PA-445 VERSION 11.2.7-h8

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

PA-445 VERSION 11.2.7-h8

L3 Networker

My pa-445 version 11.2.7-h8 sufferred a suddenly reboot affecting the whole operation. 

 

Troubleshooting :

 

1.   ID:69b1fcea60b6f010bfa3a5e8, Serial:028101007082, OS:11.2.7-h8, Platform:400, IP:10.166.240.10
+++++ 2026/03/11 11:52:35  System reboot             /opt/panrepo/logs/reboot.log          2026-03-11 11:52:35 SYSTEM REBOOT [Watchdog timer expired]
         2026/03/11 11:53:16  Orphaned partition        /var/log/pan/panlogs-partition.log    Mar 11 11:53:16 DEBUG: Clearing orphaned inode 396631 (uid=0, gid=0, mode=0100644, size=476)
         2026/03/11 11:56:27  Mp-monitor reboot info    /var/log/pan/mp-monitor.log           Monitor  ======== MP restart after up for 37 days ========
     +++ 2026/03/11 14:44:03  User                                                            Techsupport package was generated
2. messages.log
2026/03/11 11:53:01 Mar 11 11:53:01 PA-445-EXTERNO kernel: [    0.644162] ERST: Error Record Serialization Table (ERST) support is initialized.
2026/03/11 11:53:01 Mar 11 11:53:01 PA-445-EXTERNO kernel: [    1.029800] RAS: Correctable Errors collector initialized.
3. chasd.log
2026/03/11 11:53:19 2026-03-11 11:53:19.712 -0500 Start time.
2026/03/11 11:53:19 2026-03-11 11:53:19.718 -0500 sysd worker[0]: 7fa244240700: starting up...
2026/03/11 11:53:19 2026-03-11 11:53:19.719 -0500 sysd worker[1]: 7fa243e3f700: starting up...
2026/03/11 11:53:19 2026-03-11 11:53:19.719 -0500 sysd worker[2]: 7fa243a3e700: starting up...
2026/03/11 11:53:19 2026-03-11 11:53:19.722 -0500 sysd worker[3]: 7fa24363d700: starting up...
2026/03/11 11:53:19 2026-03-11 11:53:19.724 -0500 Not restart case
2026/03/11 11:53:57 2026-03-11 11:53:57.691 -0500 Slot 1 LED implementation node: hw.s1.mp.leds
2026/03/11 11:56:05 2026-03-11 11:56:05.848 -0500 config done 0x1, slot1
2026/03/11 11:56:47 2026-03-11 11:56:47.777 -0500 set up the autocommit completion
4. Ehmon.log
2026/03/11 11:53:20 2026-03-11 11:53:20.508 -0500 Start time.
2026/03/11 11:53:22 2026-03-11 11:53:22.510 -0500 Loading: libfans.so... done
2026/03/11 11:53:22 2026-03-11 11:53:22.511 -0500 Loading: libkernel_error.so... done
2026/03/11 11:53:22 2026-03-11 11:53:22.512 -0500 Loading: libpower.so... done
2026/03/11 11:53:22 2026-03-11 11:53:22.512 -0500 Loading: libpwrsupply.so... done
2026/03/11 11:53:22 2026-03-11 11:53:22.512 -0500 Loading: libsfp_mon.so... done
2026/03/11 11:53:22 2026-03-11 11:53:22.513 -0500 Loading: libthermal.so... done
5. brdagent.log
2026/03/11 11:53:22 2026-03-11 11:53:22.193 -0500 Error:  pan_get_sysd_init_cfg(src_400/pan_400_packet_io.c:99): sysd fetch obj cfg.platform.jumbo-mtu failed
2026/03/11 11:53:23 2026-03-11 11:53:23.146 -0500 Error:  pan_sysd_get_dpdk_max_qnum(src_x86_64/pan_dpdk_packet_io.c:411): sysd_fetch_obj() failed for cfg.platform.dpdk-max-qnum
2026/03/11 11:53:24 2026-03-11 11:53:24.693 -0500 Error:  is_pan_over_temp_shutdown_en(400/pan_cpld_ctrl.c:84): Platform does not have over temp. shutdown
2026/03/11 11:53:51 2026-03-11 11:53:51.610 -0500 Error:  pan_get_sysd_init_cfg(src_400/pan_400_packet_io.c:99): sysd fetch obj cfg.platform.jumbo-mtu failed
6. mprelay
2026/03/11 11:54:05 2026-03-11 11:54:05.319 -0500 Error:  pan_mprelay_app_dos_init(src/pan_mprelay_dos.c:544): * No hardware ACL capability on this platform !!!*
2026/03/11 11:54:05 2026-03-11 11:54:05.320 -0500 Error:  pan_mprelay_event_start(src/pan_mprelay_event.c:209): HW ACL is not supported - skip start acl ager timer
2026/03/11 11:54:05 2026-03-11 11:54:05.321 -0500 Error:  pan_chassis_slot_status_fetch(pan_chassis.c:181): cannot find chassis.summary
2026/03/11 11:54:06 2026-03-11 11:54:06.309 -0500 Error:  pan_chassis_slot_status_fetch(pan_chassis.c:181): cannot find chassis.summary

 

as you can see , there is a critical watchdog log that was causing the issue , however, the version is new 11.2.7-h8 and I would like to know if your recommendation is to move to the preferred release 11.2.10 any kind of suggestion would be highly cherished.

2 accepted solutions

Accepted Solutions

Hi 

 

in this case , TAC determined to proceed with a RMA to solve the issue. Morever, I was asking for Daemon that helped them to determine the RMA process.

View solution in original post

Community Team Member

Hi @F.Pinar ,

 

Thanks for the heads-up!

I'm sure this experience will be helpful for other users encountering the same issue in the future!

 

Cheers!

 

LIVEcommunity team member, CISSP
Cheers,
Kiwi
Please help out other users and “Accept as Solution” if a post helps solve your problem !

Read more about how and why to accept solutions.

View solution in original post

3 REPLIES 3

Community Team Member

Hi @F.Pinar ,

 

A watchdog timer expiration is almost always a sign that a specific process became unresponsive for so long that the system's hardware monitor "pulled the plug" to force a recovery.

 

Seeing this on 11.2.7-h8 is particularly notable because that specific hotfix was released to address stability issues, yet you are still hitting a kernel-level hang.

 

Watchdog timer expired confirms the reboot was not a power failure or a manual restart. The system hung, and the internal timer reached zero.

Orphaned partition / inode clearing is a secondary effect. Because the system crashed suddenly, the file system didn't unmount cleanly. The "clearing orphaned inode" is just the firewall fixing itself during the subsequent boot.

 

I recommend moving to 11.2.10-h3 (the current "Preferred" release for the 11.2 train as of March 2026).

You can check the preferred releases on our Release Guidance Page:

https://live.paloaltonetworks.com/t5/customer-resources/pan-os-globalprotect-amp-user-id-preferred-r...

 

I noticed in your logs that a TSF was already generated. I'd recommend opening a TAC case and specifically asking them to parse that file for MP-Monitor hangs. If the watchdog was triggered by a heartbeat failure, they can identify exactly which process (like mgmtsrvr, devsrvr, or all_pkt_proc) caused the freeze, which will confirm if the jump to 11.2.10 is the definitive fix for your specific crash.

 

Hope this helps !

LIVEcommunity team member, CISSP
Cheers,
Kiwi
Please help out other users and “Accept as Solution” if a post helps solve your problem !

Read more about how and why to accept solutions.

Hi 

 

in this case , TAC determined to proceed with a RMA to solve the issue. Morever, I was asking for Daemon that helped them to determine the RMA process.

Community Team Member

Hi @F.Pinar ,

 

Thanks for the heads-up!

I'm sure this experience will be helpful for other users encountering the same issue in the future!

 

Cheers!

 

LIVEcommunity team member, CISSP
Cheers,
Kiwi
Please help out other users and “Accept as Solution” if a post helps solve your problem !

Read more about how and why to accept solutions.
  • 2 accepted solutions
  • 2314 Views
  • 3 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!