Urgent case : base image is deleted and can not download through internet and uploaded manually but not loaded

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

Urgent case : base image is deleted and can not download through internet and uploaded manually but not loaded

L2 Linker

last week 95% root partition usage alarm, then I clear disk space 

last week deleted base image wrongly then i try to download again but failed in web
then today I power socket is unplugged and restarted, ethernet 1/1 not function

 

uploaded manually  10.0.0 and 10.2.0 it show uploaded

but it can not load base image after restart, now ethernet 1/1 can not have function and light

firewall is totally out of function

I try to change IP address of management interface with subnet of wifi router
but commit force failed due to certificate error

there is no other ports to download 10.0.0 image through internet

 

what should I do now?

I am a Palo Alto user setup Palo Alto Firewall from new and clean Palo Alto from the beginning. Advanced threat, Wildfire, advanced URL and advanced DNS are my licenses.
4 REPLIES 4

Cyber Elite
Cyber Elite

Might be a good time to run a factory reset to clear your system from clutter and to get a fresh start for PAN-OS

 

don't forget to export your config file, factory reset to your current PAN-OS, upload the config file and you should be good to go

Tom Piens
PANgurus - Strata specialist; config reviews, policy optimization

L2 Linker

I have factory reset , connected outside port with wifi router

originally see two light flashing at outside port

 

but after snapshot config load or may be after a while , the outside port has only one left light on , and DHCP of outside vlan 

originally can get ip address but after a while , the DHCP client of outside vlan back to initial state

can not get IP address, then i set fixed IP address, it still one left light on,  the other light is off

 

is recent DOS vulnerability make ethernet ports malfunction ?

 

I have requested RMA, but afraid of this happen the same , I think the difference is start from 9.2 I will not import snapshot config

in the beginning but configured to get license first

 

the base image is deleted in software , I do not know whether maintenance mode get the version 9.2

because when it boot , it show 10.2  banner , now can not get license because outside port has problem

I am a Palo Alto user setup Palo Alto Firewall from new and clean Palo Alto from the beginning. Advanced threat, Wildfire, advanced URL and advanced DNS are my licenses.

Cyber Elite
Cyber Elite

the one light is 'link' the second light is 1gbps (100mbps has only 1 light) so you may need to play areound with your speed and duplex settings on that interface to match whatever you are connecting to

sounds like the upstream device may have a static configuration or incompatible auto sequence

Tom Piens
PANgurus - Strata specialist; config reviews, policy optimization

I know the problem now

there is another interface using the same network address and netmask same as DHCP client

now it can online now

 

but validate old image 10.0.0 and 10.2.0 has no selection to validate

 

though I do not know where it get base image of 10.2 , I do not dare to delete 10.0.0 and 10.2.0 to download through internet again

because previously it failed to download

 

I just afraid next time it reboot or restart , it will need to factory reset again

 

 

today afternoon, support said SSL decrypt need default certificate

 

then I enable back certificate of china, hong kong ,japan  korea , taiwan and thailand default certificate,

but there is no save button to save change and no commit need

then I change one of interface static IP address, still no commit and no save changes

then I change from super user to admin user
and find no need to commit change, the certificate had already been enabled

why it bypass save change and commit after change IP address of unused interface?

I am a Palo Alto user setup Palo Alto Firewall from new and clean Palo Alto from the beginning. Advanced threat, Wildfire, advanced URL and advanced DNS are my licenses.
  • 1788 Views
  • 4 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!