-1-5-to-9-0-6-and-ha2-won-t-come-up/m-p/315035#M81194</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/27580"&gt;@OtakarKlier&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The issue is not related to HA2 config of the firewall, as TAC explained, something went wrong in auto commit.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Suggestion 1 , commit force.&lt;/P&gt;&lt;P&gt;Suggestion 2, reboot the firewall.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I rolled back both firewall to 8.1.5 and upgraded to 8.1.13, then to 9.0.0, and then upgraded to 9.0.6.&amp;nbsp; HA2 link stay up.&amp;nbsp; &amp;nbsp;Just want to share my experience to save others time and pain to do many many upgrades.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;E&lt;/P&gt;</description>
      <pubDate>Fri, 06 Mar 2020 23:58:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/5200-upgrade-from-8-1-5-to-9-0-6-and-ha2-won-t-come-up/m-p/315035#M81194</guid>
      <dc:creator>nextgenhappines</dc:creator>
      <dc:date>2020-03-06T23:58:48Z</dc:date>
    </item>
    <item>
      <title>Re: 5200 upgrade from 8.1.5 to 9.0.6 and HA2 won't come up</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/5200-upgrade-from-8-1-5-to-9-0-6-and-ha2-won-t-come-up/m-p/315167#M81216</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/23897"&gt;@nextgenhappines&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;So you went from a non-recommended upgrade path to mirroring the recommended upgrade path and your issues went away, funny how that works out &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&amp;nbsp;; - )&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In all seriousness, this is exactly why I stress following the actual recommended upgrade path as much as I do. 95% of the time it won't matter and everything will work perfectly fine, but then 5% of the time something breaks and can cause an outage. It's better that you follow the proper process and need a bit more time for the maintenance window than have an issue and cause an unexpected outage or unexpected extended maintenance.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 08 Mar 2020 05:50:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/5200-upgrade-from-8-1-5-to-9-0-6-and-ha2-won-t-come-up/m-p/315167#M81216</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2020-03-08T05:50:03Z</dc:date>
    </item>
    <item>
      <title>Re: 5200 upgrade from 8.1.5 to 9.0.6 and HA2 won't come up</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/5200-upgrade-from-8-1-5-to-9-0-6-and-ha2-won-t-come-up/m-p/315181#M81218</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Change window is difficult to request.&amp;nbsp; Don't want to fill out additional paper works to explain what happened.&amp;nbsp; &amp;nbsp; "Recommended" upgrade. takes 3 times long.&amp;nbsp; &amp;nbsp;It takes 35 minutes for a firewall to reboot (I do miss the good old days work on screenos) and I have to do 6 upgrades instead of 2..&amp;nbsp; hmm.. that is a hard sales for me.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If I knew the TAC tricks,&amp;nbsp; 1) try commit force, or 2) reboot the firewall on the version that you wanted.&amp;nbsp; That would have save so much time as well.&amp;nbsp; &amp;nbsp;Just want to share my experience and hope to save others; time and stress.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 08 Mar 2020 12:16:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/5200-upgrade-from-8-1-5-to-9-0-6-and-ha2-won-t-come-up/m-p/315181#M81218</guid>
      <dc:creator>nextgenhappines</dc:creator>
      <dc:date>2020-03-08T12:16:19Z</dc:date>
    </item>
  </channel>
</rss>

