Any issues not documented on version 8.0.6?

Reply
L7 Applicator

Any issues not documented on version 8.0.6?

Hello Community,

Since the security advisories were released yesterday, we are looking to upgrade to the newer version. Has anyone experienced any issues with 8.0.6 from 8.0.5 that are not in the release notes?

 

 https://securityadvisories.paloaltonetworks.com/

 

https://downloads.paloaltonetworks.com/software/PAN-OS_8.0.6_RN.pdf?__gda__=1512621490_dc551bd77c01f...

 

Thanks in advance!

L2 Linker

Re: Any issues not documented on version 8.0.6?

I'm working on the 8.0.6 upgrade as well. Last Friday, I upgraded 3 set of PA-500s in HA from 7.1.x to 8.0.6, and it seems okay, no complaints yet. However, there are always bugs in there, and it triggers in different situations. So the final decision is yours.

L7 Applicator

Re: Any issues not documented on version 8.0.6?

@OtakarKlier,

Not runnning into anything that isn't already a known-issue. It's actually been a suprisingly smooth upgrade cycle so far. 

L2 Linker

Re: Any issues not documented on version 8.0.6?

We put it in lab last week - no issues to report.

We'll start testing in the production environment after the holidays.

L7 Applicator

Re: Any issues not documented on version 8.0.6?

@MatthewSabin @OtakarKlier,

FYI, you'll want to move the version to 8.0.6-h3. One of the CVEs that was believed to be fixed in 8.0.6 is not. 

L7 Applicator

Re: Any issues not documented on version 8.0.6?

Hello @BPry,

I saw that note that was sent out and this was why we were upgrading. However since the hotfix is so new, we are going to wait a bit and let it bake in the wild for a bit. While I like living on the edge, bleeding edge is just too risky for my tastes.

 

Cheers!

L3 Networker

Re: Any issues not documented on version 8.0.6?

FWIW: regarding this vulnerability, I recently upgraded an HA pair of PA-3050's running 7.0.18 to 7.0.19.   I'm experiencing some issues with SSH connections.  I do not know if this is related or not.   I've also been running into errors causing commit failures.   These are errors I've never seen before though is reminiscent of a problem I recall from the PanOS 4.x days.   I would post the message had I not since cleared the logs.

 

What I've noticed is this:

  1.  LAN->DMZ SSH sessions are being dropped even though the destination IP is whitelisted.   This destination has decryption disabled by the destination IP address.  After many attempts to resolve the issue, SSH began working after I removed all security profiles from the security policy for this destination.
  2. LAN->WWW sFTP sessions are being dropped.  The destination is whitelisted and has SSL decryption disabled.  In this case there is no decryption profile assigned to the SSH proxy decryption policy rule.   After many attempts I was able to get this working within the latest version of WinSCP by turning on SSH decryption at the firewall.  Yes, enable decryption.   Yes, this is sFTP and not FTPs.  FileZilla still does not work.   It begins cipher exchange and then the connection drops.   From very limited testing, AIX sFTP does work as does Ubuntu sFTP.   The destination is secure2<.>benefitfocus<.>com on port 22.    The site is apparently running a version of GlobalSCAPE Enhanced File Transfer Server from 2007 (v. 5.1).

 

This may not be applicable to 8.0.6 and I am not 100% positive that this is a PanOS issue.  

L2 Linker

Re: Any issues not documented on version 8.0.6?

After upgrading to 8.0.6 Dynamic Updates was showing 4 to 5 previous updates for download and install in each column of dynamic updates . I downgraded back to 8.04

Highlighted
L2 Linker

Re: Any issues not documented on version 8.0.6?

we have been on 8.0.6 for a few weeks now and have been good (knock on wood). Running 5020s. 8.0.3 was a different story but good now.

L7 Applicator

Re: Any issues not documented on version 8.0.6?

Thanks all!

I'm still waiting for the 8.0.6-h3 to bake in the wild before deploying it. I'll update when I have my prod systems running on it. Right now only my little lab200 is on it but it doesnt really do much.

 

Regards,

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!

The Live Community thanks you for your participation!