7.01 and certs

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

7.01 and certs

L4 Transporter

I am looking for the article that says that you cannot upgrade directly to anything past 7.01 without breaking certs.

1 accepted solution

Accepted Solutions

L4 Transporter

There is a warning in the release notes up to 7.0.7:

 

https://www.paloaltonetworks.com/documentation/70/pan-os/pan-os-release-notes/pan-os-7-0-7-addressed...

 

Before you upgrade to PAN-OS 7.0.3 or a later PAN-OS 7.0 release, review the information about how to upgrade a firewall to PAN-OS 7.0. Additionally, if virtual system (vsys) configuration is not enabled on your firewall or appliance, you must reboot your firewall or appliance after you install PAN-OS 7.0.1 and before you upgrade to PAN-OS 7.0.3 or a later release.

 

This should be fixed with 7.0.8 though:

90982: Fixed an issue where upgrading from a PAN-OS 6.1 release to PAN-OS 7.0.3 or a later PAN-OS 7.0 release caused the GlobalProtect portal or gateway and SSL decryption processes to stop responding. This issue occurred because SSL/TLS Service Profiles (introduced in PAN-OS 7.0) were not created successfully if you did not enable multiple virtual system (multi-vsys) functionality on the firewall. With this fix, SSL/TLS Service profiles are now successfully created on non-multi-vsys platforms when upgrading to PAN-OS 7.0.8 or later releases or to PAN-OS 7.1 releases.

View solution in original post

1 REPLY 1

L4 Transporter

There is a warning in the release notes up to 7.0.7:

 

https://www.paloaltonetworks.com/documentation/70/pan-os/pan-os-release-notes/pan-os-7-0-7-addressed...

 

Before you upgrade to PAN-OS 7.0.3 or a later PAN-OS 7.0 release, review the information about how to upgrade a firewall to PAN-OS 7.0. Additionally, if virtual system (vsys) configuration is not enabled on your firewall or appliance, you must reboot your firewall or appliance after you install PAN-OS 7.0.1 and before you upgrade to PAN-OS 7.0.3 or a later release.

 

This should be fixed with 7.0.8 though:

90982: Fixed an issue where upgrading from a PAN-OS 6.1 release to PAN-OS 7.0.3 or a later PAN-OS 7.0 release caused the GlobalProtect portal or gateway and SSL decryption processes to stop responding. This issue occurred because SSL/TLS Service Profiles (introduced in PAN-OS 7.0) were not created successfully if you did not enable multiple virtual system (multi-vsys) functionality on the firewall. With this fix, SSL/TLS Service profiles are now successfully created on non-multi-vsys platforms when upgrading to PAN-OS 7.0.8 or later releases or to PAN-OS 7.1 releases.

  • 1 accepted solution
  • 1612 Views
  • 1 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!