- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
11-13-2019 04:01 AM
We are having a warning when we push in panorama:
We have check the apps&threats version and everything is OK. Panorama version is 9.0.4. It could be a cosmetic issue?
11-21-2019 08:43 AM
Not that I am aware of... short of recommending that you upgrade FWs (or downgrade Panorama)
11-13-2019 10:10 AM
http2 is a new protocol decoder in the 9.0.x version of the PANOS.
Is this message seen on the Panorama, or on a FW that receives its config from the Panorama.
If you go under your AntiVirus Profile, how many protocol decoders do you see?
11-21-2019 08:19 AM
Yes, you are right. Panorama is in version 9.0.4, and FWs in 8.1.10.
Is there any way to delete this warning in Panorama?
11-21-2019 08:43 AM
Not that I am aware of... short of recommending that you upgrade FWs (or downgrade Panorama)
01-21-2020 08:24 AM
I can confirm Panorama 9.0.5 push to 8.1.12 (pa5060) still has this warning. Will 9.0.6 resolve this (if/when released)? Does 9.1.0 resolve this?
Any one from Palo Alto wish to comment?
01-21-2020 08:48 AM
As soon as you upgrade the firewall to 9.0.x or downgrade panorama to 8.1.x the warning will disappear.
If you only upgrade panorama to 9.0.6 or even 9.1.0 but the firewall stays on 8.1.x this won't change anything.
01-21-2020 09:03 AM
Thanks for the quick response. So Panorama 9.x does not fully support 8.1.x firewalls? If it does, then it should be smart enough to know that a 8.1.x firewall doesn't support http/2 and not produce a red warning message. PA5060s cannot run 9.x
If one is using Panorama to manage several firewalls (which is by design), and most are at 9.x but a couple have to stay at 8.1.x (ex. PA5060), then having Panorama at 9.x would make sense for the majority of the other firewalls. I feel this is a UI defect as a warning shouldn't be produced when pushing from 9.x Panorama to 8.1.x PAN OS firewall(s).
01-21-2020 10:07 AM
What did you choose as option in the AV profile(/s) that is(/are) pushed to the 8.1 firewall for http2?
PS: I do not work for paloalto
01-21-2020 10:18 AM
Thanks for the response. It is set to allow for http2.
01-21-2020 10:34 AM
Did you try to set it to default in the profiles that are applied to your 8.1 firewall?
01-21-2020 10:53 AM
Hi, yes, it results in the same warning.
01-21-2020 10:58 AM
Ok, last try until I give up 😛
Did this warning start right then when you upgraded your panorama to 9.0.x? What about deleting the action in that profile (via cli on panorama), did you try this? The goal is to have a profile where maybe the http2 is shown in the web UI but not actually in the config that is applied to the firewall.
PS: I am with you that panorama should detect that as this warnkng is totally useless in this situation.
01-21-2020 11:41 AM
Hi, thanks for the help and support. No I didn't try that. I'll probably put in a support request. Obviously others have this issue, so maybe they will have a solution?
01-21-2020 12:32 PM
Give it a short try 😉
Maybe then you get rid of this warning as the other possibility is probably waiting for a fix ... and this could take some time - or you live with the warning...
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!