Enhanced Security Measures in Place:   To ensure a safer experience, we’ve implemented additional, temporary security measures for all users.

PA-220 - 9.1.6 - DO NOT UPDATE

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

PA-220 - 9.1.6 - DO NOT UPDATE

L1 Bithead

Hi guys,

 

We have had 3 PA-220's recently that have all failed and needed to be factory reset when upgrading to 9.1.6. I have a case open to investigate further but this version is still the recommended version which is worrying. 

 

Luke

8 REPLIES 8

L7 Applicator

@LukeRath 

wow...   nightmare...

 

we have 18 3020's recently upgraded from 9.0.9 and all are OK so not sure what the difference is with yours.

 

just downloaded both 9.10 and 9.1.6 and then installed 9.1.6.

 

we have a mixture of SA and HA all managed by panorama and most are GP gateways but all went well.

I know that doesn't really help you but must be something else going on here... what version were they on when you upgraded?

We were running 9.0.8 so it was a fairly big jump. Some of the 220's have updated fine so it might be something to do with the disk space or configs. 

Cyber Elite
Cyber Elite

@LukeRath,

What was your actual upgrade procedure and what version were you upgrading from? All of my PA-220s upgraded to 9.1.6 perfectly fine, but they were also all running 9.1.5. 

L4 Transporter

Very thankful for this post.   Are most actually running 9.1 in production environments now - or is 9.0 the norm?


@Sec101 wrote:

Very thankful for this post.   Are most actually running 9.1 in production environments now - or is 9.0 the norm?


We've got some 5250s, 5220s, 3220s, 3020s and 220s.  I haven't put 9.1.X on the 3020s or 220s yet, but 9.1.X is on the others.  We ran into a NAT oversubscription issue on the 3220s, but other than that the code seems stable.  (docs.paloaltonetworks.com/pan-os/9-0/pan-os-admin/networking/nat/dynamic-ip-and-port-nat-oversubscription.html)

@Sec101 

 

I have few PA 220 and I did upgrade from 9.1.5 to 9.1.6 and they are working fine.

 

Regards

MP

Help the community: Like helpful comments and mark solutions.

L0 Member

to redesign your PA-220, PA-820, and VM-300 firewalls to PAN-OS 9.0.0, download.

 

 

FaceTime for Windows

9.1 has been fine for us so far. The GP logs are a great feature too.  

 

We have found the issue was with the previous version, not 9.1.6. 

 

PAN-148676

Fixed an issue where the panlogs directory reached 100% utilization on the firewall due to early calculation of the .size file.

 

This bug fills the panlogs and causes the fw to fail during the upgrade. We have only noticed it with the PA-220 due to the smaller storage availability. 

  • 5095 Views
  • 8 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!