<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic software update question in Next-Generation Firewall Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/software-update-question/m-p/595643#M3616</link>
    <description>&lt;P&gt;When updating Palo firewalls, why the need to update through each base version as well as a preferred maintenance version?&lt;/P&gt;
&lt;P&gt;e.g. if going from version 8.1.x, to 10.1.x,&amp;nbsp; why 9.0 &amp;gt;&amp;nbsp; 9.0.x &amp;gt; 9.1 &amp;gt; 9.1 &amp;gt; 10.0 etc.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;IF each baseline version release e.g. 9.0, 9.1, 10.0 is a full release of the software then what is to stop upgrading to 9.0 &amp;gt; 10.0 &amp;gt; 10.1 skipping the interim preferred maintenance releases?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The only obvious 2x explanations that I can come up with are :&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;the baseline releases for 9.0, 10.0 etc are not in fact full versions of the firewall software and must have a dependency on previous versions.&lt;/LI&gt;
&lt;LI&gt;The preferred maintenance versions are ONLY required if upgrading a firewall with an existing configuration, so that each version update can rewrite each policy rule in line with internal database changes etc. thus not corrupting the configuration if theoretically jumping from 8.1.x to 10.1.0 for example.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Does anyone have any internal level of technical understanding which can confirm if I can get away with upgrading from 8.1.x to 10.1.0 without interim versions, on an otherwise factory reset firewall with no customised configuration in place?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Always curious!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 22 Aug 2024 15:41:57 GMT</pubDate>
    <dc:creator>Dustynet</dc:creator>
    <dc:date>2024-08-22T15:41:57Z</dc:date>
    <item>
      <title>software update question</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/software-update-question/m-p/595643#M3616</link>
      <description>&lt;P&gt;When updating Palo firewalls, why the need to update through each base version as well as a preferred maintenance version?&lt;/P&gt;
&lt;P&gt;e.g. if going from version 8.1.x, to 10.1.x,&amp;nbsp; why 9.0 &amp;gt;&amp;nbsp; 9.0.x &amp;gt; 9.1 &amp;gt; 9.1 &amp;gt; 10.0 etc.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;IF each baseline version release e.g. 9.0, 9.1, 10.0 is a full release of the software then what is to stop upgrading to 9.0 &amp;gt; 10.0 &amp;gt; 10.1 skipping the interim preferred maintenance releases?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The only obvious 2x explanations that I can come up with are :&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;the baseline releases for 9.0, 10.0 etc are not in fact full versions of the firewall software and must have a dependency on previous versions.&lt;/LI&gt;
&lt;LI&gt;The preferred maintenance versions are ONLY required if upgrading a firewall with an existing configuration, so that each version update can rewrite each policy rule in line with internal database changes etc. thus not corrupting the configuration if theoretically jumping from 8.1.x to 10.1.0 for example.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Does anyone have any internal level of technical understanding which can confirm if I can get away with upgrading from 8.1.x to 10.1.0 without interim versions, on an otherwise factory reset firewall with no customised configuration in place?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Always curious!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 22 Aug 2024 15:41:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/software-update-question/m-p/595643#M3616</guid>
      <dc:creator>Dustynet</dc:creator>
      <dc:date>2024-08-22T15:41:57Z</dc:date>
    </item>
    <item>
      <title>Re: software update question</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/software-update-question/m-p/596007#M3642</link>
      <description>&lt;P&gt;it is perfectly possible to perform these upgrades using only the base versions&lt;/P&gt;
&lt;P&gt;that said, it is recommended to also download the latest maintenance release to protect you from running into any bugs while you're upgrading&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;so you can do&amp;nbsp;&lt;/P&gt;
&lt;P&gt;8.1.x &amp;gt; 9.0.0 &amp;gt; 9.1.0 &amp;gt; 10.0.0 &amp;gt; 10.1.0 (starting from 10.1 you can actually skip intermediate versions so you could do 10.1 &amp;gt; 11.1)&lt;/P&gt;
&lt;P&gt;but if you run into a bug, you may need to get TAC involved and your upgrade grinds to a halt&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;hence the recommendation to&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;from 8.1.x&lt;/P&gt;
&lt;P&gt;download 9.0.0 and 9.0.17-h5, install and reboot 9.0.17-h5&lt;/P&gt;
&lt;P&gt;download 9.1.0 and 9.1.18, install and reboot 9.1.18&lt;/P&gt;
&lt;P&gt;download 10.0.0 and 10.0.12, install and reboot 10.0.12&lt;/P&gt;
&lt;P&gt;download 10.1.0 and 10.1.13-h1, install and reboot 10.1.13-h1&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;if you're feeling lucky and there's no config on the firewall, feel free to go for the base images only&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;hope this helps&lt;/P&gt;</description>
      <pubDate>Mon, 26 Aug 2024 23:29:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/software-update-question/m-p/596007#M3642</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2024-08-26T23:29:31Z</dc:date>
    </item>
  </channel>
</rss>

