<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Best practices - Multi large upgrades pan-os Firewall HA in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/best-practices-multi-large-upgrades-pan-os-firewall-ha/m-p/511734#M106363</link>
    <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Best practices - Multi large upgrades pan-os Firewall HA&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Good afternoon, as usual, thank you very much for your support and collaboration.&lt;/P&gt;
&lt;P&gt;We have the possibility with a customer to perform multiple upgrades in one day, maintenance window.&lt;/P&gt;
&lt;P&gt;We need to move from 8.1 to 9.1, i.e. 8.1.x to 9.0.x and from 9.0.x to 9.1.x.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;So the question is the following:&lt;/P&gt;
&lt;P&gt;1.- What is the best practice when it comes to make that jump, that intermediate upgrade from 9.0, for example when going from 8.1.x to ""9.0.x"" ( PAN-OS Intermediate, transitive ) final 9.1.x.&lt;/P&gt;
&lt;P&gt;That intermediate jump, what is the best practice: I mean, for example, the current version 8.1.5, download and install the base 9.0.0? or is it recommended to download the base (9.0.0) and download and install (the recommended version of 9.0.x (9.0.16-h2), although it is say the intermediate transition version? to reach the recommended version 9.1.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;2.- Also in relation to the same, the recommendation is still, in each jump, for example when moving to the same intermediate version 9.0, love or reassemble the HA and then continue with the upgrade ? or is it possible to apply both upgrades to a node and then on the other node ? I would understand that the best practice is to re-amplify the HA at each stage of the upgrade.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please give me your comments, advice, recommendations and suggestions.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you very much&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Best regards&lt;/P&gt;</description>
    <pubDate>Fri, 12 Aug 2022 16:00:42 GMT</pubDate>
    <dc:creator>Metgatz</dc:creator>
    <dc:date>2022-08-12T16:00:42Z</dc:date>
    <item>
      <title>Best practices - Multi large upgrades pan-os Firewall HA</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/best-practices-multi-large-upgrades-pan-os-firewall-ha/m-p/511734#M106363</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Best practices - Multi large upgrades pan-os Firewall HA&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Good afternoon, as usual, thank you very much for your support and collaboration.&lt;/P&gt;
&lt;P&gt;We have the possibility with a customer to perform multiple upgrades in one day, maintenance window.&lt;/P&gt;
&lt;P&gt;We need to move from 8.1 to 9.1, i.e. 8.1.x to 9.0.x and from 9.0.x to 9.1.x.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;So the question is the following:&lt;/P&gt;
&lt;P&gt;1.- What is the best practice when it comes to make that jump, that intermediate upgrade from 9.0, for example when going from 8.1.x to ""9.0.x"" ( PAN-OS Intermediate, transitive ) final 9.1.x.&lt;/P&gt;
&lt;P&gt;That intermediate jump, what is the best practice: I mean, for example, the current version 8.1.5, download and install the base 9.0.0? or is it recommended to download the base (9.0.0) and download and install (the recommended version of 9.0.x (9.0.16-h2), although it is say the intermediate transition version? to reach the recommended version 9.1.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;2.- Also in relation to the same, the recommendation is still, in each jump, for example when moving to the same intermediate version 9.0, love or reassemble the HA and then continue with the upgrade ? or is it possible to apply both upgrades to a node and then on the other node ? I would understand that the best practice is to re-amplify the HA at each stage of the upgrade.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please give me your comments, advice, recommendations and suggestions.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you very much&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Best regards&lt;/P&gt;</description>
      <pubDate>Fri, 12 Aug 2022 16:00:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/best-practices-multi-large-upgrades-pan-os-firewall-ha/m-p/511734#M106363</guid>
      <dc:creator>Metgatz</dc:creator>
      <dc:date>2022-08-12T16:00:42Z</dc:date>
    </item>
    <item>
      <title>Re: Best practices - Multi large upgrades pan-os Firewall HA</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/best-practices-multi-large-upgrades-pan-os-firewall-ha/m-p/511763#M106367</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;First backup the config. This doc should step you through the process. I forget when they allowed the base release download only and install the preferred release, i.e. just download 9.0 and download and install the latest version of the 9.0.x release. But you can do it with the 9.1, eg download 9.1.0 code but download and install the preferred release 9.1.x.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-upgrade/upgrade-pan-os/upgrade-the-firewall-pan-os/upgrade-an-ha-firewall-pair#id062f1ad5-adb3-4d25-b4a4-529bde5dc96a" target="_blank"&gt;https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-upgrade/upgrade-pan-os/upgrade-the-firewall-pan-os/upgrade-an-ha-firewall-pair#id062f1ad5-adb3-4d25-b4a4-529bde5dc96a&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/customer-resources/support-pan-os-software-release-guidance/ta-p/258304" target="_blank"&gt;https://live.paloaltonetworks.com/t5/customer-resources/support-pan-os-software-release-guidance/ta-p/258304&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;With an HA pair, do it all on the standby unit first. I when doing large jumps as these, it might be wise to go slow. What I mean is do the first jump on the standby, fail over, then upgrade the other one to the same version. Then keep going until you are up to the version you want to be at. Also make sure you dynamic updates are up to date as well, otherwise the PAN wont let you upgrade the OS.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Cheers!&lt;/P&gt;</description>
      <pubDate>Fri, 12 Aug 2022 18:42:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/best-practices-multi-large-upgrades-pan-os-firewall-ha/m-p/511763#M106367</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2022-08-12T18:42:21Z</dc:date>
    </item>
    <item>
      <title>Re: Best practices - Multi large upgrades pan-os Firewall HA</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/best-practices-multi-large-upgrades-pan-os-firewall-ha/m-p/511789#M106372</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Ok, thanks for your time and your comments.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;So, to confirm, each step even transitive, always the recommended version to install. (do not install the base then, even if it is transitive, the correct way then is to download the base and download and install the recommended version per jump, and the best practice is to synchronize the HA for each stage, each jump, perform the upgrade, rearm and sync the HA and then continue with the other version).&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 12 Aug 2022 21:55:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/best-practices-multi-large-upgrades-pan-os-firewall-ha/m-p/511789#M106372</guid>
      <dc:creator>Metgatz</dc:creator>
      <dc:date>2022-08-12T21:55:15Z</dc:date>
    </item>
    <item>
      <title>Re: Best practices - Multi large upgrades pan-os Firewall HA</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/best-practices-multi-large-upgrades-pan-os-firewall-ha/m-p/512381#M106474</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;Correct, that is how I would go about it.&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Fri, 19 Aug 2022 16:17:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/best-practices-multi-large-upgrades-pan-os-firewall-ha/m-p/512381#M106474</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2022-08-19T16:17:42Z</dc:date>
    </item>
    <item>
      <title>Re: Best practices - Multi large upgrades pan-os Firewall HA</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/best-practices-multi-large-upgrades-pan-os-firewall-ha/m-p/512528#M106498</link>
      <description>&lt;P&gt;Hey &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/179185"&gt;@Metgatz&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;I am not able to find it in the docs at the moment, but somewhere was explicetly mentioned to keep the difference between the HA member as lower as possible.&lt;BR /&gt;Meaning&lt;BR /&gt;- Upgrade secondary to latest maintenance release for 8.1.x&lt;/P&gt;
&lt;P&gt;- Upgrade secondary to latest maintenance release for 9.0.x ( downloading 9.0 and installing 9.0.x)&lt;/P&gt;
&lt;P&gt;Failover&lt;/P&gt;
&lt;P&gt;- Upgrade primary to latest maintenance for 8.1.x&lt;/P&gt;
&lt;P&gt;- Upgrade primarto latest maintenance for 9.0 (download 9.0 install latest 9.0.x)&lt;/P&gt;
&lt;P&gt;Sync cluster&lt;/P&gt;
&lt;P&gt;- Repeat for 9.1&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 22 Aug 2022 12:14:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/best-practices-multi-large-upgrades-pan-os-firewall-ha/m-p/512528#M106498</guid>
      <dc:creator>aleksandar.astardzhiev</dc:creator>
      <dc:date>2022-08-22T12:14:51Z</dc:date>
    </item>
  </channel>
</rss>

