<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic HA Pair - peer version too old in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/ha-pair-peer-version-too-old/m-p/605573#M120207</link>
    <description>&lt;P&gt;I have two hardware gateways in a HA pair running 9.1.19.&amp;nbsp; Ive upgraded one to 10.0 and then to 10.1.14.&amp;nbsp; It now complains that the HA 'peer version is too old' and it has suspended HA.&amp;nbsp; If i suspend HA on the remaining 9.1 gateway, HA doesnt activate on the 10.1 gateway. If i suspend the 9.1 gateway and try to manually "make local device functional for HA" on 10.1, it still wont enable.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;How can i get 10.1 to become the active member while i update the remaining 9.1 member?&lt;/P&gt;</description>
    <pubDate>Thu, 17 Oct 2024 13:47:46 GMT</pubDate>
    <dc:creator>JimMcGrady</dc:creator>
    <dc:date>2024-10-17T13:47:46Z</dc:date>
    <item>
      <title>HA Pair - peer version too old</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ha-pair-peer-version-too-old/m-p/605573#M120207</link>
      <description>&lt;P&gt;I have two hardware gateways in a HA pair running 9.1.19.&amp;nbsp; Ive upgraded one to 10.0 and then to 10.1.14.&amp;nbsp; It now complains that the HA 'peer version is too old' and it has suspended HA.&amp;nbsp; If i suspend HA on the remaining 9.1 gateway, HA doesnt activate on the 10.1 gateway. If i suspend the 9.1 gateway and try to manually "make local device functional for HA" on 10.1, it still wont enable.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;How can i get 10.1 to become the active member while i update the remaining 9.1 member?&lt;/P&gt;</description>
      <pubDate>Thu, 17 Oct 2024 13:47:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ha-pair-peer-version-too-old/m-p/605573#M120207</guid>
      <dc:creator>JimMcGrady</dc:creator>
      <dc:date>2024-10-17T13:47:46Z</dc:date>
    </item>
    <item>
      <title>Re: HA Pair - peer version too old</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ha-pair-peer-version-too-old/m-p/605844#M120232</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/37508"&gt;@JimMcGrady&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;
&lt;P&gt;I have two hardware gateways in a HA pair running 9.1.19.&amp;nbsp; Ive upgraded one to 10.0 and then to 10.1.14.&amp;nbsp; It now complains that the HA 'peer version is too old' and it has suspended HA.&amp;nbsp; If i suspend HA on the remaining 9.1 gateway, HA doesnt activate on the 10.1 gateway. If i suspend the 9.1 gateway and try to manually "make local device functional for HA" on 10.1, it still wont enable.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;How can i get 10.1 to become the active member while i update the remaining 9.1 member?&lt;/P&gt;
&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;
&lt;P&gt;I would disconnect any data interfaces on your 9.1 FW and also disconnect your HA connections between both FWs.&amp;nbsp; Your Active firewall running 10.1.14 will continue to function as your active firewall.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;With your 9.1 FW now fully isolated you should still be able to access the firewall via the management connection.&amp;nbsp; In this disconnected state the firewall should let you upgrade it to 10.1.14 matching your active one.&amp;nbsp; I would also ensure dynamic updates match the current active as well.&amp;nbsp; Once this is completed connect your HA-1 connection let things normalize, then connect your HA-2 link and let things normalize.&amp;nbsp; Your current active should still stay active with the other firewall in a HA paired state, but down (non-functional) due to the data links still disconnected.&amp;nbsp; Now reconnect your datalinks to the passive firewall.&amp;nbsp; Shortly there after both firewalls should be in a healthy HA A/P state.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;All of these steps should be in a maintenance window.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;--edit-- in the future I wouldn't recommend going so far in software version between firewalls.&amp;nbsp; Keep them only 1 revision apart.&lt;/P&gt;</description>
      <pubDate>Thu, 17 Oct 2024 15:09:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ha-pair-peer-version-too-old/m-p/605844#M120232</guid>
      <dc:creator>Brandon_Wertz</dc:creator>
      <dc:date>2024-10-17T15:09:44Z</dc:date>
    </item>
    <item>
      <title>Re: HA Pair - peer version too old</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ha-pair-peer-version-too-old/m-p/606734#M120395</link>
      <description>&lt;P&gt;Thanks for the suggestion.&amp;nbsp; Meanwhile, i reinstalled a recent 10.0 version on the 10.1 gateway to try and resolve the issue. It did in that HA is now happy. However Panorama is now disconnected. I gather that is because 10.1 introduced a more secure link between Panorama and gateway. Since i have reverted to 10.0, that is no longer applicable.&lt;/P&gt;
&lt;P&gt;How would i reconnect Panorama to the now-10.0 gateway without impacting the working active 9.1 HA member?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;EDIT: It turns out the 10.0 version i used is just a bit too old to receive the cert renewal that was recently done for Panorama. Ive applied the most recent 10.0 and that fixed the connection.&lt;/P&gt;</description>
      <pubDate>Fri, 18 Oct 2024 03:24:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ha-pair-peer-version-too-old/m-p/606734#M120395</guid>
      <dc:creator>JimMcGrady</dc:creator>
      <dc:date>2024-10-18T03:24:27Z</dc:date>
    </item>
  </channel>
</rss>

