<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Palo Alto Cluster Upgrade in Next-Generation Firewall Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/palo-alto-cluster-upgrade/m-p/564508#M2057</link>
    <description>&lt;P&gt;are your DC and DR clustered (via HA4)? If yes, all members of the cluster should be on the same PAN-OS. If the DR is simply a copy (managed by Panorama or not doesn't really matter), it won't matter if the DR is upgraded way ahead of the normal DC&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;to upgrade the HA cluster, i'd recommend the following:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;- disable preempt&lt;/P&gt;
&lt;P&gt;- suspend the primary firewall (this triggers a failover to the secondary, this is a good 'double check' to see if your secondary is passing traffic as expected. if this part fails, troubleshoot connectivity on the secondary before going forward with the upgrade)&lt;/P&gt;
&lt;P&gt;- install your desired PAN-OS on the primary&lt;/P&gt;
&lt;P&gt;- make primary active again and suspend secondary&lt;/P&gt;
&lt;P&gt;- check if everything's still working as expected&lt;/P&gt;
&lt;P&gt;- upgrade secondary&lt;/P&gt;
&lt;P&gt;- enable preempt again if you had it enabled&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;if the 'distance' between current and future PAN-OS is too great, you'll have to repeat this process a few times i.e. coming from 9.1 to 10.1 you'll have to do a layover on 10.0 for both peers before moving on to 10.1.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-upgrade" target="_blank" rel="noopener"&gt;https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-upgrade&lt;/A&gt;&amp;nbsp;&amp;lt;- the upgrade guide&lt;/P&gt;</description>
    <pubDate>Mon, 06 Nov 2023 13:40:21 GMT</pubDate>
    <dc:creator>reaper</dc:creator>
    <dc:date>2023-11-06T13:40:21Z</dc:date>
    <item>
      <title>Palo Alto Cluster Upgrade</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/palo-alto-cluster-upgrade/m-p/564467#M2054</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Our current setup is We have Active/Passive on main dc and standalone fw on DR site. Configured as Cluster.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It is identified that the DR site is affected by a certain CVE, and it is recommended for upgrade. But we also wish to upgrade the Active/Passive Main DC firewall.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I cannot find any articles on how to upgrade an Firewall Cluster, Can you share any tips on what approach upgrade for this setup?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Would there be no effect bearing if for example the Active/Passive Firewall is running on 10.1.0 then the DR Stand alone site is running on 10.1.0 version?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Mon, 06 Nov 2023 06:56:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/palo-alto-cluster-upgrade/m-p/564467#M2054</guid>
      <dc:creator>NickoKristian</dc:creator>
      <dc:date>2023-11-06T06:56:33Z</dc:date>
    </item>
    <item>
      <title>Re: Palo Alto Cluster Upgrade</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/palo-alto-cluster-upgrade/m-p/564506#M2056</link>
      <description>&lt;P&gt;Upgrade passive, reboot passive.&lt;/P&gt;
&lt;P&gt;Upgrade active, reboot active.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What is your current version and what is goal version?&lt;/P&gt;</description>
      <pubDate>Mon, 06 Nov 2023 13:29:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/palo-alto-cluster-upgrade/m-p/564506#M2056</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2023-11-06T13:29:12Z</dc:date>
    </item>
    <item>
      <title>Re: Palo Alto Cluster Upgrade</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/palo-alto-cluster-upgrade/m-p/564508#M2057</link>
      <description>&lt;P&gt;are your DC and DR clustered (via HA4)? If yes, all members of the cluster should be on the same PAN-OS. If the DR is simply a copy (managed by Panorama or not doesn't really matter), it won't matter if the DR is upgraded way ahead of the normal DC&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;to upgrade the HA cluster, i'd recommend the following:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;- disable preempt&lt;/P&gt;
&lt;P&gt;- suspend the primary firewall (this triggers a failover to the secondary, this is a good 'double check' to see if your secondary is passing traffic as expected. if this part fails, troubleshoot connectivity on the secondary before going forward with the upgrade)&lt;/P&gt;
&lt;P&gt;- install your desired PAN-OS on the primary&lt;/P&gt;
&lt;P&gt;- make primary active again and suspend secondary&lt;/P&gt;
&lt;P&gt;- check if everything's still working as expected&lt;/P&gt;
&lt;P&gt;- upgrade secondary&lt;/P&gt;
&lt;P&gt;- enable preempt again if you had it enabled&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;if the 'distance' between current and future PAN-OS is too great, you'll have to repeat this process a few times i.e. coming from 9.1 to 10.1 you'll have to do a layover on 10.0 for both peers before moving on to 10.1.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-upgrade" target="_blank" rel="noopener"&gt;https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-upgrade&lt;/A&gt;&amp;nbsp;&amp;lt;- the upgrade guide&lt;/P&gt;</description>
      <pubDate>Mon, 06 Nov 2023 13:40:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/palo-alto-cluster-upgrade/m-p/564508#M2057</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2023-11-06T13:40:21Z</dc:date>
    </item>
  </channel>
</rss>

