<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Delaying upgrade between an HA pair in Next-Generation Firewall Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/delaying-upgrade-between-an-ha-pair/m-p/1255935#M6958</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/7542"&gt;@jambulo&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Yes, I have upgraded an HA pair in that order, except I did not wait 1 or more days.&amp;nbsp; The HA pair will remain in an active/passive state as long as the PAN-OS version is &amp;lt;= one major version away.&amp;nbsp; "When HA peers are two or more feature releases apart, the firewall with the older release installed enters a &lt;STRONG&gt;&lt;SPAN class="ph systemoutput"&gt;suspended&lt;/SPAN&gt;&lt;/STRONG&gt; state with the message &lt;STRONG&gt;&lt;SPAN class="ph systemoutput"&gt;Peer version too old&lt;/SPAN&gt;&lt;/STRONG&gt;."&amp;nbsp;&amp;nbsp;&lt;A href="https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-upgrade/upgrade-pan-os/upgrade-the-firewall-pan-os/upgrade-an-ha-firewall-pair" target="_blank"&gt;https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-upgrade/upgrade-pan-os/upgrade-the-firewall-pan-os/upgrade-an-ha-firewall-pair&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Once you upgrade 1 NGFW, expect the Running Configuration and the PAN-OS Version status to turn red in the High Availability widget on the dashboard.&amp;nbsp; This is normal as the new version may modify the running configuration.&amp;nbsp; Do not sync the config.&amp;nbsp; Most of the time when you upgrade the 2nd NGFW, the running config will show synced again.&amp;nbsp; Everything else in the widget should show green except the passive NGFW will show yellow.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;So, in summary your process will work but I would not make changes on the NGFW during the mismatch because the config sync probably will not work.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;</description>
    <pubDate>Wed, 10 Jun 2026 20:47:08 GMT</pubDate>
    <dc:creator>TomYoung</dc:creator>
    <dc:date>2026-06-10T20:47:08Z</dc:date>
    <item>
      <title>Delaying upgrade between an HA pair</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/delaying-upgrade-between-an-ha-pair/m-p/1255459#M6951</link>
      <description>&lt;P&gt;Does any successfully perform their HA firewall upgrades in this manner?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;1. Upgrade the Seconday(passive) firewall.&lt;/P&gt;
&lt;P&gt;2. Make Secondary firewall Active.&lt;/P&gt;
&lt;P&gt;3. Wait 1 or more days.&lt;/P&gt;
&lt;P&gt;4. Upgrade the Primary(now passive) firewall.&lt;/P&gt;
&lt;P&gt;5. Make the Primary firewall active.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It would bring us a lot more comfort knowing that we can easily switch to a different firewall (on the older version) in the event of an issue caused by the upgrade. Will HA syncs still work(sessions, configs, etc) This could be for minor or major versions.&lt;/P&gt;</description>
      <pubDate>Thu, 04 Jun 2026 20:58:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/delaying-upgrade-between-an-ha-pair/m-p/1255459#M6951</guid>
      <dc:creator>jambulo</dc:creator>
      <dc:date>2026-06-04T20:58:06Z</dc:date>
    </item>
    <item>
      <title>Re: Delaying upgrade between an HA pair</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/delaying-upgrade-between-an-ha-pair/m-p/1255935#M6958</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/7542"&gt;@jambulo&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Yes, I have upgraded an HA pair in that order, except I did not wait 1 or more days.&amp;nbsp; The HA pair will remain in an active/passive state as long as the PAN-OS version is &amp;lt;= one major version away.&amp;nbsp; "When HA peers are two or more feature releases apart, the firewall with the older release installed enters a &lt;STRONG&gt;&lt;SPAN class="ph systemoutput"&gt;suspended&lt;/SPAN&gt;&lt;/STRONG&gt; state with the message &lt;STRONG&gt;&lt;SPAN class="ph systemoutput"&gt;Peer version too old&lt;/SPAN&gt;&lt;/STRONG&gt;."&amp;nbsp;&amp;nbsp;&lt;A href="https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-upgrade/upgrade-pan-os/upgrade-the-firewall-pan-os/upgrade-an-ha-firewall-pair" target="_blank"&gt;https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-upgrade/upgrade-pan-os/upgrade-the-firewall-pan-os/upgrade-an-ha-firewall-pair&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Once you upgrade 1 NGFW, expect the Running Configuration and the PAN-OS Version status to turn red in the High Availability widget on the dashboard.&amp;nbsp; This is normal as the new version may modify the running configuration.&amp;nbsp; Do not sync the config.&amp;nbsp; Most of the time when you upgrade the 2nd NGFW, the running config will show synced again.&amp;nbsp; Everything else in the widget should show green except the passive NGFW will show yellow.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;So, in summary your process will work but I would not make changes on the NGFW during the mismatch because the config sync probably will not work.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;</description>
      <pubDate>Wed, 10 Jun 2026 20:47:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/delaying-upgrade-between-an-ha-pair/m-p/1255935#M6958</guid>
      <dc:creator>TomYoung</dc:creator>
      <dc:date>2026-06-10T20:47:08Z</dc:date>
    </item>
  </channel>
</rss>

