- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
06-28-2016 06:34 AM
I am looking for the article that says that you cannot upgrade directly to anything past 7.01 without breaking certs.
06-28-2016 07:57 AM - edited 06-28-2016 07:58 AM
There is a warning in the release notes up to 7.0.7:
Before you upgrade to PAN-OS 7.0.3 or a later PAN-OS 7.0 release, review the information about how to upgrade a firewall to PAN-OS 7.0. Additionally, if virtual system (vsys) configuration is not enabled on your firewall or appliance, you must reboot your firewall or appliance after you install PAN-OS 7.0.1 and before you upgrade to PAN-OS 7.0.3 or a later release.
This should be fixed with 7.0.8 though:
90982: Fixed an issue where upgrading from a PAN-OS 6.1 release to PAN-OS 7.0.3 or a later PAN-OS 7.0 release caused the GlobalProtect portal or gateway and SSL decryption processes to stop responding. This issue occurred because SSL/TLS Service Profiles (introduced in PAN-OS 7.0) were not created successfully if you did not enable multiple virtual system (multi-vsys) functionality on the firewall. With this fix, SSL/TLS Service profiles are now successfully created on non-multi-vsys platforms when upgrading to PAN-OS 7.0.8 or later releases or to PAN-OS 7.1 releases.
06-28-2016 07:57 AM - edited 06-28-2016 07:58 AM
There is a warning in the release notes up to 7.0.7:
Before you upgrade to PAN-OS 7.0.3 or a later PAN-OS 7.0 release, review the information about how to upgrade a firewall to PAN-OS 7.0. Additionally, if virtual system (vsys) configuration is not enabled on your firewall or appliance, you must reboot your firewall or appliance after you install PAN-OS 7.0.1 and before you upgrade to PAN-OS 7.0.3 or a later release.
This should be fixed with 7.0.8 though:
90982: Fixed an issue where upgrading from a PAN-OS 6.1 release to PAN-OS 7.0.3 or a later PAN-OS 7.0 release caused the GlobalProtect portal or gateway and SSL decryption processes to stop responding. This issue occurred because SSL/TLS Service Profiles (introduced in PAN-OS 7.0) were not created successfully if you did not enable multiple virtual system (multi-vsys) functionality on the firewall. With this fix, SSL/TLS Service profiles are now successfully created on non-multi-vsys platforms when upgrading to PAN-OS 7.0.8 or later releases or to PAN-OS 7.1 releases.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!