AD trouble after installing content version 729

Announcements

Changes to the LIVEcommunity experience are coming soon... Here's what you need to know.

Reply
RichColeman
L2 Linker

Word on the street is the content team is working on resolving the issue, I would expect a fix in the next 24 hours. 

 

Also its always worth setting a delay on the download/install just to protect yourselves against this sort of issue. We set a 24 defer period on our estate. Saved us a few times

molander
L2 Linker

We were seeing various issues with authentication and various traffic breaking on our 7050 HA pairs.

Reverted the App and Threat content version to 726 which resolved all issues.

cdp181
L1 Bithead

Our Palo partner suggested a 72 hour delay on content updates.  Interestingly you don't seem to be able to configure a delay in Panorama only on the devices themselves.

mlinsemier
L4 Transporter

We ran into the same issues with content 729.  Rolling back to 727 resolved our issues.  

 

I'm thinking that delaying it by 24 hours sounds like a good idea.  I saw a post above stating that they waiting 72 hours inbetween updates.

 

By waiting to long it seems we run into a chicken and the egg scenario.  What are the dangers where Threats and App-ID are not updated?   I assume there could be a window where new Vulnerabilities may not be addressed or changes by the vendors for App-ID may not be properly identified correctly by Policy rules.

 

Thoughts?


Matt

CRHC
L4 Transporter

We are also experiencing many issues with 729 and connections related PACS images and interface engines.  Removing Threat, resolves all issues.

Gun-Slinger
L3 Networker

We had issues associated with HL7 traffic. We have completed a roll back and that resolved the issue.

Tags (2)
niuk
L3 Networker

Was it seen in Monitor/Traffic or Threats , like drops anything ?

BrianGittens
L0 Member

We also had this problem and committed an Any on the Service for AD to work. We were about to test what the issue was when we saw the PA  update on  729. We are reverting to 727 and deleted 729.

 

Written by Edward Millington

mivaldi
L7 Applicator

Please refer to the following Palo Alto Networks Customer Advisory available at:

 

https://live.paloaltonetworks.com/t5/Customer-Advisories/Important-information-regarding-Content-App...

ajr13
L3 Networker


@cdp181 wrote:

Our Palo partner suggested a 72 hour delay on content updates.  Interestingly you don't seem to be able to configure a delay in Panorama only on the devices themselves.


 

FYI on panorama 7.x.x and above I think this option is available. It may be available prior to that release but I cannot confirm,.

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!