<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Upgrade path to 11.2.5 from 11.0.0 on a PA-410 in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/upgrade-path-to-11-2-5-from-11-0-0-on-a-pa-410/m-p/1225857#M123894</link>
    <description>&lt;P&gt;That is a great point, &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/197789"&gt;@CosminM&lt;/a&gt; !&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I wonder if ...&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;you wanted to save time (and an outage of a few minutes is acceptable),&lt;/LI&gt;
&lt;LI&gt;you upgrade directly (skipping a version or two), and&lt;/LI&gt;
&lt;LI&gt;once you start the upgrade process on the 2nd NGFW,&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;You could then "Make local device functional" and it would become active?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I guess currently there is no HA support for the Skip Software Version Upgrade feature.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;</description>
    <pubDate>Mon, 07 Apr 2025 19:34:08 GMT</pubDate>
    <dc:creator>TomYoung</dc:creator>
    <dc:date>2025-04-07T19:34:08Z</dc:date>
    <item>
      <title>Upgrade path to 11.2.5 from 11.0.0 on a PA-410</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/upgrade-path-to-11-2-5-from-11-0-0-on-a-pa-410/m-p/1225838#M123888</link>
      <description>&lt;P&gt;Hi there,&lt;/P&gt;
&lt;P&gt;Can you tell me what would be the recommended Upgrade path to 11.2.5 from 11.0.0 on&amp;nbsp;an HA Firewall Pair&amp;nbsp;PA-410, please?&lt;/P&gt;
&lt;P&gt;FW firmware Current ver.: 11.0.0&lt;BR /&gt;1. PAN-OS 11.1.0&lt;BR /&gt;2. PAN-OS 11.2.0&lt;BR /&gt;3. PAN-OS 11.2.5&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;In PAN-OS 11.0, you can now skip up to three software versions when upgrading or downgrading standalone devices or&amp;nbsp;&lt;/SPAN&gt;&lt;A class="xref" title="" href="https://docs.paloaltonetworks.com/pan-os/11-0/pan-os-upgrade/upgrade-pan-os/upgrade-the-firewall-pan-os-from-panorama" target="_blank" rel="noopener" data-scope="external" data-format="html" data-type=""&gt;Panorama managed devices running PAN-OS 10.1 or a later release&lt;/A&gt;&lt;SPAN&gt;. This feature builds on the&amp;nbsp;&lt;/SPAN&gt;&lt;A class="xref" title="" href="https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-new-features/management-features/simplified-software-upgrade" target="_blank" rel="noopener" data-scope="external" data-format="html" data-type=""&gt;Simplified Software Upgrade&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;process introduced in PAN-OS 10.2, which includes capabilities such as a multi-image download option and a pre-install validation check, to make the upgrade process even faster.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 07 Apr 2025 17:38:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/upgrade-path-to-11-2-5-from-11-0-0-on-a-pa-410/m-p/1225838#M123888</guid>
      <dc:creator>A.Otsu</dc:creator>
      <dc:date>2025-04-07T17:38:37Z</dc:date>
    </item>
    <item>
      <title>Re: Upgrade path to 11.2.5 from 11.0.0 on a PA-410</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/upgrade-path-to-11-2-5-from-11-0-0-on-a-pa-410/m-p/1225852#M123892</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/1618960391"&gt;@A.Otsu&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As you mentioned, with the &lt;A href="https://docs.paloaltonetworks.com/pan-os/11-0/pan-os-new-features/management-features/skip-software-version-upgrade" target="_self"&gt;Skip Software Version Upgrade&lt;/A&gt; feature of 11.0, you can upgrade directly from 11.0 to 11.2.&amp;nbsp; This &lt;A href="https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-upgrade/upgrade-pan-os/upgrade-the-firewall-pan-os/determine-the-upgrade-path#id85bdf6f4-2e83-49f0-8525-3eb2163f2d2e" target="_self"&gt;Upgrade Path&lt;/A&gt; is for 11.1 and later.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;</description>
      <pubDate>Mon, 07 Apr 2025 15:32:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/upgrade-path-to-11-2-5-from-11-0-0-on-a-pa-410/m-p/1225852#M123892</guid>
      <dc:creator>TomYoung</dc:creator>
      <dc:date>2025-04-07T15:32:32Z</dc:date>
    </item>
    <item>
      <title>Re: Upgrade path to 11.2.5 from 11.0.0 on a PA-410</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/upgrade-path-to-11-2-5-from-11-0-0-on-a-pa-410/m-p/1225856#M123893</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/1618960391"&gt;@A.Otsu&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The&amp;nbsp;&lt;A href="https://docs.paloaltonetworks.com/pan-os/11-0/pan-os-new-features/management-features/skip-software-version-upgrade" target="_self" rel="nofollow noopener noreferrer"&gt;Skip Software Version Upgrade&lt;/A&gt;&amp;nbsp;is referring to "standalone devices or Panorama managed devices running PAN-OS 10.1 or a later release".&lt;/P&gt;
&lt;P&gt;For HA pair there is another statement saying that: "&lt;A href="https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-upgrade/upgrade-pan-os/upgrade-the-firewall-pan-os/upgrade-an-ha-firewall-pair" target="_blank" rel="noopener"&gt;When HA peers are two or more feature releases apart, the firewall with the older release installed enters a suspended state with the message Peer version too old.&lt;/A&gt;".&lt;/P&gt;
&lt;P&gt;In the past the same page was more explicit, see this post:&amp;nbsp;&lt;A href="https://live.paloaltonetworks.com/t5/next-generation-firewall/upgrade-path-from-10-2-3-h14-to-11-1-4-h7/m-p/1220168" target="_blank" rel="noopener"&gt;https://live.paloaltonetworks.com/t5/next-generation-firewall/upgrade-path-from-10-2-3-h14-to-11-1-4-h7/m-p/1220168&lt;/A&gt;&amp;nbsp;where I post the previous sentence about upgrading HA pair firewalls.&lt;/P&gt;
&lt;P&gt;Based on all of the above, my suggestion is first to bring both HA firewalls to the latest preferred version of 11.1.x and only after to proceed with upgrade on 11.2.5.&lt;/P&gt;</description>
      <pubDate>Tue, 08 Apr 2025 05:16:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/upgrade-path-to-11-2-5-from-11-0-0-on-a-pa-410/m-p/1225856#M123893</guid>
      <dc:creator>CosminM</dc:creator>
      <dc:date>2025-04-08T05:16:08Z</dc:date>
    </item>
    <item>
      <title>Re: Upgrade path to 11.2.5 from 11.0.0 on a PA-410</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/upgrade-path-to-11-2-5-from-11-0-0-on-a-pa-410/m-p/1225857#M123894</link>
      <description>&lt;P&gt;That is a great point, &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/197789"&gt;@CosminM&lt;/a&gt; !&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I wonder if ...&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;you wanted to save time (and an outage of a few minutes is acceptable),&lt;/LI&gt;
&lt;LI&gt;you upgrade directly (skipping a version or two), and&lt;/LI&gt;
&lt;LI&gt;once you start the upgrade process on the 2nd NGFW,&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;You could then "Make local device functional" and it would become active?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I guess currently there is no HA support for the Skip Software Version Upgrade feature.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;</description>
      <pubDate>Mon, 07 Apr 2025 19:34:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/upgrade-path-to-11-2-5-from-11-0-0-on-a-pa-410/m-p/1225857#M123894</guid>
      <dc:creator>TomYoung</dc:creator>
      <dc:date>2025-04-07T19:34:08Z</dc:date>
    </item>
    <item>
      <title>Re: Upgrade path to 11.2.5 from 11.0.0 on a PA-410</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/upgrade-path-to-11-2-5-from-11-0-0-on-a-pa-410/m-p/1225922#M123903</link>
      <description>&lt;P&gt;Based on suggestion this would be the path&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;1. download 11.1.0&lt;/P&gt;
&lt;P&gt;2. download 11.1.6-h3 (the latest preferred release from 11.1) + install&lt;/P&gt;
&lt;P&gt;3. reboot the first firewall&lt;/P&gt;
&lt;P&gt;4. repeat steps 1-2 for second firewall and reboot second firewall&lt;/P&gt;
&lt;P&gt;4. download 11.2.0&lt;/P&gt;
&lt;P&gt;5. download 11.2.5 or&amp;nbsp;11.2.13-h5 (the latest preferred release from 11.2) + install&lt;/P&gt;
&lt;P&gt;6. second reboot for first firewall&lt;/P&gt;
&lt;P&gt;7. repeat steps 5-6 for second firewall&lt;/P&gt;
&lt;P&gt;8. second reboot for the second firewall&lt;/P&gt;
&lt;P&gt;Each HA peer will have 2 reboots.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 08 Apr 2025 08:15:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/upgrade-path-to-11-2-5-from-11-0-0-on-a-pa-410/m-p/1225922#M123903</guid>
      <dc:creator>A.Otsu</dc:creator>
      <dc:date>2025-04-08T08:15:43Z</dc:date>
    </item>
    <item>
      <title>Re: Upgrade path to 11.2.5 from 11.0.0 on a PA-410</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/upgrade-path-to-11-2-5-from-11-0-0-on-a-pa-410/m-p/1225933#M123905</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/1618960391"&gt;@A.Otsu&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;Since you are starting from 11.0.0 I recommend first to install the latest preferred version from 11.0.0 (i guess it's 11.0.4-h6, you can check that on the Customer Support Portal -&amp;gt; Updates for your device series) on both firewall and only after to go to 11.1.x as you describe.&lt;/P&gt;
&lt;P&gt;At this time there is no preferred version for 11.2.x but you find the updated info on:&amp;nbsp;&amp;nbsp;&lt;A href="https://live.paloaltonetworks.com/t5/customer-resources/support-pan-os-software-release-guidance/ta-p/258304" target="_blank" rel="noopener"&gt;Support PAN-OS Software Release Guidance&lt;/A&gt;&amp;nbsp;.&lt;/P&gt;
&lt;P&gt;Do you have any special request to upgrade up to 11.2.x?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 08 Apr 2025 10:44:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/upgrade-path-to-11-2-5-from-11-0-0-on-a-pa-410/m-p/1225933#M123905</guid>
      <dc:creator>CosminM</dc:creator>
      <dc:date>2025-04-08T10:44:51Z</dc:date>
    </item>
  </channel>
</rss>

