Intermittent connection issue after upgrade to 9.1.14

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.
Palo Alto Networks Approved
Palo Alto Networks Approved
Community Expert Verified
Community Expert Verified

Intermittent connection issue after upgrade to 9.1.14

L1 Bithead

Anyone out there facing issue with LSVPN connection after upgrading to 9.1.14?

After upgrading gateway firewall to 9.1.14 , all satellite offices to the gateway are reporting intermittent connectivity.

I don't see any issue with LSVPN tunnel between sat and gw but connection to internal network drop in a specific pattern.

I believe its a bug and has open a case with PA support since it has only been a week this code is out.

3 accepted solutions

Accepted Solutions

Cyber Elite
Cyber Elite

Hi @Nischal ,

 

Have you seen this link -> https://live.paloaltonetworks.com/t5/customer-resources/support-pan-os-software-release-guidance/ta-....  PAN-OS 9.1.13-h3 is the preferred release right now.  I would stick with it.

 

Thanks,

 

Tom

Help the community: Like helpful comments and mark solutions.

View solution in original post

Well our GP clients to same gateway are not facing issue but all satellite office to same gateway are facing this issue. 

Post changing tunnel monitor profile from custom (fail-over) to default (wait-recover) helped stabilize the LSVPN connection.

Strangely the tunnel monitor didn't show going down. 

PAN-187151 is fixed both in 9.1.13h3 and 9.1.14 but seems somehow its not yet fixed in these codes.

Ticket opened with PA support , waiting for their update

View solution in original post

We reverted to 9.1.13-H3 and the problems were resolved, not sure what's up with 9.1.14 we upgraded last Friday and the problems started this afternoon at 2:30PM and impacted both IPSEC connections and global protect.

View solution in original post

5 REPLIES 5

L1 Bithead

We are seeing issues with out Azure tunnel and today we started having issues with Global Protect failing to connect.

Cyber Elite
Cyber Elite

Hi @Nischal ,

 

Have you seen this link -> https://live.paloaltonetworks.com/t5/customer-resources/support-pan-os-software-release-guidance/ta-....  PAN-OS 9.1.13-h3 is the preferred release right now.  I would stick with it.

 

Thanks,

 

Tom

Help the community: Like helpful comments and mark solutions.

Well our GP clients to same gateway are not facing issue but all satellite office to same gateway are facing this issue. 

Post changing tunnel monitor profile from custom (fail-over) to default (wait-recover) helped stabilize the LSVPN connection.

Strangely the tunnel monitor didn't show going down. 

PAN-187151 is fixed both in 9.1.13h3 and 9.1.14 but seems somehow its not yet fixed in these codes.

Ticket opened with PA support , waiting for their update

We reverted to 9.1.13-H3 and the problems were resolved, not sure what's up with 9.1.14 we upgraded last Friday and the problems started this afternoon at 2:30PM and impacted both IPSEC connections and global protect.

Thank you for pointing us in the right direction, we were contemplating reverting back but this sealed the deal and reverting resolved all of our issues.

  • 3 accepted solutions
  • 3020 Views
  • 5 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!