What PAN-OS version is PAN support currently recommending for active/passive PA-3050s? Last I checked (a few months ago), it was 7.0.8. We're currently running this version, but it has a minor bug that is impacting us. We were told by support a few months ago that the bug is fixed in the 7.1.x branch and that there are no plans to fix it in 7.0.x, but that they don't consider 7.1.4 (at the time) the stable, recommended version.
Solved! Go to Solution.
Yes, also for PA-2050 the recommended release is PAN-OS 7.1.5 for the 7.1.x branch.
Other recommended releases on other branches are : 6.0.15, 6.1.15, 7.0.11, 7.1.5.
what was your bug? we are currently running 7.0.8 and I have noticed that the percentage on the dataplane has really increased
We do TLS decrypt with "block sessions from untrusted issuers" enabled. In previous major releases of PAN-OS (e.g. 4,.1.x, 5.0.x, and 6.0.x), the block page that would appear when a certificate wasn't trusted would list the certificate issuer and certificate common name. In 7.0.x, those fields are blank, which can make troubleshooting a bit of a pain. For whatever reason, support was told by PAN engineering that they aren't going to fix it in 7.0.x.
It led to an interesting conversation with support:
Me: "You're telling me that I need to move to the 7.1.x branch, but in the same breath you are telling me that 7.0.8 is the version that PAN recommends."
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!
The Live Community thanks you for your participation!