PA-220 - 9.1.6 - DO NOT UPDATE

Reply
LukeRath
L1 Bithead

PA-220 - 9.1.6 - DO NOT UPDATE

Hi guys,

 

We have had 3 PA-220's recently that have all failed and needed to be factory reset when upgrading to 9.1.6. I have a case open to investigate further but this version is still the recommended version which is worrying. 

 

Luke

Tags (2)
MickBall
L7 Applicator

@LukeRath 

wow...   nightmare...

 

we have 18 3020's recently upgraded from 9.0.9 and all are OK so not sure what the difference is with yours.

 

just downloaded both 9.10 and 9.1.6 and then installed 9.1.6.

 

we have a mixture of SA and HA all managed by panorama and most are GP gateways but all went well.

I know that doesn't really help you but must be something else going on here... what version were they on when you upgraded?

LukeRath
L1 Bithead

We were running 9.0.8 so it was a fairly big jump. Some of the 220's have updated fine so it might be something to do with the disk space or configs. 

BPry
Cyber Elite

@LukeRath,

What was your actual upgrade procedure and what version were you upgrading from? All of my PA-220s upgraded to 9.1.6 perfectly fine, but they were also all running 9.1.5. 

Sec101
L2 Linker

Very thankful for this post.   Are most actually running 9.1 in production environments now - or is 9.0 the norm?

Brandon_Wertz
Cyber Elite


@Sec101 wrote:

Very thankful for this post.   Are most actually running 9.1 in production environments now - or is 9.0 the norm?


We've got some 5250s, 5220s, 3220s, 3020s and 220s.  I haven't put 9.1.X on the 3020s or 220s yet, but 9.1.X is on the others.  We ran into a NAT oversubscription issue on the 3220s, but other than that the code seems stable.  (docs.paloaltonetworks.com/pan-os/9-0/pan-os-admin/networking/nat/dynamic-ip-and-port-nat-oversubscription.html)

MP18
Cyber Elite

@Sec101 

 

I have few PA 220 and I did upgrade from 9.1.5 to 9.1.6 and they are working fine.

 

Regards

MP
Richards265
L0 Member

to redesign your PA-220, PA-820, and VM-300 firewalls to PAN-OS 9.0.0, download.

 

 

FaceTime for Windows

LukeRath
L1 Bithead

9.1 has been fine for us so far. The GP logs are a great feature too.  

 

We have found the issue was with the previous version, not 9.1.6. 

 

PAN-148676

Fixed an issue where the panlogs directory reached 100% utilization on the firewall due to early calculation of the .size file.

 

This bug fills the panlogs and causes the fw to fail during the upgrade. We have only noticed it with the PA-220 due to the smaller storage availability. 

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!