<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Updating the HA configuration in large hops. in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/updating-the-ha-configuration-in-large-hops/m-p/511788#M106371</link>
    <description>&lt;P&gt;I updated a standalone from 8.1.x to 9.1.x. When doing that one I downloaded the 9.0.0 and the 9.0.x updates and did it in one update to 9.0.x. Then a second download/update cycle to 9.1.x. Seemed to work fine.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For my HA pair I was advised not to do that by PA support, to download/install the 9.0.0 and reboot, then the 9.0.x and reboot, etc...Until you got to the final 9.1.x version. Probably for the best as updating broke the config syncing between active and passive units. So I updated the secondary unit to 9.0.0, then to 9.0.x. Failed over traffic to the secondary unit. Upgraded the primary to 9.0.0, 9.0.x, 9.1.0, and then finally 9.1.x. Checked all the config appeared to be OK and failed back to the primary unit. Updated the secondary unit to 9.1.x in stages. Then did forced config sync from the primary to secondary units.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Overall it wasn't too painful, just took a long time waiting for reboots.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Edit: Also, a potential trap... When updating from 8.x to 9.x, the Threat/App/URL databases format/provider changes. In my case the "Unknown" URL category is set to block instead of allow (the default). That meant after going to 9.0.0 I could no longer download system/dynamic updates, or confirm licenses, because the databases had been reset in the upgrade and every URL was now "Unknown". Had to bypass to be able to initialize the threat databases and continue updating.&lt;/P&gt;</description>
    <pubDate>Fri, 12 Aug 2022 21:35:55 GMT</pubDate>
    <dc:creator>Adrian_Jensen</dc:creator>
    <dc:date>2022-08-12T21:35:55Z</dc:date>
    <item>
      <title>Updating the HA configuration in large hops.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/updating-the-ha-configuration-in-large-hops/m-p/511778#M106370</link>
      <description>&lt;P&gt;Hello community&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I am upgrading a PANOS 8.0.7 to version 9.1.14-h1&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I would like to know if in the transit versions, you download and install only the base 9.0.0.0 or is recommended to download the base 9.0.0 and install the recommended 9.0.16-h2&lt;BR /&gt;for example:&lt;BR /&gt;Go from 8.1.x to 9.0.0 (transit version) and continue from 9.0.0 to 9.1.x.&lt;BR /&gt;or&lt;BR /&gt;Go from 8.1.x download base 9.0.0 (transit version) download and install version 9.0.6-h2 and continue from 9.0.6-h2 to 9.1.x.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Would there be any problem in case of only downloading and installing the base of the next jump and continue in the same way until reaching the 9.1.14-h1?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks for your help.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Brian Mendoza.&lt;/P&gt;</description>
      <pubDate>Fri, 12 Aug 2022 19:35:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/updating-the-ha-configuration-in-large-hops/m-p/511778#M106370</guid>
      <dc:creator>BrianMendoza</dc:creator>
      <dc:date>2022-08-12T19:35:29Z</dc:date>
    </item>
    <item>
      <title>Re: Updating the HA configuration in large hops.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/updating-the-ha-configuration-in-large-hops/m-p/511788#M106371</link>
      <description>&lt;P&gt;I updated a standalone from 8.1.x to 9.1.x. When doing that one I downloaded the 9.0.0 and the 9.0.x updates and did it in one update to 9.0.x. Then a second download/update cycle to 9.1.x. Seemed to work fine.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For my HA pair I was advised not to do that by PA support, to download/install the 9.0.0 and reboot, then the 9.0.x and reboot, etc...Until you got to the final 9.1.x version. Probably for the best as updating broke the config syncing between active and passive units. So I updated the secondary unit to 9.0.0, then to 9.0.x. Failed over traffic to the secondary unit. Upgraded the primary to 9.0.0, 9.0.x, 9.1.0, and then finally 9.1.x. Checked all the config appeared to be OK and failed back to the primary unit. Updated the secondary unit to 9.1.x in stages. Then did forced config sync from the primary to secondary units.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Overall it wasn't too painful, just took a long time waiting for reboots.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Edit: Also, a potential trap... When updating from 8.x to 9.x, the Threat/App/URL databases format/provider changes. In my case the "Unknown" URL category is set to block instead of allow (the default). That meant after going to 9.0.0 I could no longer download system/dynamic updates, or confirm licenses, because the databases had been reset in the upgrade and every URL was now "Unknown". Had to bypass to be able to initialize the threat databases and continue updating.&lt;/P&gt;</description>
      <pubDate>Fri, 12 Aug 2022 21:35:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/updating-the-ha-configuration-in-large-hops/m-p/511788#M106371</guid>
      <dc:creator>Adrian_Jensen</dc:creator>
      <dc:date>2022-08-12T21:35:55Z</dc:date>
    </item>
  </channel>
</rss>

