- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
Content translations are temporarily unavailable due to site maintenance. We apologize for any inconvenience. Visit our blog to learn more.
03-29-2018 07:25 AM
I am having a problem trying to push Apps&Threats or AV from the panorama to the firewalls. We have a Panorama M100 at 8.0.5 (recently upgraded from 6.1.10) with 5020 FW's at same release. We are NOT able to do the reachback to Palo Alto servers since we are a segregated testing network. When i go through the process to push the Apps&Threats or the AV updates there are no devices listed in the Devices section (no filters applied). I can go to Managed Devices and see the FW's connected and in sync. I have tried both paths to push the updates.
I can modify the device templates and have them committed and pushed to the fw's. I can update the FW's manually.
Is the reachback now a requirement for the deployment?
Is this a known Issue, i tried searching for it but don't get anything.
07-18-2018 05:22 AM
The issue as it turns out is the offline status of the panorama and firewalls. Since these systems do not have reachback capability the Mandatory license check fails. The support engineer said it was a Known issue. The manual update on each firewall works so i have a path to keep the systems updated but definitely not happy that Palo Also doesn't have a process of offline license updates/checks.
04-08-2018 01:49 PM
Did you maybe download the apps and threats update and now you're trying to install this update on a firewall without threat prevention license?
04-09-2018 03:31 AM
I can manually update the FW's with the same package. I grab the Apps only package for the Panorama and the Apps&Threats for the firewalls that have support. It is looking like the support license is not on the Panorama. Without the Support license (or reachback) the panorama can't do deployments.)
Thanks though.
07-18-2018 05:22 AM
The issue as it turns out is the offline status of the panorama and firewalls. Since these systems do not have reachback capability the Mandatory license check fails. The support engineer said it was a Known issue. The manual update on each firewall works so i have a path to keep the systems updated but definitely not happy that Palo Also doesn't have a process of offline license updates/checks.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!