Experience with PANOS 6 so far ?

Reply
L4 Transporter

Experience with PANOS 6 so far ?

I installed PANOS 6 on our Lab Box. Upgraded from 5.0.9. No problems so far.

Anyone else ?

L0 Member

Re: Experience with PANOS 6 so far ?

I received an odd error when I tried to upgrade from 5.0.10 -

" Failed to install 6.0.0 with the following errors. SW version is 6.0.0 Error: Upgrading from 5.0.10 to 6.0.0 requires a content version of 401 or greater and found 320-1459. Failed to install version 6.0.0 type panos"

Maybe I'll try downgrading, to upgrade.

Highlighted
L0 Member

Re: Experience with PANOS 6 so far ?

updating / installing the App and Threats option fixed the install

L4 Transporter

Re: Experience with PANOS 6 so far ?

Used it in a vwire setup for the DNS sinkholing feature.

Helped me root out a virus infection with a customer.

No issues so far.

L4 Transporter

Re: Experience with PANOS 6 so far ?

We just bought two new PA-3020s that will go live with 6.0 on Friday night. I'll try to remember and report back and let you know how it goes. I've been using them via the management interface since 6.0 release and I haven't had any problems. Of course, a data load will be the true test.

L7 Applicator

Re: Experience with PANOS 6 so far ?

Running on a test box now and no issues with the upgrade or the 300 rule policy push.  The tap traffic of production all seems to behave the same way.

On the feature side, ssl port mirror and the dns sinkhole look like good additions to take a closer look at application in the network.

Steve Puluka BSEET - IP Architect - DQE Communications (Metro Ethernet/ISP)
ACE PanOS 6; ACE PanOS 7; ASE 3.0; PSE 7.0 Foundations & Associate in Platform; Cyber Security; Data Center
L3 Networker

Re: Experience with PANOS 6 so far ?

So far so good. Seems pretty solid. Only issue I found thus far is the dynamic content error when upgrading from 5.x to 6.0. The dynamic content page gives an error and it does not scan traffic for threats.

L2 Linker

Re: Experience with PANOS 6 so far ?

We use PA-5020s, and I couldn't wait to update to 6, to take advantage of the safe-search filtering. Unfortunately, when we upgraded it broke our user-id system, specifically the group mappings. 90% of all filtering went out of the 'default" policy. We are a large school system and rely on our group filtering. I reverted back to 5.0.9 and have a case open.

L4 Transporter

Re: Experience with PANOS 6 so far ?

Still running 6.0 since almost two weeks without any problems. Well done PAN from my side !

L4 Transporter

Re: Experience with PANOS 6 so far ?

gafrol would you care to provide some details of your implementation? PA 5000s? IPsec tunnels? HA? GlobalProtect? What all are you using? Are you taking advantage of the new DNS blackholing?

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!

The Live Community thanks you for your participation!