- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
02-03-2025 06:43 PM
Hello.
If we upgrade PA-450 from 10.1.6-h6 to 10.2 or 11.1 (or 11.2) series, is it correct to assume that there is no change in SSH communication method or ARP output format?
I am aware that there is no change as far as I can see from the release notes, but please let me check just to be sure.
02-04-2025 11:37 AM
Hello,
I cant recall ever seeing an issue with either when upgrading a PAN. Both hold to pretty strict standards.
SSH https://datatracker.ietf.org/doc/html/rfc4253
ARP https://datatracker.ietf.org/doc/html/rfc826
Regards,
02-04-2025 08:21 PM
Hello @n-tomo
over past years I have done a few Firewall migrations / upgrades. I never came across an issue with SSH, however I run into an issue with ARP during migrations. By doing upgrades there will be no change in SSH or ARP, however you might run into a bug affecting functionality of either of the protocols. In earliest PAN-OS releases of 10.2 there are a few bugs related to ARP: PAN-221033, PAN-209346, PAN-207533, PAN-204838, PAN-199726. Regardless what target PAN-OS version you decide to upgrade to you should aim for latest recommended version that has all bugs addressed.
Kind Regards
Pavel
02-05-2025 07:29 AM - edited 02-05-2025 07:30 AM
@OtakarKlier wrote:
Hello,
I cant recall ever seeing an issue with either when upgrading a PAN. Both hold to pretty strict standards.
SSH https://datatracker.ietf.org/doc/html/rfc4253
ARP https://datatracker.ietf.org/doc/html/rfc826
Regards,
@OtakarKlier -- Palo has actually has such an issue when we were upgrading to a 10.1.X from a 10.0.X we had "weird" traffic not working issues. In the end, it was because we had our NAT rules setup wrong. Prior to the upgrade from 10.0.X to 10.1.X traffic worked just fine with the firewall matching traffic to the NAT policy, but in 10.1.9 (mid code) they changed how the device functioned regarding ARP (Ours was a single VR, not dual):
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!