Hello,
So I upgraded to 10.2.10-h9 (current preferred release). After doing so when I click “check now” for updates on the global protect tab I get the error
“request → global-protect-client → software → check → preferred unexpected here”
This happens on multiple firewalls. So I opened a ticket. The solution per support is:
- Go to Device->software and uncheck the preferred release and base release to see all the version.
- After unchecking these options, Go to globalprotectclient tab and then do ‘check now’
Also per support this is as designed.
How does this make any sense? 1) A lot of people aren’t going to know that without opening a support ticket 2) the unchecking of those items under software is not permanent, so every time you visit the software page they revert and you have to uncheck them again or next time you go to the globalprotect tab you get the error again.
—-
Update
FYI from after escalating with support and managers and getting engineering involved:
“Wanted to update you that engineering team has provided a code fix for this issue (JIRA ID : PAN-276795) which will be tested by QA and released in future releases.
Engineering team is updating the logic that for softwareType ‘global-protect-client’ and ‘vpnclient’ - base and preferred options are not applicable. This should not throw error seen when we click on “Check Now” button on GlobalProtect Client screen.”
Confirmed, I hate it all too. Same thing applies for code versions, It only shows the preferred releases. Best is the smaller firewalls take forever to re-draw the page.
At least remember my settings. I hate refreshing the page only to have to uncheck → wait a few minutes for the stupid thing to load again → uncheck the other box → wait longer.
Default show is preferred release.
Yeah it sucks instead of showing everything, them allow to user to filter down.
It’s an amazing feature. Love it for both panos and go client.
Sorry. Joking. Their junkets and merch aren’t good enough to make me forget that the real answer is to not have so many SHITE SOFTWARE releases concurrently that the admin has to filter through. Legitimately- even this “feature “ is a joke, admins should 100% be reading release notes and reviewing the recommended versions page which has a bit more info. Relying on this feature is absolutely insufficient at any rate.
Yet more shtfckry no one really asked for. Maybe it has expensive generative ai though?
I lost 2 weeks of my life because 11.1.2-h3 was a “preferred release” if we would have upgraded to 11.1.4-h1 we would have had zero problems.
The same “fix” worked for me, too. I’m not in love with the new Software option checkboxes. I DO appreciate that off to the far right, the different builds display if they’re a base image, preferred, etc. Past that, I don’t need this sort of masking applied by default to keep me from installing something I don’t want.
FYI from after escalating with support and managers and getting engineering involved:
“Wanted to update you that engineering team has provided a code fix for this issue (JIRA ID : PAN-276795) which will be tested by QA and released in future releases.
Engineering team is updating the logic that for softwareType ‘global-protect-client’ and ‘vpnclient’ - base and preferred options are not applicable. This should not throw error seen when we click on “Check Now” button on GlobalProtect Client screen.”
Most hilarious was at some points there has been nothing in that menu because there were no preferred releases.
They have a serious problem with code trains that I am convinced is leading to all these software screw ups lately.
After that last vulnerability, they released 40 different versions of code. Pure madness.
What happened to you with that release?
Hahahaha. I think I saw a h18 hotfix in there somewhere.
I was like “the crack smoking is strong at PANW “
Yeh if you look at the software release guidance they didn’t have a new preferred 10.2 version since May, so 6-7 months because everyone they released was riddled with issues.
Pretty much. We hit all of them, I think.