<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Upgrading HA setup in large steps in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/upgrading-ha-setup-in-large-steps/m-p/98711#M44150</link>
    <description>&lt;P&gt;Hi,&lt;BR /&gt;&lt;BR /&gt;I'm going to upgrade a PANOS 5.0.14 to version 7.1.&lt;/P&gt;&lt;P&gt;As I understand, the correct sequence is:&lt;BR /&gt;Update PAN-OS 5.0.14 to 7.1.x:&lt;BR /&gt;Download 6.0.0&lt;BR /&gt;Download + install latest 6.0.x release (reboot)&lt;BR /&gt;Download 6.1.0&lt;BR /&gt;Download+Install latest 6.1.x release (reboot)&lt;BR /&gt;Download 7.0.1&lt;BR /&gt;Download + install latest 7.0.x release (reboot)&lt;BR /&gt;Download 7.1.0&lt;BR /&gt;Download + Install latest 7.1.x release (reboot)&lt;BR /&gt;&lt;BR /&gt;It's pretty straightforward to do this on a single device, but when you do this in an HA setup, is it a good idea to update 1 device to 7.1 while the other trails behind on version 5? Won't that create issues?&lt;BR /&gt;Or do I need to get primary and secondary to the same major version so there isn't a large difference between them?&lt;/P&gt;&lt;P&gt;F.e.: Get both from version 5 to 6 before carrying on to version 7,...&lt;BR /&gt;&lt;BR /&gt;Thanks for your help&lt;BR /&gt;&lt;BR /&gt;Tim Schepers&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 20 Jul 2016 10:07:58 GMT</pubDate>
    <dc:creator>TSchepers</dc:creator>
    <dc:date>2016-07-20T10:07:58Z</dc:date>
    <item>
      <title>Upgrading HA setup in large steps</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/upgrading-ha-setup-in-large-steps/m-p/98711#M44150</link>
      <description>&lt;P&gt;Hi,&lt;BR /&gt;&lt;BR /&gt;I'm going to upgrade a PANOS 5.0.14 to version 7.1.&lt;/P&gt;&lt;P&gt;As I understand, the correct sequence is:&lt;BR /&gt;Update PAN-OS 5.0.14 to 7.1.x:&lt;BR /&gt;Download 6.0.0&lt;BR /&gt;Download + install latest 6.0.x release (reboot)&lt;BR /&gt;Download 6.1.0&lt;BR /&gt;Download+Install latest 6.1.x release (reboot)&lt;BR /&gt;Download 7.0.1&lt;BR /&gt;Download + install latest 7.0.x release (reboot)&lt;BR /&gt;Download 7.1.0&lt;BR /&gt;Download + Install latest 7.1.x release (reboot)&lt;BR /&gt;&lt;BR /&gt;It's pretty straightforward to do this on a single device, but when you do this in an HA setup, is it a good idea to update 1 device to 7.1 while the other trails behind on version 5? Won't that create issues?&lt;BR /&gt;Or do I need to get primary and secondary to the same major version so there isn't a large difference between them?&lt;/P&gt;&lt;P&gt;F.e.: Get both from version 5 to 6 before carrying on to version 7,...&lt;BR /&gt;&lt;BR /&gt;Thanks for your help&lt;BR /&gt;&lt;BR /&gt;Tim Schepers&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 20 Jul 2016 10:07:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/upgrading-ha-setup-in-large-steps/m-p/98711#M44150</guid>
      <dc:creator>TSchepers</dc:creator>
      <dc:date>2016-07-20T10:07:58Z</dc:date>
    </item>
    <item>
      <title>Re: Upgrading HA setup in large steps</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/upgrading-ha-setup-in-large-steps/m-p/98732#M44151</link>
      <description>&lt;P&gt;Hi,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;To be on the safe site, just do in stages. HA passive first&amp;gt;reboot&amp;gt;suspend Active&amp;gt;upgrade&amp;gt;Reboot. Advice to disable "preemption" while doing an upgrade.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thx&lt;/P&gt;</description>
      <pubDate>Wed, 20 Jul 2016 11:26:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/upgrading-ha-setup-in-large-steps/m-p/98732#M44151</guid>
      <dc:creator>TranceforLife</dc:creator>
      <dc:date>2016-07-20T11:26:27Z</dc:date>
    </item>
    <item>
      <title>Re: Upgrading HA setup in large steps</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/upgrading-ha-setup-in-large-steps/m-p/98733#M44152</link>
      <description>&lt;P&gt;Thanks for your reply. Exactly what I was thinking. 'Just to be safe'. Since HA can be very sensitive to version differences.&lt;BR /&gt;But there has to be some sort of official Palo Alto recommendation for situation like this, right?&lt;BR /&gt;&lt;BR /&gt;So my upgrade path would now become something like this:&lt;BR /&gt;download 6.0 on both devices&lt;BR /&gt;Suspend Primary and upgrade to 6.0.X&lt;BR /&gt;Suspend secondary and upgrade to 6.0.X&lt;BR /&gt;Suspend Primary and upgrade to 6.1.X&lt;BR /&gt;Suspend Secondary....&lt;/P&gt;</description>
      <pubDate>Wed, 20 Jul 2016 11:41:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/upgrading-ha-setup-in-large-steps/m-p/98733#M44152</guid>
      <dc:creator>TSchepers</dc:creator>
      <dc:date>2016-07-20T11:41:29Z</dc:date>
    </item>
    <item>
      <title>Re: Upgrading HA setup in large steps</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/upgrading-ha-setup-in-large-steps/m-p/98757#M44154</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please see below:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.paloaltonetworks.com/documentation/71/pan-os/newfeaturesguide/upgrade-to-pan-os-7-1/upgrade-an-ha-firewall-pair-to-pan-os-7-1" target="_blank"&gt;https://www.paloaltonetworks.com/documentation/71/pan-os/newfeaturesguide/upgrade-to-pan-os-7-1/upgrade-an-ha-firewall-pair-to-pan-os-7-1&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thx&lt;/P&gt;</description>
      <pubDate>Wed, 20 Jul 2016 12:17:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/upgrading-ha-setup-in-large-steps/m-p/98757#M44154</guid>
      <dc:creator>TranceforLife</dc:creator>
      <dc:date>2016-07-20T12:17:48Z</dc:date>
    </item>
    <item>
      <title>Re: Upgrading HA setup in large steps</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/upgrading-ha-setup-in-large-steps/m-p/260702#M73897</link>
      <description>&lt;P&gt;Hello everyone,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp; I'm resuming this old thread instead of opening a new one.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;After reading the best practices, knowledge base and hearing from some support engineers, I think the recommended way to upgrade a HA pair (active/passive) should be as follows. I will use the same terminology used in &lt;A title="BEST PRACTICES FOR PAN-OS UPGRADE" href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClRrCAK" target="_blank" rel="noopener"&gt;this document&lt;/A&gt;:&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Terminology&lt;/STRONG&gt;&lt;/P&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;&lt;P&gt;Active firewall&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P&gt;The firewall in an HA cluster that's passing traffic&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&lt;P&gt;Passive firewall&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P&gt;The firewall in an HA cluster that's&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;not&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;passing traffic&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&lt;P&gt;Primary firewall&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P&gt;The firewall in an HA cluster that's usually the active firewall&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&lt;P&gt;Secondary firewall&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P&gt;The firewall in an HA cluster that's usually the passive firewall&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In the example &lt;STRONG&gt;I will upgrade a HA pair from 7.0.6 to 7.1.23&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;disable preemption on both firewalls;&lt;/LI&gt;&lt;LI&gt;suspend the primary (currently active) firewall; this will cause a failover, but there will be no traffic disruption and you can confirm that the secondary firewall is working as expected;&lt;/LI&gt;&lt;LI&gt;download and install PAN-OS 7.0.19 on the primary firewall and reboot it. After rebooting, the primary firewall returns in the passive state and HA sync is working even though the firewalls are running a different PAN-OS version;&lt;/LI&gt;&lt;LI&gt;suspend the secondary (currently active) firewall; this will cause another failover without traffic disruption;&lt;/LI&gt;&lt;LI&gt;download and install PAN-OS 7.0.19 on the secondary firewall and reboot it. After rebooting, both firewalls are running PAN-OS 7.0.19;&lt;/LI&gt;&lt;LI&gt;download PAN-OS 7.1 base image on the secondary (currently passive) firewall; do not install it. Download and install PAN-OS 7.1.23 on the secondary firewall and then reboot it. After rebooting, the secondary firewall is in the passive state and HA sync is working even though the PAN-OS versions mismatch (the secondary firewall is only one major version ahead of the primary one);&lt;/LI&gt;&lt;LI&gt;suspend the primary (currently active) firewall; this will cause a failover without traffic disruption;&lt;/LI&gt;&lt;LI&gt;download PAN-OS 7.1 base image on the primary (currently suspended) firewall; do not install it. Download and install PAN-OS 7.1.23 on the primary firewall and reboot. After rebooting, both firewalls are running PAN-OS 7.1.23;&lt;/LI&gt;&lt;LI&gt;restore the preemption settings (if needed) and wait until the primary firewall takes over the secondary one.&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;I know there are some extra-steps, and some support engineers say that we can upgrade from 7.0.6 straight to 7.1.23, but &lt;A title="Upgrade an HA Firewall Pair to PAN-OS 7.1" href="https://docs.paloaltonetworks.com/pan-os/7-1/pan-os-new-features/upgrade-to-pan-os-7-1/upgrade-an-ha-firewall-pair-to-pan-os-7-1" target="_blank" rel="noopener"&gt;this document&lt;/A&gt; states that if you are running PAN-OS version older than 7.0.9 you should install the 7.0.9 or later release first. As per best practice, I always install the latest maintenance release before jumping to the next feature release.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What do you think about it?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;</description>
      <pubDate>Mon, 13 May 2019 10:25:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/upgrading-ha-setup-in-large-steps/m-p/260702#M73897</guid>
      <dc:creator>grenzi</dc:creator>
      <dc:date>2019-05-13T10:25:57Z</dc:date>
    </item>
    <item>
      <title>Re: Upgrading HA setup in large steps</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/upgrading-ha-setup-in-large-steps/m-p/260711#M73899</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/61214"&gt;@grenzi&lt;/a&gt;: yeah, that way looks good.&lt;/P&gt;&lt;P&gt;I would not recommend preemption in general, because you can get problems in case you have a link-flapping situation.&lt;/P&gt;&lt;P&gt;Please note, that a failover will cause minimal disruption (no up to 3 ping losses) depending on your environment.&lt;/P&gt;&lt;P&gt;That shouldn't be a problem at all, but if you are using highly sensitive network applications like a bad configured SAP, you may have session losses - as I said: shouldn't be a problem with most environment, but you cannot preclude that.&lt;/P&gt;</description>
      <pubDate>Mon, 13 May 2019 10:55:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/upgrading-ha-setup-in-large-steps/m-p/260711#M73899</guid>
      <dc:creator>Chacko42</dc:creator>
      <dc:date>2019-05-13T10:55:20Z</dc:date>
    </item>
    <item>
      <title>Re: Upgrading HA setup in large steps</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/upgrading-ha-setup-in-large-steps/m-p/260723#M73905</link>
      <description>&lt;P&gt;Thanks&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/79934"&gt;@Chacko42&lt;/a&gt;&lt;/P&gt;&lt;P&gt;I never had an issue with the environments I usually manage. My biggest concerns are about multiple VPN tunnels terminating on the firewalls, but the support engineers ensure that VPN traffic will be preserved during the upgrade.&lt;/P&gt;</description>
      <pubDate>Mon, 13 May 2019 11:11:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/upgrading-ha-setup-in-large-steps/m-p/260723#M73905</guid>
      <dc:creator>grenzi</dc:creator>
      <dc:date>2019-05-13T11:11:07Z</dc:date>
    </item>
    <item>
      <title>Re: Upgrading HA setup in large steps</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/upgrading-ha-setup-in-large-steps/m-p/260725#M73906</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/61214"&gt;@grenzi&lt;/a&gt;: Right, the SAs are included in the session synced&lt;/P&gt;</description>
      <pubDate>Mon, 13 May 2019 11:32:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/upgrading-ha-setup-in-large-steps/m-p/260725#M73906</guid>
      <dc:creator>Chacko42</dc:creator>
      <dc:date>2019-05-13T11:32:19Z</dc:date>
    </item>
    <item>
      <title>Re: Upgrading HA setup in large steps</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/upgrading-ha-setup-in-large-steps/m-p/262544#M74384</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/61214"&gt;@grenzi&lt;/a&gt;&amp;nbsp;wrote:&lt;OL&gt;&lt;LI&gt;download PAN-OS 7.1 base image on the primary (currently suspended) firewall; do not install it. Download and install PAN-OS 7.1.23 on the primary firewall and reboot. After rebooting, both firewalls are running PAN-OS 7.1.23;&lt;/LI&gt;&lt;/OL&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It seems that on PA-3000 series you have to install the base image too (without reboot) prior to install the 7.1.23 version.&lt;/P&gt;</description>
      <pubDate>Wed, 29 May 2019 13:45:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/upgrading-ha-setup-in-large-steps/m-p/262544#M74384</guid>
      <dc:creator>grenzi</dc:creator>
      <dc:date>2019-05-29T13:45:59Z</dc:date>
    </item>
    <item>
      <title>Re: Upgrading HA setup in large steps</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/upgrading-ha-setup-in-large-steps/m-p/265516#M74436</link>
      <description>&lt;P&gt;There is no need to suspend the "active" firewall.&amp;nbsp; Installing on the "passive" firewall first reduces the number of failover events.&amp;nbsp; Yes, you can install the latest image of the code train as long at the base x.x.0 image is downloaded to the firewall first.&amp;nbsp; It's best to run the latest recommended version of your code train before jumping.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here is my recommendation for the fewest failover events (ditch preemption and don't fixate on a "primary" firewall)&amp;nbsp;&lt;/P&gt;&lt;P&gt;*5.0 so old you might want to verify versions jumps&lt;/P&gt;&lt;P&gt;*Always read HA version compatibility notes before large version hops&lt;/P&gt;&lt;P&gt;*Make sure to update threat prevention/wildfire/etc before upgrades (read the release notes)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1. Download 6.0.0 and latest 6.0.x to both devices (deviceA deviceB)&lt;/P&gt;&lt;P&gt;2. Install latest 6.0.x on PASSIVE deviceB&lt;/P&gt;&lt;P&gt;3. Failover to PASSIVE deviceB&lt;/P&gt;&lt;P&gt;4.&amp;nbsp;Install latest 6.0.x on PASSIVE deviceA&lt;/P&gt;&lt;P&gt;5.&amp;nbsp;Download 7.0.0 and latest 7.0.x to both devices (deviceA deviceB)&lt;/P&gt;&lt;P&gt;6.&amp;nbsp;Install latest 7.0.x on PASSIVE deviceA&lt;/P&gt;&lt;P&gt;7.&amp;nbsp;Failover to PASSIVE deviceA&lt;/P&gt;&lt;P&gt;8.&amp;nbsp;Install latest 7.0.x on PASSIVE deviceB&lt;/P&gt;&lt;P&gt;9.&amp;nbsp;Download 7.1.0 and latest 7.0.x to both devices (deviceA deviceB)&lt;/P&gt;&lt;P&gt;10.&amp;nbsp;Install latest 7.1.x on PASSIVE deviceB&lt;/P&gt;&lt;P&gt;11.&amp;nbsp;Failover to PASSIVE deviceB&lt;/P&gt;&lt;P&gt;12.&amp;nbsp;Install latest 7.1.x on PASSIVE deviceA&lt;/P&gt;&lt;P&gt;... wash, rinse, repeat for 8.0/8.1/9.0&lt;/P&gt;</description>
      <pubDate>Mon, 03 Jun 2019 15:05:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/upgrading-ha-setup-in-large-steps/m-p/265516#M74436</guid>
      <dc:creator>jeremy.larsen</dc:creator>
      <dc:date>2019-06-03T15:05:17Z</dc:date>
    </item>
  </channel>
</rss>

