Upgraded our tap mode only PA 4020 from 5.0.5 to 5.0.6 and it "cratered"... we get dataplane restarts every 10 minutes. Anybody else seeing this?

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Upgraded our tap mode only PA 4020 from 5.0.5 to 5.0.6 and it "cratered"... we get dataplane restarts every 10 minutes. Anybody else seeing this?

L4 Transporter

We have a PA4020 that serves as a "canary in the mine" so to speak if you will... we have it only in tap mode, and we feed it various network taps at various points in our network.

Well, having this "canary in the mine" just paid off. I upgraded this box from 5.0.5 to 5.0.6 and we started seeing dataplane restarts every few hours. At support's request and after they'd looked at some core files and tech support dumps, I moved the URL database from BrightCloud to PANDB. After doing so the dataplane literally does not stay up long enough to even boot... the box crapped its pants and booted into maintenance mode on its own.

I downgraded back to 5.0.5 in maintenance mode (made no other changes), and the problem went away again.

Is anyone else seeing this on 5.0.6? If anything else, this should serve as a warning...

2 REPLIES 2

L5 Sessionator

Good Afternoon Egearhart,

The TAC is investigating  this issue. Its unfortunate that the device became unstable after the upgrade. Let me see if I am seeing a similar behavior on one of our lab systems. Was this specific to the 4020, or do you have other firewalls that reported the same issue?

BR,

Karthik

This is the only firewall that we have in this configuration... what I mean by that is, this is the only firewall that we have in only tap mode, where we're sending it gigs of traffic per day via the taps we have into it (not more than the dataplane can handle, it's just that we don't have any other firewalls in this specific configuration).

I don't mean this in a mean way, but I would hope that you guys (PA I mean) have various models of your Palo Altos in tap mode, basically running different code revisions and you're feeding your corporate office "day to day" Internet traffic through them, just sort of as your own "canaries in the mine" so to speak.

Thanks,

Eric

  • 2375 Views
  • 2 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!