<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: General question to software updates of Palo Alto Firewalls in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/general-question-to-software-updates-of-palo-alto-firewalls/m-p/141361#M48398</link>
    <description>&lt;P&gt;The command via ssh to initiate a failover is&amp;nbsp;&lt;EM&gt;request high-availablity state suspend&lt;/EM&gt; from the active firewall will bring your passive unit to active status. During the upgrade I would recommend updating whatever unit is active, fully upgrading to 7.1.7, then manually do the failover from your active unit making the newly updated 7.1.7 the active firewall.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I would never try to process an upgrade on the active unit while it's still processing traffic if you have an active-passive HA setup. Just upgrade your passive unit that isn't handling any traffic so if for some reason the update bombs out traffic is never interuppted and you can guarentee that the updated unit has returned to normal operations before kicking traffic to it.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 06 Feb 2017 19:48:56 GMT</pubDate>
    <dc:creator>BPry</dc:creator>
    <dc:date>2017-02-06T19:48:56Z</dc:date>
    <item>
      <title>General question to software updates of Palo Alto Firewalls</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/general-question-to-software-updates-of-palo-alto-firewalls/m-p/141217#M48364</link>
      <description>&lt;P&gt;Hey guys,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have two PA-3020 firewalls with 7.0.7 installed.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I want to upgrade to a version of 7.1&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Since I have never made an update before, I'm a bit worried about it.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;How do you perform updates?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can I just pick the latest version (currently 7.1.7) and install it?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Or is there like in Cisco a page showing a suggested version?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Or can I install every version without having concerns?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I already checked the minimum supported versions of User-ID Agent, GP andContent Release. These are fine.&lt;/P&gt;</description>
      <pubDate>Mon, 06 Feb 2017 08:27:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/general-question-to-software-updates-of-palo-alto-firewalls/m-p/141217#M48364</guid>
      <dc:creator>MPI-AE</dc:creator>
      <dc:date>2017-02-06T08:27:12Z</dc:date>
    </item>
    <item>
      <title>Re: General question to software updates of Palo Alto Firewalls</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/general-question-to-software-updates-of-palo-alto-firewalls/m-p/141229#M48365</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/50331"&gt;@MPI-AE&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You can't go directly to 7.1.7.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You need to download the 7.1 base first (no need to install it ... just download it to your device).&lt;/P&gt;
&lt;P&gt;Once you have downloaded it you can move forward and download+install the 7.1.7 version.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You have 2 PA-3020. &amp;nbsp;Are they set up in HA ?&lt;/P&gt;
&lt;P&gt;In that case you might want to check out the following article :&lt;/P&gt;
&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Management-Articles/How-to-upgrade-a-High-Availability-HA-pair/ta-p/57081" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Management-Articles/How-to-upgrade-a-High-Availability-HA-pair/ta-p/57081&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Cheers !&lt;/P&gt;
&lt;P&gt;-Kim.&lt;/P&gt;</description>
      <pubDate>Mon, 06 Feb 2017 08:50:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/general-question-to-software-updates-of-palo-alto-firewalls/m-p/141229#M48365</guid>
      <dc:creator>kiwi</dc:creator>
      <dc:date>2017-02-06T08:50:49Z</dc:date>
    </item>
    <item>
      <title>Re: General question to software updates of Palo Alto Firewalls</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/general-question-to-software-updates-of-palo-alto-firewalls/m-p/141232#M48367</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/11943"&gt;@kiwi&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;ah okay, good to know!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Yes I have a active-passive cluser, thanks for the link.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But my question is:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is there a recommended version?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What version would you recommend to install?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can there be any problems upgrading from my current version to a version of 7.1.x ?&lt;/P&gt;</description>
      <pubDate>Mon, 06 Feb 2017 08:56:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/general-question-to-software-updates-of-palo-alto-firewalls/m-p/141232#M48367</guid>
      <dc:creator>MPI-AE</dc:creator>
      <dc:date>2017-02-06T08:56:56Z</dc:date>
    </item>
    <item>
      <title>Re: General question to software updates of Palo Alto Firewalls</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/general-question-to-software-updates-of-palo-alto-firewalls/m-p/141236#M48368</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/50331"&gt;@MPI-AE&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Different branches have different recommended versions.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In the 7.0 branch, the recommended release is PAN-OS 7.0.12&lt;/P&gt;
&lt;P&gt;In the 7.1 branch, the recommended release is PAN-OS 7.1.7&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Cheers !&lt;/P&gt;
&lt;P&gt;-Kim.&lt;/P&gt;</description>
      <pubDate>Mon, 06 Feb 2017 09:06:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/general-question-to-software-updates-of-palo-alto-firewalls/m-p/141236#M48368</guid>
      <dc:creator>kiwi</dc:creator>
      <dc:date>2017-02-06T09:06:06Z</dc:date>
    </item>
    <item>
      <title>Re: General question to software updates of Palo Alto Firewalls</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/general-question-to-software-updates-of-palo-alto-firewalls/m-p/141278#M48377</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/11943"&gt;@kiwi&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have an active/backup cluster of two PA-3020.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is it possible to run both firewalls with a different software version?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My intention is to upgrade only my active firewall first and test everything.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;And maybe one day later upgrade the second one (if everything works fine)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is this doable or are there HA issues because of different software versions?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Because what do I have to do if I have to undo the software upgrade?&lt;/P&gt;</description>
      <pubDate>Mon, 06 Feb 2017 13:59:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/general-question-to-software-updates-of-palo-alto-firewalls/m-p/141278#M48377</guid>
      <dc:creator>MPI-AE</dc:creator>
      <dc:date>2017-02-06T13:59:21Z</dc:date>
    </item>
    <item>
      <title>Re: General question to software updates of Palo Alto Firewalls</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/general-question-to-software-updates-of-palo-alto-firewalls/m-p/141290#M48379</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/50331"&gt;@MPI-AE&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Yes, you can upgrade just one unit.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you have session synchronization enabled, this will continue to function during the upgrade process as long as you are upgrading from one feature release to the next consecutive feature release, PAN-OS 7.0.x to PAN-OS 7.1 in this case.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you encounter an issue and decide to revert back you can execute order 66 !!&lt;/P&gt;
&lt;P&gt;Just kidding ... '&amp;gt; debug swm revert' will reboot your FW and&amp;nbsp;&lt;SPAN class="s1"&gt;revert back to the last successfully installed software.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="s1"&gt;Cheers !&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="s1"&gt;-Kim.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 06 Feb 2017 14:18:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/general-question-to-software-updates-of-palo-alto-firewalls/m-p/141290#M48379</guid>
      <dc:creator>kiwi</dc:creator>
      <dc:date>2017-02-06T14:18:36Z</dc:date>
    </item>
    <item>
      <title>Re: General question to software updates of Palo Alto Firewalls</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/general-question-to-software-updates-of-palo-alto-firewalls/m-p/141291#M48380</link>
      <description>&lt;P&gt;You can check here for PAN OS versions with critical &amp;nbsp;issues:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Management-Articles/Critical-Issues-Addressed-in-PAN-OS-Releases/ta-p/52882" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Management-Articles/Critical-Issues-Addressed-in-PAN-OS-Releases/ta-p/52882&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 06 Feb 2017 14:41:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/general-question-to-software-updates-of-palo-alto-firewalls/m-p/141291#M48380</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2017-02-06T14:41:03Z</dc:date>
    </item>
    <item>
      <title>Re: General question to software updates of Palo Alto Firewalls</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/general-question-to-software-updates-of-palo-alto-firewalls/m-p/141292#M48381</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/11943"&gt;@kiwi&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hi Kim!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So would that be an appropriate procedure:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I disable preemption on both firewalls.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I update my active firewall to 7.1.7 and do a reboot.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;my passive 7.0.7 firewall gets the active one.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My 7.1.7 firewall is again up, but is still passive.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So I just do a reboot on my 7.0.7 firewall so that my 7.1.7 becomes again the active one.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;PS: Or is there a command to manually make one firewall active?&lt;/P&gt;</description>
      <pubDate>Mon, 06 Feb 2017 15:02:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/general-question-to-software-updates-of-palo-alto-firewalls/m-p/141292#M48381</guid>
      <dc:creator>MPI-AE</dc:creator>
      <dc:date>2017-02-06T15:02:07Z</dc:date>
    </item>
    <item>
      <title>Re: General question to software updates of Palo Alto Firewalls</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/general-question-to-software-updates-of-palo-alto-firewalls/m-p/141361#M48398</link>
      <description>&lt;P&gt;The command via ssh to initiate a failover is&amp;nbsp;&lt;EM&gt;request high-availablity state suspend&lt;/EM&gt; from the active firewall will bring your passive unit to active status. During the upgrade I would recommend updating whatever unit is active, fully upgrading to 7.1.7, then manually do the failover from your active unit making the newly updated 7.1.7 the active firewall.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I would never try to process an upgrade on the active unit while it's still processing traffic if you have an active-passive HA setup. Just upgrade your passive unit that isn't handling any traffic so if for some reason the update bombs out traffic is never interuppted and you can guarentee that the updated unit has returned to normal operations before kicking traffic to it.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 06 Feb 2017 19:48:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/general-question-to-software-updates-of-palo-alto-firewalls/m-p/141361#M48398</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2017-02-06T19:48:56Z</dc:date>
    </item>
  </channel>
</rss>

