Firewall stopped sending traffic to internet from trust zone, after upgrade from 10.1.3 to 10.1.5h2

Showing results for 
Show  only  | Search instead for 
Did you mean: 
Please sign in to see details of an important advisory in our Customer Advisories area.

Firewall stopped sending traffic to internet from trust zone, after upgrade from 10.1.3 to 10.1.5h2

L0 Member

I have upgraded 3 set of palo alto PA-3220 (3 pairs) to 10.1.5h2.

Two set works good without any issue.

When upgrade completed with last set, the active firewall stopped sending traffic from trust zone to internet, though it has all valid routes in it. Post I shifted all traffic on secondary firewall and all started working.

This is the issue I am facing. Any suggestions?


Have opned the case with Palo Alto on saturday with priority S2, yet no reply from them. 


Community Team Member

Hi @Gitesh ,


It's really hard to identify the issue with the information provided. 


Have you checked how the firewall identifies the traffic ?

I mean, do you see any traffic ingressing / egressing the firewall ? Any particular denies in the traffic logs or drops in the global counters ? Any traffic logs at all (showing incomplete maybe) ?


It's great that you were able to fail over and get it to work on your secondary device but we can't really guide you much with the provided data.




LIVEcommunity team member, CISSP
Please help out other users and “Accept as Solution” if a post helps solve your problem !

Read more about how and why to accept solutions.
  • 1 replies
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!