03-11-2018 08:44 AM - edited 03-13-2018 12:43 PM
Since its release we've seen an uptick in folks deploying 8.1.0 to their firewalls, and that's a great thing. I just want to throw out a word of caution before doing so however; while 8.1.0 is one of the most stable base releases Palo Alto Networks has published, you need to do your homework before deploying this in any environment.
LAB Devices:
If you have access to any sort of LAB equipment, this is where you should be installing 8.1.0. Start testing your configuration in a LAB environment so that you can have a knowledgeable estimate of when you feel comfortable deploying 8.1 to your production equipment.
If you happen to utilize your LAB equipment in a Change Management process, take note that you are running a different version of PAN-OS when you actually test changes. Something that didn't work in your 8.1.0 LAB may work perfectly fine on 8.0.8 that you have running on your production equipment. On the other hand, something that works out perfectly fine on 8.1.0, may not function on 8.0.8 due to a bug being patched between versions.
Production Devices:
If you do not have access to LAB equipment to verify that your production configuration will actually fully function on 8.1.0, I would personally highly advise you to keep 8.1.0 off your production equipment.
Limitations of 8.1.0 are fairly small, however there are 13 pages of known issues within 8.1.0 along with 3 known issues specific to a WF-500 appliance. Before you contend with loading 8.1.0 on production equipment you should take the time to go through all of these known issues and decide if your environment would actually experience them and if you can work around them until they are patched in future maintenance releases. Causing an outage because you want to utilize the awesome SSL Decryption Broker, or the awesome new hit counters, is likely not going to go well.
Generally this boils down to following Palo Alto's recommended upgrade procedure and just doing your own due diligence before upgrading to 8.1. I think there are a few people that are getting wrapped up in the truly amazing feature improvements of 8.1, and throwing best practices out the window. If you don't have LAB equipment to properly test things out, let those of us that do find all of the bugs before causing an outage due to wanting a new software upgrade quickly.
If you truly want 8.1 and just simply can't wait to upgrade, I'd at least make a post here about what your configuration looks like prior to upgrading. We have a lot of people within these forums that have been running 8.1.0 since the beta was released on LAB equipment and home deployments that can likely take a glance at what you are doing and at least give you some real-world experience on what you should expect.
03-13-2018 12:40 PM - edited 03-13-2018 12:41 PM
Great Advice of course. Management at my company is chomping at the bit for a more secure Linux deployment of Global Protect. My test device has it working well, removing the need for the X-Auth PSK and implementing a Public Certificate authentication mechanism was key. Unfortunately, that part isn't supported on the pre 8.1 OS as "Linux" isn't a valid OS option on the Portal Config.
PS, use spell check! Some people in management see misspelling and the author's credibility is instantly diminished regardless of the years of experience.
03-13-2018 12:45 PM
I really wish spellcheck on Live was automatic like most other message boards. I've sent the original post through Word, so hopefully the spelling is at least somewhat correct. Honestly though, I don't think many management personnel are visiting the Live forums.
03-13-2018 01:07 PM - edited 03-14-2018 12:39 PM
I've been playing with PAN-OS 8.1 on a PA-200 and a PA-220 of which there is a site-to-site VPN tunnel between them. The upgrade went well overall (from 8.0.8 to 8.1.0) however I have run into two things, one more troubling than the other:
There are the two issues that I have expereince so far. The VPN issue is troubling and I may have to revert to 8.0.8 if i cant figure this one out. If anyone has any ideas, I would gladly listen to them.
-Matt
03-15-2018 05:30 PM
Did you get any specific details from support on the SMB issue? Perhaps a way to work around it without downgrade?
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!