<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Pan OS upgrade in HA pair 10.0.9 to 10.2.3 in Next-Generation Firewall Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/pan-os-upgrade-in-ha-pair-10-0-9-to-10-2-3/m-p/543534#M1340</link>
    <description>&lt;P&gt;I have vm series in ha pair managed by the panorama(10.2.3). When I look the upgrade path it appears&lt;/P&gt;
&lt;P&gt;10.0.9 -&amp;gt;10.0.11-h1 -&amp;gt; 10.1.0 -&amp;gt;10.1.10-&amp;gt;10.2.0 -&amp;gt; 10.2.3. I have confusion on fail over, do I need to fail over on each version?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 26 May 2023 17:36:00 GMT</pubDate>
    <dc:creator>MPappachan</dc:creator>
    <dc:date>2023-05-26T17:36:00Z</dc:date>
    <item>
      <title>Pan OS upgrade in HA pair 10.0.9 to 10.2.3</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/pan-os-upgrade-in-ha-pair-10-0-9-to-10-2-3/m-p/543534#M1340</link>
      <description>&lt;P&gt;I have vm series in ha pair managed by the panorama(10.2.3). When I look the upgrade path it appears&lt;/P&gt;
&lt;P&gt;10.0.9 -&amp;gt;10.0.11-h1 -&amp;gt; 10.1.0 -&amp;gt;10.1.10-&amp;gt;10.2.0 -&amp;gt; 10.2.3. I have confusion on fail over, do I need to fail over on each version?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 26 May 2023 17:36:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/pan-os-upgrade-in-ha-pair-10-0-9-to-10-2-3/m-p/543534#M1340</guid>
      <dc:creator>MPappachan</dc:creator>
      <dc:date>2023-05-26T17:36:00Z</dc:date>
    </item>
    <item>
      <title>Re: Pan OS upgrade in HA pair 10.0.9 to 10.2.3</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/pan-os-upgrade-in-ha-pair-10-0-9-to-10-2-3/m-p/543541#M1341</link>
      <description>&lt;P&gt;Yes you need to fail over every time.&lt;/P&gt;
&lt;P&gt;Upgrade passive, reboot.&lt;/P&gt;
&lt;P&gt;Upgrade active, reboot.&lt;/P&gt;
&lt;P&gt;repeat...&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Although I like path you suggested and I follow it myself there is a way to save time if you are in a rush.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Starting point 10.0.9&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Download and install 10.0.11-h1&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Download&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;10.1.0&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Download and install 10.1.10&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Download 10.2.0 &lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Download and install 10.2.4 (10.2.3 unless you can upgrade Panorama before).&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;10.2.4 is currently preferred release.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Raido_Rattameister_0-1685125563207.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/50366iA45020BCAF556F89/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Raido_Rattameister_0-1685125563207.png" alt="Raido_Rattameister_0-1685125563207.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;One thing to keep in mind is that virtual Palos use hypervisor assigned mac addresses not virtual floating mac.&lt;/P&gt;
&lt;P&gt;This means that mac addresses change during failover.&lt;/P&gt;
&lt;P&gt;If you have devices that don't accept gratuitous arp then you need to clear their arp table.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Good example is other Palo firewalls themselves that don't update their arp table if gratuitous arp is received.&lt;/P&gt;</description>
      <pubDate>Fri, 26 May 2023 18:28:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/pan-os-upgrade-in-ha-pair-10-0-9-to-10-2-3/m-p/543541#M1341</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2023-05-26T18:28:55Z</dc:date>
    </item>
    <item>
      <title>Re: Pan OS upgrade in HA pair 10.0.9 to 10.2.3</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/pan-os-upgrade-in-ha-pair-10-0-9-to-10-2-3/m-p/543549#M1343</link>
      <description>&lt;P&gt;Thank you for your detailed responses. One more clarification, are you skipping the steps for 'Disable preemptive, request&amp;nbsp;high-availability state suspend and request high-availability functional state? for each fail over or is that included?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks again.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 26 May 2023 19:59:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/pan-os-upgrade-in-ha-pair-10-0-9-to-10-2-3/m-p/543549#M1343</guid>
      <dc:creator>MPappachan</dc:creator>
      <dc:date>2023-05-26T19:59:23Z</dc:date>
    </item>
    <item>
      <title>Re: Pan OS upgrade in HA pair 10.0.9 to 10.2.3</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/pan-os-upgrade-in-ha-pair-10-0-9-to-10-2-3/m-p/543550#M1344</link>
      <description>&lt;P&gt;Yes I skip manual failover.&lt;/P&gt;
&lt;P&gt;After passive is upgraded/rebooted I upgrade and reboot active and let firewalls to perform HA automatically.&lt;BR /&gt;When active goes to reboot then passive will become automatically active.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As I often upgrade remote firewalls I don't like to place any firewall into suspend state.&lt;/P&gt;
&lt;P&gt;I also have preemt enabled so when primary firewall returns from reboot it will take active role back automatically as well.&lt;/P&gt;</description>
      <pubDate>Fri, 26 May 2023 20:11:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/pan-os-upgrade-in-ha-pair-10-0-9-to-10-2-3/m-p/543550#M1344</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2023-05-26T20:11:09Z</dc:date>
    </item>
  </channel>
</rss>

