<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PaloAlto firewall HA upgrade in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/paloalto-firewall-ha-upgrade/m-p/1222175#M123426</link>
    <description>&lt;P&gt;Hi&lt;/P&gt;
&lt;P&gt;What would be the dedicated HA management interface when we do the upgrade. That interface IP shouldn't sync across the devices. can we use any ports other than mgmt port?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;</description>
    <pubDate>Thu, 27 Feb 2025 11:06:38 GMT</pubDate>
    <dc:creator>thushy</dc:creator>
    <dc:date>2025-02-27T11:06:38Z</dc:date>
    <item>
      <title>PaloAlto firewall HA upgrade</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/paloalto-firewall-ha-upgrade/m-p/1222165#M123423</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;
&lt;P&gt;I am new to Palo Alto firewalls. I need to upgrade the firmware on PA-3220 firewalls&amp;nbsp;in A-P HA . Firewalls doesn't have management ports connected to network and they are remote. It looks like i need management port access of individual firewall to upgrade the firmware. Is it possible to upgrade without management port access? if so, how do you do that? if it is required, can i use any other ports for management connectivity of the firewall for firmware upgrade?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Thu, 27 Feb 2025 09:30:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/paloalto-firewall-ha-upgrade/m-p/1222165#M123423</guid>
      <dc:creator>thushy</dc:creator>
      <dc:date>2025-02-27T09:30:47Z</dc:date>
    </item>
    <item>
      <title>Re: PaloAlto firewall HA upgrade</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/paloalto-firewall-ha-upgrade/m-p/1222171#M123425</link>
      <description>&lt;H2 data-start="306" data-end="352"&gt;&lt;STRONG data-start="309" data-end="352"&gt;Recommended HA Interface Assignments&lt;/STRONG&gt;&lt;/H2&gt;
&lt;TABLE data-start="353" data-end="1083"&gt;
&lt;THEAD data-start="353" data-end="415"&gt;
&lt;TR data-start="353" data-end="415"&gt;
&lt;TH data-start="353" data-end="372"&gt;&lt;STRONG data-start="355" data-end="370"&gt;HA Function&lt;/STRONG&gt;&lt;/TH&gt;
&lt;TH data-start="372" data-end="400"&gt;&lt;STRONG data-start="374" data-end="399"&gt;Recommended Interface&lt;/STRONG&gt;&lt;/TH&gt;
&lt;TH data-start="400" data-end="415"&gt;&lt;STRONG data-start="402" data-end="413"&gt;Purpose&lt;/STRONG&gt;&lt;/TH&gt;
&lt;/TR&gt;
&lt;/THEAD&gt;
&lt;TBODY data-start="478" data-end="1083"&gt;
&lt;TR data-start="478" data-end="620"&gt;
&lt;TD&gt;&lt;STRONG data-start="480" data-end="502"&gt;HA1 (Control Link)&lt;/STRONG&gt;&lt;/TD&gt;
&lt;TD&gt;&lt;STRONG data-start="506" data-end="554"&gt;Management Port or Ethernet1/1 – Ethernet1/9&lt;/STRONG&gt;&lt;/TD&gt;
&lt;TD&gt;Synchronizes configuration, heartbeats, and failover messages&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR data-start="621" data-end="720"&gt;
&lt;TD&gt;&lt;STRONG data-start="623" data-end="637"&gt;HA1 Backup&lt;/STRONG&gt; (Optional)&lt;/TD&gt;
&lt;TD&gt;&lt;STRONG data-start="651" data-end="682"&gt;Ethernet1/10 – Ethernet1/12&lt;/STRONG&gt;&lt;/TD&gt;
&lt;TD&gt;Backup for HA1 in case of failure&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR data-start="721" data-end="841"&gt;
&lt;TD&gt;&lt;STRONG data-start="723" data-end="742"&gt;HA2 (Data Link)&lt;/STRONG&gt;&lt;/TD&gt;
&lt;TD&gt;&lt;STRONG data-start="746" data-end="777"&gt;Ethernet1/10 – Ethernet1/12&lt;/STRONG&gt;&lt;/TD&gt;
&lt;TD&gt;Synchronizes session tables, forwarding tables, and objects&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR data-start="842" data-end="947"&gt;
&lt;TD&gt;&lt;STRONG data-start="844" data-end="858"&gt;HA2 Backup&lt;/STRONG&gt; (Optional)&lt;/TD&gt;
&lt;TD&gt;&lt;STRONG data-start="872" data-end="902"&gt;Ethernet1/9 – Ethernet1/12&lt;/STRONG&gt;&lt;/TD&gt;
&lt;TD&gt;Backup for HA2 if the primary link fails&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR data-start="948" data-end="1083"&gt;
&lt;TD&gt;&lt;STRONG data-start="950" data-end="1009"&gt;HA3 (Packet Forwarding Sync, for Active-Active HA only)&lt;/STRONG&gt;&lt;/TD&gt;
&lt;TD&gt;&lt;STRONG data-start="1012" data-end="1043"&gt;Ethernet1/10 – Ethernet1/12&lt;/STRONG&gt;&lt;/TD&gt;
&lt;TD&gt;Syncs packets in Active-Active mode&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;</description>
      <pubDate>Thu, 27 Feb 2025 10:52:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/paloalto-firewall-ha-upgrade/m-p/1222171#M123425</guid>
      <dc:creator>Mudhireddy</dc:creator>
      <dc:date>2025-02-27T10:52:47Z</dc:date>
    </item>
    <item>
      <title>Re: PaloAlto firewall HA upgrade</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/paloalto-firewall-ha-upgrade/m-p/1222175#M123426</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;
&lt;P&gt;What would be the dedicated HA management interface when we do the upgrade. That interface IP shouldn't sync across the devices. can we use any ports other than mgmt port?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Thu, 27 Feb 2025 11:06:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/paloalto-firewall-ha-upgrade/m-p/1222175#M123426</guid>
      <dc:creator>thushy</dc:creator>
      <dc:date>2025-02-27T11:06:38Z</dc:date>
    </item>
    <item>
      <title>Re: PaloAlto firewall HA upgrade</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/paloalto-firewall-ha-upgrade/m-p/1222185#M123431</link>
      <description>&lt;P&gt;You need mgmt port to access specific device.&lt;/P&gt;
&lt;P&gt;Only active firewall can be accessed through dataplane ports.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Procedure:&lt;/P&gt;
&lt;P&gt;Upgrade passive&lt;/P&gt;
&lt;P&gt;Reboot passive&lt;/P&gt;
&lt;P&gt;Wait until passive returns from reboot and is functional&lt;/P&gt;
&lt;P&gt;Upgrade active&lt;/P&gt;
&lt;P&gt;Reboot active&lt;/P&gt;
&lt;P&gt;If you have preemtion enabled then active role will migrate back to the firewall it was initially.&lt;/P&gt;</description>
      <pubDate>Thu, 27 Feb 2025 13:26:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/paloalto-firewall-ha-upgrade/m-p/1222185#M123431</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2025-02-27T13:26:44Z</dc:date>
    </item>
  </channel>
</rss>

