Any issues with PANOS 4.0.5?

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

Any issues with PANOS 4.0.5?

L0 Member

Has anyone ran into issues with PANOS 4.05?

My previous past experience with PANOS 4.0.x was not the greatest.

High CPU utilization, network latency, GUI issues, and logging issues were not

the greatest. The end result was tech support and rollback to PANOS 3.1.x.

28 REPLIES 28

L3 Networker

we are running 4.04 in prod since a while.

We had some issues indeed, but we received workarrounds from the TAC for most of them.

Running 4.05 in lab now.

L1 Bithead

I've had the dataplane restarting due to crashing packet process multiple times. I have a TAC case open.

L1 Bithead

We're about 1 week into using 4.0.5 and have only run into a couple issues, neither of which I consider to be show stoppers.

The first doesn't seem to be specific to 4.0.5 but it's an issue with administrator accounts syncing down from Panorama to the devices and shared authentication profiles not being useable outside of the Panorama context.  Here's a link to the thread on that whole discussion:

https://live.paloaltonetworks.com/message/9307#9307

The other issue that we're dealing with concerns ACC and I currently have a support case open for it.  In the ACC tab it shows the list of top applications, but when you drill down into each specific application the sections for additional information such as "Top Users" and "Top Destinations" show "No matching records" even though the traffic logs exist and are viewable on the Monitor tab.

Other than those two issues, from a functional standpoint 4.0.5 has been pretty stable for us so far.

L4 Transporter

With the possible exception of an abacus its a fair statement to say no product is without issues. PAN-OS 4.0.5 has been deployed throughout the world in very large to very small, simple to complex networks, in most cases without issue. Of course this isn't to say that we haven't had reports of problems with this code or any past code, rather to point out that we are a responsive developer and if you do encounter a problem PaloAlto Networks is committed to addressing and resolving these issues in a timely efficient fashion. We are a customer driven company and we welcome any input good, bad or indifferent from our customer base.

~Phil

Good to know that's only minor issues. I'm 2 days away from deploying it to our 4050. No testlab so it's production device for me.

issues i faced on a 4020 HA were:

1. firewall could not communicate with the PANAGENTS correctly resulting in our domain name being truncated. This inturn means that specific rules relying on a users to AD group membership resulted in them being denied access ( show user pan-agent user-IDs ). SSL VPN login denied for example.

2. Certain SSL decryption certs had to be re-imported.

3. Few app dependencies warnings appeared out of nowhere but easy enough to fix

4. SSL VPN custom portal page ( web login page )  was lost and had to be re-imported.

i hope this helps.

L0 Member

I'm only a few days into my 4.0.5 upgrade, from 3.1.8 and it was a very smooth upgrade.  There were just a few small minor issues and from previous posts, it looks like I wasn't alone.  I upgraded 3 HA Systems and each had different minor issues, that were easily fixed.

1. SSL-VPN Authentication Profile had to be removed and recreated along with the RAIUS Profile.

2. SSL-VPN Custom Portal page had to be reselected in the configuration page.

3. NetConnect 1.2.0 clients prompted for the Java Certificate Experation even if the clients had previously choosen to always trust the certificate.

4. Several URL Filter rules were detecting an overlap which caused a commit failure.  After removing the unchecking the URL catagory that was in the error message the commit succeded.

5. Same ACC problem when drilling down on first day, but seems to be working properly today.  Might have just need time to generate the logs, since the active units were changed after the upgrade.

All systems under 3.1.8 had CPU usage 20 to 50% consistantly, but after the upgrade and the CPU usage now run at under 5%.

L2 Linker

Well, we've got a major problem with 4.0.5, which appears to be the same issue we were having with 4.0.4 until we rolled back to 4.0.3.  The Dataplane restarts occasionaly for no apparent reason!  This causes traffic to stop for about 10 minutes.  We were told it was a known bug in 4.0.4 and that it would be fixed in 4.0.5.  Apparently not.  It's happened twice since Sunday.  We are probably going to rollback to 4.0.3 yet again. 


Anyone else run across this problem??

Smiley Sad

@toddinva: I've run across the same problem. This started happening in 4.0.3, and continued in 4.0.4. I was told it would be fixed in 4.0.5, but the dataplane keeps crashing about once a day on average.

Wonderful.  4.0.3 was stable for us though.  We've already gotten the issue escalated, but they really need to fix this...

i am having the same dataplane crashing issue as well. not every day but it is still there, upgraded from 4.0.4 to 4.0.5 and this issue is not resolved.

Currently escalated to engineering. my boxes are 5020's is active-passive mode.

Not applicable

wr tried to update von Version 3.1.8 to 4.0.5 (4.0.1 was downloaeded before).

The update failed, because the autocommit job failed.(per CLI show jobs processed)

After Reboot, we tried to install 4.0.1. Here was the same failure, autocommit job Failed.

Then we activated 3.1.10 , and everything works.

Now, we wait for the support.

Are there any log.files, which show us the failure .

They are now telling me a fix will be in 4.0.6 which is due in mid-October.  With a bug this significant, you'd think they would have pulled 4.0.4 and 4.0.5 until this was corrected!  Very disappointing...

Same here, Working with engineering on this and disabled zone protection,DDOS and also any block changes in profiles and it's still an issue. I am sure more tech dumps to follow today.

  • 9981 Views
  • 28 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!