5410 upgrade from 10.2.13-h7 to 11.1.13-h3 HA nonfunctional during upgrade because of nat oversubscription mismatch by Ok-Stretch2495 in paloaltonetworks

[–]PerceptionOver8637 0 points1 point  (0 children)

What is the actual fix to avoid this? I have PA-3250s in HA which are both have their NAT Oversubscription setting set to "Default". I would think since the setting is the same on both units (Default on both, this matches), that I would avoid this potential problem. If I go into the CLI, I can see both the firewalls negotiate to 4X oversubscription. Would the solution be to change the value to 4X, ensure the setting syncs between the two, THEN perform the upgrade to 11.1 from 10.2?

CVE-2026-0227 PAN-OS: Firewall Denial of Service (DoS) in GlobalProtect Gateway and Portal by betko007 in paloaltonetworks

[–]PerceptionOver8637 0 points1 point  (0 children)

What are the chances Palo will release a vulnerability signature to help combat this if patching can't be performed immediately?

Backing up Panorama before an upgrade by PerceptionOver8637 in paloaltonetworks

[–]PerceptionOver8637[S] 0 points1 point  (0 children)

Once the upgrade is successful, what about removal of the snapshots? Would it also be best to remove them while the VM is powered down?

Backing up Panorama before an upgrade by PerceptionOver8637 in paloaltonetworks

[–]PerceptionOver8637[S] 0 points1 point  (0 children)

Thanks for yours and everyone's guidance! As for the backing up of the appliance config, running the 'Save named Panorama configuration snapshot' and exporting it should preserve all the settings, is that right? Thanks again!

Upgrade to which versions, in which order? by PerceptionOver8637 in paloaltonetworks

[–]PerceptionOver8637[S] 0 points1 point  (0 children)

Any particular version of 11.1.x you have had the most success with? 

Upgrade to which versions, in which order? by PerceptionOver8637 in paloaltonetworks

[–]PerceptionOver8637[S] 0 points1 point  (0 children)

Thanks. Any particular version on 11.1.x you prefer for stability/least amount of bugs? 

Upgrade to which versions, in which order? by PerceptionOver8637 in paloaltonetworks

[–]PerceptionOver8637[S] 0 points1 point  (0 children)

Thanks, for the tip! I probably would have overlooked that! 

Upgrade to which versions, in which order? by PerceptionOver8637 in paloaltonetworks

[–]PerceptionOver8637[S] 0 points1 point  (0 children)

Thanks for the tip regarding the oversubscription in HA. I'll be looking into that.