Pan-OS 10.2.13-h4 known issues

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Pan-OS 10.2.13-h4 known issues

L1 Bithead

Hello everyone, 

 

Can I ask if anyone already installed Pan-OS 10.2.13-h4 on their firewalls? Any issues with this hotfix? 

 

I am hesitant to install it after reading reddit comments about the 10.2.13-h3 and how it breaks IPv6. 

1 accepted solution

Accepted Solutions

L4 Transporter

Hello @pavel.sharypov ,

 

I would suggest you to upgrade one device and monitor first if any side effect.

As its name implies, it is a hotfix version, it has its associated risks compared to a normal release.

Regarding the feedback from third party, I would suggest for you to take it "as is" ("zero trust" mindset, always verify the facts).

Olivier

PCSNE - CISSP

Best Effort contributor

Check out our PANCast Channel

Disclaimer : All messages are my personal ones and do not represent my company's view in any way.

View solution in original post

5 REPLIES 5

L1 Bithead

Just upgrade to 10.2.13h4 from 10.2.12h2 over the weekend, firewall locked up, I am running AWS version still trying to figure out what the issue was. 

L4 Transporter

Hello @pavel.sharypov ,

 

I would suggest you to upgrade one device and monitor first if any side effect.

As its name implies, it is a hotfix version, it has its associated risks compared to a normal release.

Regarding the feedback from third party, I would suggest for you to take it "as is" ("zero trust" mindset, always verify the facts).

Olivier

PCSNE - CISSP

Best Effort contributor

Check out our PANCast Channel

Disclaimer : All messages are my personal ones and do not represent my company's view in any way.

I upgraded several firewalls and I am noticing an issue with Azure SAML when the authentication page shows as blank. If I restart Windows or pangp service on the affected laptops, then the authentication page shows normal. 

 

Found this article but adding additional azure authentication portals into fqdn exception list doesn't seem to fix the issue.

Globalprotect SAML Authentication login screen does not load an... - Knowledge Base - Palo Alto Netw...

Enforce GP Connection feature is on. I didn't see this issue at all before installing pan-os 10.2.13-h4. GP logs also don't show any blocked fqdn so now I am hesitant to apply 10.2.13-h4 on every firewall to be honest. 

I am using an embedded browser for SAML authentication. It turns out that it is something related to the window size. When I stretched it a bit, the login page appeared without any issues 😑

this is a GP client issue, not PAN-OS issue 😉

PCSNE - CISSP

Best Effort contributor

Check out our PANCast Channel

Disclaimer : All messages are my personal ones and do not represent my company's view in any way.

  • 1 accepted solution
  • 725 Views
  • 5 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!