<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Upgrading Active/Passive pair, pause in between upgrades? in Next-Generation Firewall Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/upgrading-active-passive-pair-pause-in-between-upgrades/m-p/1249429#M6753</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/7542"&gt;@jambulo&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-end="570" data-start="257"&gt;I would recommend upgrading your FW02 to your target version first. Once it comes back up, you could manually fail over and make FW02 active to validate everything is working as expected. If you run into any issues, you can always fail back to FW01, which is still running the previous PAN-OS version.&lt;/P&gt;
&lt;P data-end="570" data-start="257"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-end="908" data-start="572"&gt;Since you plan on validating for a bit longer, just be mindful of pushing configuration changes during that time. With mismatched PAN-OS versions, I wouldn’t rely on configuration sync between the two firewalls. If you do need to make changes, it’s best to document them so you can manually apply them to the other firewall &lt;STRONG&gt;IF&lt;/STRONG&gt; needed.&amp;nbsp;&lt;/P&gt;
&lt;P data-end="908" data-start="572"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-end="908" data-start="572"&gt;I would also recommend creating a testing plan rather than keeping the upgraded unit active for an arbitrary amount of time. For example, test egress connectivity, inter-zone traffic,&amp;nbsp; GlobalProtect, DMZ traffic, app traffic, verify routing, S2S tunnels, etc. If you coordinate the right stakeholders and walk through these tests together, you can usually validate everything much faster and reduce the amount of time the HA pair is running on mismatched versions.&lt;/P&gt;</description>
    <pubDate>Wed, 04 Mar 2026 14:17:58 GMT</pubDate>
    <dc:creator>JayGolf</dc:creator>
    <dc:date>2026-03-04T14:17:58Z</dc:date>
    <item>
      <title>Upgrading Active/Passive pair, pause in between upgrades?</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/upgrading-active-passive-pair-pause-in-between-upgrades/m-p/1249428#M6752</link>
      <description>&lt;P&gt;When upgrading PAN-OS on an Active/Passive pair, does any pause for 1 or more days after upgrading the first firewall (and before upgrading the second firewall)?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The idea here is we will have a bit more time to test for issues. If there is a failure post upgrade, we will have the option to suspend the upgraded firewall and make the firewall that did not yet get upgraded, active.&lt;/P&gt;</description>
      <pubDate>Wed, 04 Mar 2026 13:45:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/upgrading-active-passive-pair-pause-in-between-upgrades/m-p/1249428#M6752</guid>
      <dc:creator>jambulo</dc:creator>
      <dc:date>2026-03-04T13:45:04Z</dc:date>
    </item>
    <item>
      <title>Re: Upgrading Active/Passive pair, pause in between upgrades?</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/upgrading-active-passive-pair-pause-in-between-upgrades/m-p/1249429#M6753</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/7542"&gt;@jambulo&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-end="570" data-start="257"&gt;I would recommend upgrading your FW02 to your target version first. Once it comes back up, you could manually fail over and make FW02 active to validate everything is working as expected. If you run into any issues, you can always fail back to FW01, which is still running the previous PAN-OS version.&lt;/P&gt;
&lt;P data-end="570" data-start="257"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-end="908" data-start="572"&gt;Since you plan on validating for a bit longer, just be mindful of pushing configuration changes during that time. With mismatched PAN-OS versions, I wouldn’t rely on configuration sync between the two firewalls. If you do need to make changes, it’s best to document them so you can manually apply them to the other firewall &lt;STRONG&gt;IF&lt;/STRONG&gt; needed.&amp;nbsp;&lt;/P&gt;
&lt;P data-end="908" data-start="572"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-end="908" data-start="572"&gt;I would also recommend creating a testing plan rather than keeping the upgraded unit active for an arbitrary amount of time. For example, test egress connectivity, inter-zone traffic,&amp;nbsp; GlobalProtect, DMZ traffic, app traffic, verify routing, S2S tunnels, etc. If you coordinate the right stakeholders and walk through these tests together, you can usually validate everything much faster and reduce the amount of time the HA pair is running on mismatched versions.&lt;/P&gt;</description>
      <pubDate>Wed, 04 Mar 2026 14:17:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/upgrading-active-passive-pair-pause-in-between-upgrades/m-p/1249429#M6753</guid>
      <dc:creator>JayGolf</dc:creator>
      <dc:date>2026-03-04T14:17:58Z</dc:date>
    </item>
    <item>
      <title>Re: Upgrading Active/Passive pair, pause in between upgrades?</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/upgrading-active-passive-pair-pause-in-between-upgrades/m-p/1249459#M6754</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/7542"&gt;@jambulo&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;I personally would not recommend having mismatched PAN-OS versions for any sort of extended period. In the event that you encounter an issue, you can easily swap partitions on your passive unit and then force it to take over the active role. I just don't see a need when reverting an update takes a minimal amount of time in an HA environment with minimal disruption, or no disruption, as you failover traffic.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/220841"&gt;@JayGolf&lt;/a&gt;&amp;nbsp;mentioned you're just kind of asking for something to be forgotten or configuration drift to occur. I've seen far too many people who have failed to remember to upgrade the passive unit, encounter issues after a failover because they neglected to sync the configuration, or mistakenly sync the "old" configuration between units.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 04 Mar 2026 22:25:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/upgrading-active-passive-pair-pause-in-between-upgrades/m-p/1249459#M6754</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2026-03-04T22:25:58Z</dc:date>
    </item>
    <item>
      <title>Re: Upgrading Active/Passive pair, pause in between upgrades?</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/upgrading-active-passive-pair-pause-in-between-upgrades/m-p/1249615#M6756</link>
      <description>&lt;P&gt;Thanks for the response.&lt;/P&gt;
&lt;P&gt;We're choosing to upgrade FW01(designated "active" firewall) first so we are certain that we are upgrading a firewall that is in a known healthy state.&lt;/P&gt;
&lt;P&gt;Good call on the config changes, definitely something to keep in mind.&lt;/P&gt;
&lt;P&gt;We do have a test plan to run through right after the upgrade, but in our experiences, issues/bugs do not show themselves until 1+ days after the upgrade.&lt;/P&gt;</description>
      <pubDate>Fri, 06 Mar 2026 13:33:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/upgrading-active-passive-pair-pause-in-between-upgrades/m-p/1249615#M6756</guid>
      <dc:creator>jambulo</dc:creator>
      <dc:date>2026-03-06T13:33:04Z</dc:date>
    </item>
    <item>
      <title>Re: Upgrading Active/Passive pair, pause in between upgrades?</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/upgrading-active-passive-pair-pause-in-between-upgrades/m-p/1249640#M6757</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;Like&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/220841"&gt;@JayGolf&lt;/a&gt;&amp;nbsp;stated, do FW02 first. If youre going to do FW01, just do them both.&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Fri, 06 Mar 2026 21:21:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/upgrading-active-passive-pair-pause-in-between-upgrades/m-p/1249640#M6757</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2026-03-06T21:21:25Z</dc:date>
    </item>
  </channel>
</rss>

