Configuration guides for IT Administrators

Challenges upgrading Paloalto firewall to 8.1.0 Version

Challenges upgrading Paloalto firewall to 8.1.0 Version

We were upgrading all paloalto firewall appliances to latest base version 8.1.0 and we encountered numerous issues. We are sharing our experience here, you may also consider with caution while upgrading to latest version.

1. SMB traffic are blocked:

Paloalto firewall blocks SMB traffic traversing through it. You cannot access the share drives that are located in a server behind Paloalto firewall, this is applicable if you are accessing share drives over VPN. In the firewall traffic logs, you will notice that the traffic were allowed as per the rule configured, however PA considers the resource to be ‘resource-unavailable’ and blocks it internally.

The solution to override SMB traffic – click to read.

2. False-positive Oracle vulnerability:

HostGator $2.75 per month
HostGator
24/7/365 Technical Support, Free Site Building Tools, 4500 Website Templates, Free Shopping Cart Software, Ideal for WordPress, 45 Day Money Back Guarantee

Paloalto firewall blocks connections to Oracle database over 1521 port, based on a vulnerability identified on Oracle DB version 10.1.0.5 and 10.2.0.4. However our Oracle DB is running a different higher version and not vulnerable. You can search in Vulnerability DB for ID 3291 and get to know more details.

The solution to bypass such filter is to IP address exception to an Vulnerability – click to read.

3. User-ID authentication :

All in One WordPress Hosting Starts at 30$ per month
All in One WordPress Hosting
WordPress
High optimized WordPress hosting, secure firewall, HTTPS, Backup, hack-fix guarantee and many others at 30$ per month

This issue has occurred only at one site , while 4 other sites have not faced this issue after upgrading to 8.1.0 version.

Users started to receive ‘Website Blocked’ message for legitimate websites that are permitted for their windows login account in the PA firewall security policies.  There was no user-id mapping issue as we could see the domain user name listed properly in their browser. But this is what we eventually found out while investigating further, the users who reported problems were seen as domain.com\username in the Paloalto User-Id Agent tool, rest all haven’t faced issue.

As this was a show stopper, we had to roll back to previous version and unfortunately, there was no time given to explore further.

2 responses to “Challenges upgrading Paloalto firewall to 8.1.0 Version”

  1. Ram avatar
    Ram

    good job..usefull

  2. Anya162mr avatar

    Hello guys!
    I came across a 162 useful tool that I think you should take a look at.
    This site is packed with a lot of useful information that you might find valuable.
    It has everything you could possibly need, so be sure to give it a visit!
    https://thelakewoodscoop.com/news/how-to-place-bets-play-games-and-develop-yourself/

    And don’t overlook, guys, which one always may inside the article discover responses for the the very complicated queries. We tried to present the complete information via an most easy-to-grasp method.

Leave a Reply

Your email address will not be published. Required fields are marked *

Lucas Brey

I’m Lucas Brey, a travel blogger sharing practical guides, hidden gems, and honest tips from the road. Follow along for smart itineraries, great food finds, and stories worth bookmarking.

Tags