That's a nice, polite corporate line, but I smell male bovine droppings. I don't mean to be confrontational, but on both occasions where I've needed a hotfix (in my current installation, not counting previous positions), it's been for fairly major issues - the high management CPU with 4.1.11-h1, and from memory a HA synchronisation issue with 4.1.8-h3 - issues, especially in the case of the high management CPU which were/are affecting a *lot* of people, judging by the comments and queries in this forum. Releasing these to general population and posting a broadcast email to subscribers (as is done for maintenance outages etc) would be the best action - then users can choose to apply the hotfix if they're experiencing the issue concerned. And your comment about thorough QA is patently untrue - if it was, then the issue with the management CPU wouldn't exist across several different releases 9I've seen reports of it from 4.1.11, 5.0.1 & 5.0.2 so far) - or, if it's true, Palo Alto needs to hire some new QA engineers, because the existing ones are falling down on the job - these aren't obscure, little problems - they're issues which are part of the *core* of the system which makes Palo Alto better than, say, Cisco or Checkpoint - and they...are...failing. Either Palo Alto's definition of a "full QA testing cycle" is different to mine, or it's not being done properly. OK, maybe I *do* mean to be confrontational. But with what we pay for these boxes compared to other solutions, I expect them to work WITHOUT running into such basic bugs.
... View more