<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: HA cluster interoperability between PANOS version 5 and version 6 in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/ha-cluster-interoperability-between-panos-version-5-and-version/m-p/41401#M30434</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Sir,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You have to follow the DOC- to upgrade the HA pair from 5.0.x to 6.0.x version.&lt;/P&gt;&lt;P&gt; &lt;A href="https://live.paloaltonetworks.com/docs/DOC-4043"&gt;How to Upgrade an High Availability (HA) Pair &lt;/A&gt; &lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/docs/DOC-2092"&gt;How to Upgrade PAN-OS and Panorama&lt;/A&gt; &lt;/P&gt;&lt;P&gt;Ideally there should not be any service interruption&amp;nbsp; but as a safer side you should take a maintenance window for the same.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But there are few new features has been introduced on PAN-OS version 6.0.0 onward for HA:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;In v6.0, enhancements have been made to assure that existing sessions can be synchronized to a peer device, despite their being an OS mismatch/device running a newer major/minor version of code. &lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;When you will upgrades one firewall in an HA pair from one major/minor version to the next, sessions are not synchronized. Without session synchronization, they are forced to compromise security by permitting non-syn-tcp. It can be difficult/impossible to determine how long this setting must be enabled when long-lived sessions exist. If you are not willing or able to sacrifice security, you are forced to take an outage which can have a monetary value attached due to missed SLA’s or even more severe, placing patient lives at risk in environments such as Hospitals where hiccups in uptime/accessibility to patient records, etc... is simply not an option. &lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;In v6.0, we have developed a session synchronization format and other runtime object synchronization mechanisms to ensure that an existing session can be synchronized to a peer device running a newer major/minor version of code.&amp;nbsp; &lt;/SPAN&gt;&lt;/EM&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;&lt;EM&gt;This is supported in both Active/Passive as well as Active/Active HA Configurations.&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;&lt;EM&gt;&lt;BR /&gt;&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;&lt;EM&gt;Hope this helps.&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;&lt;EM&gt;&lt;BR /&gt;&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;&lt;EM&gt;Thanks&lt;BR /&gt;&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 21 Feb 2014 09:57:01 GMT</pubDate>
    <dc:creator>HULK</dc:creator>
    <dc:date>2014-02-21T09:57:01Z</dc:date>
    <item>
      <title>HA cluster interoperability between PANOS version 5 and version 6</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ha-cluster-interoperability-between-panos-version-5-and-version/m-p/41400#M30433</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;the migation between a PANOS version 5 to PANOS version 6.&lt;/P&gt;&lt;P&gt;is it supported without service interruption.&lt;/P&gt;&lt;P&gt;we will have to migrate all the cluster firewall in on shot. to minimize the interruption time frame. or another solution exist?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regard's &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 21 Feb 2014 09:36:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ha-cluster-interoperability-between-panos-version-5-and-version/m-p/41400#M30433</guid>
      <dc:creator>Gregoux</dc:creator>
      <dc:date>2014-02-21T09:36:22Z</dc:date>
    </item>
    <item>
      <title>Re: HA cluster interoperability between PANOS version 5 and version 6</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ha-cluster-interoperability-between-panos-version-5-and-version/m-p/41401#M30434</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Sir,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You have to follow the DOC- to upgrade the HA pair from 5.0.x to 6.0.x version.&lt;/P&gt;&lt;P&gt; &lt;A href="https://live.paloaltonetworks.com/docs/DOC-4043"&gt;How to Upgrade an High Availability (HA) Pair &lt;/A&gt; &lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/docs/DOC-2092"&gt;How to Upgrade PAN-OS and Panorama&lt;/A&gt; &lt;/P&gt;&lt;P&gt;Ideally there should not be any service interruption&amp;nbsp; but as a safer side you should take a maintenance window for the same.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But there are few new features has been introduced on PAN-OS version 6.0.0 onward for HA:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;In v6.0, enhancements have been made to assure that existing sessions can be synchronized to a peer device, despite their being an OS mismatch/device running a newer major/minor version of code. &lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;When you will upgrades one firewall in an HA pair from one major/minor version to the next, sessions are not synchronized. Without session synchronization, they are forced to compromise security by permitting non-syn-tcp. It can be difficult/impossible to determine how long this setting must be enabled when long-lived sessions exist. If you are not willing or able to sacrifice security, you are forced to take an outage which can have a monetary value attached due to missed SLA’s or even more severe, placing patient lives at risk in environments such as Hospitals where hiccups in uptime/accessibility to patient records, etc... is simply not an option. &lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;In v6.0, we have developed a session synchronization format and other runtime object synchronization mechanisms to ensure that an existing session can be synchronized to a peer device running a newer major/minor version of code.&amp;nbsp; &lt;/SPAN&gt;&lt;/EM&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;&lt;EM&gt;This is supported in both Active/Passive as well as Active/Active HA Configurations.&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;&lt;EM&gt;&lt;BR /&gt;&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;&lt;EM&gt;Hope this helps.&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;&lt;EM&gt;&lt;BR /&gt;&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;&lt;EM&gt;Thanks&lt;BR /&gt;&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 21 Feb 2014 09:57:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ha-cluster-interoperability-between-panos-version-5-and-version/m-p/41401#M30434</guid>
      <dc:creator>HULK</dc:creator>
      <dc:date>2014-02-21T09:57:01Z</dc:date>
    </item>
    <item>
      <title>Re: HA cluster interoperability between PANOS version 5 and version 6</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ha-cluster-interoperability-between-panos-version-5-and-version/m-p/41402#M30435</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have successfully upgraded HA pairs without service interruption.&amp;nbsp; But we do always schedule in a maintenance window for safety sake.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 21 Feb 2014 13:46:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ha-cluster-interoperability-between-panos-version-5-and-version/m-p/41402#M30435</guid>
      <dc:creator>pulukas</dc:creator>
      <dc:date>2014-02-21T13:46:24Z</dc:date>
    </item>
    <item>
      <title>Re: HA cluster interoperability between PANOS version 5 and version 6</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ha-cluster-interoperability-between-panos-version-5-and-version/m-p/41403#M30436</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you for this information&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 21 Feb 2014 16:11:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ha-cluster-interoperability-between-panos-version-5-and-version/m-p/41403#M30436</guid>
      <dc:creator>Gregoux</dc:creator>
      <dc:date>2014-02-21T16:11:53Z</dc:date>
    </item>
  </channel>
</rss>

