Experience with PANOS 6 so far ?

Showing results for 
Show  only  | Search instead for 
Did you mean: 

Experience with PANOS 6 so far ?

L4 Transporter

I installed PANOS 6 on our Lab Box. Upgraded from 5.0.9. No problems so far.

Anyone else ?


L0 Member

I received an odd error when I tried to upgrade from 5.0.10 -

" Failed to install 6.0.0 with the following errors. SW version is 6.0.0 Error: Upgrading from 5.0.10 to 6.0.0 requires a content version of 401 or greater and found 320-1459. Failed to install version 6.0.0 type panos"

Maybe I'll try downgrading, to upgrade.

updating / installing the App and Threats option fixed the install

L4 Transporter

Used it in a vwire setup for the DNS sinkholing feature.

Helped me root out a virus infection with a customer.

No issues so far.

L4 Transporter

We just bought two new PA-3020s that will go live with 6.0 on Friday night. I'll try to remember and report back and let you know how it goes. I've been using them via the management interface since 6.0 release and I haven't had any problems. Of course, a data load will be the true test.

L7 Applicator

Running on a test box now and no issues with the upgrade or the 300 rule policy push.  The tap traffic of production all seems to behave the same way.

On the feature side, ssl port mirror and the dns sinkhole look like good additions to take a closer look at application in the network.

Steve Puluka BSEET - IP Architect - DQE Communications (Metro Ethernet/ISP)
ACE PanOS 6; ACE PanOS 7; ASE 3.0; PSE 7.0 Foundations & Associate in Platform; Cyber Security; Data Center

L3 Networker

So far so good. Seems pretty solid. Only issue I found thus far is the dynamic content error when upgrading from 5.x to 6.0. The dynamic content page gives an error and it does not scan traffic for threats.

L2 Linker

We use PA-5020s, and I couldn't wait to update to 6, to take advantage of the safe-search filtering. Unfortunately, when we upgraded it broke our user-id system, specifically the group mappings. 90% of all filtering went out of the 'default" policy. We are a large school system and rely on our group filtering. I reverted back to 5.0.9 and have a case open.

L4 Transporter

Still running 6.0 since almost two weeks without any problems. Well done PAN from my side !

gafrol would you care to provide some details of your implementation? PA 5000s? IPsec tunnels? HA? GlobalProtect? What all are you using? Are you taking advantage of the new DNS blackholing?

L4 Transporter

We installed new PA-3020s on Friday with 6.0. It's only been a few days and we haven't had a single problem. We have HA, IPSec tunnels, multiple virtual routers, tons of PBFs and static routes and everything has been great.

Not applicable

I use PA-3050 in my lab, from 5.0.10 to 6.0.0, but some feature like DHCP is not working well, i try to delete and recreate, then it working.

DNS Proxy is failed too, try to delete and recreate is still problem.


Has PA resolved this for you?  I use group membership in several critical rules, this kind of issue really grabs my attention.



We are using DHCP on 6.0 for one of our networks and it's working great.

Hi Mario,

Yes it work for workstation, but tested with mobile phone it can't, then i delete and recreate, it's work well now.

For DNS proxy, i think it should work, because my dns server is the problem then it effect to appliance to resolve name.

  • 36 replies
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!