<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Best Practices for PAN-OS Upgrade without downtime in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/best-practices-for-pan-os-upgrade-without-downtime/m-p/197199#M58640</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;If you suspend the device (i usually dont but understand why TAC would say so) make sure to make it active again or verify that it is active prior to upgrading the second one otherwise everything will go down during the reboot since one PAN is rebooting and the other is suspended. I had to learn this the hard way when another admin suspended a device and didtn make it active again :(.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;</description>
    <pubDate>Fri, 26 Jan 2018 20:55:11 GMT</pubDate>
    <dc:creator>OtakarKlier</dc:creator>
    <dc:date>2018-01-26T20:55:11Z</dc:date>
    <item>
      <title>Best Practices for PAN-OS Upgrade without downtime</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/best-practices-for-pan-os-upgrade-without-downtime/m-p/149308#M49772</link>
      <description>&lt;P&gt;Hello all,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;i have Active /passive firewalls&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;how can i upgrade PAN-OS without downtime ??&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1-when i upgrade active , it will reboot then passive will be active ..&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;2- When i upgrade the new active is it will be back to old active again ?? what about OS mismatching is it have any impact on HA&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;3- If both devices will be for VPN ? Tunnel will be down with failover ?&lt;/P&gt;</description>
      <pubDate>Fri, 24 Mar 2017 07:41:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/best-practices-for-pan-os-upgrade-without-downtime/m-p/149308#M49772</guid>
      <dc:creator>NetworkGeek</dc:creator>
      <dc:date>2017-03-24T07:41:09Z</dc:date>
    </item>
    <item>
      <title>Re: Best Practices for PAN-OS Upgrade without downtime</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/best-practices-for-pan-os-upgrade-without-downtime/m-p/149315#M49773</link>
      <description>&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Management-Articles/How-to-upgrade-a-High-Availability-HA-pair/ta-p/57081" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Management-Articles/How-to-upgrade-a-High-Availability-HA-pair/ta-p/57081&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 24 Mar 2017 07:55:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/best-practices-for-pan-os-upgrade-without-downtime/m-p/149315#M49773</guid>
      <dc:creator>santonic</dc:creator>
      <dc:date>2017-03-24T07:55:43Z</dc:date>
    </item>
    <item>
      <title>Re: Best Practices for PAN-OS Upgrade without downtime</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/best-practices-for-pan-os-upgrade-without-downtime/m-p/149327#M49777</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Last time l did this way:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1) Disable preemption&amp;nbsp;(if any) from the both devices.&lt;/P&gt;&lt;P&gt;2) Upgrade FIRST&amp;nbsp;PASSIVE then reboot.&lt;/P&gt;&lt;P&gt;3) Upgrade the&amp;nbsp;currently active box, before reboot failover&amp;nbsp;to passive with already new PAN-OS running on it.&lt;/P&gt;&lt;P&gt;4) Reboot the first device (the one which was active).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;From what l understood&amp;nbsp;all session wich are terminates on the Active box will be reestablished (BGP, OSPF, IPSec etc). Only traversing session will not be interrupted during failover. So yes VPN will be reestablished (short downtime)&lt;/P&gt;</description>
      <pubDate>Fri, 24 Mar 2017 08:53:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/best-practices-for-pan-os-upgrade-without-downtime/m-p/149327#M49777</guid>
      <dc:creator>TranceforLife</dc:creator>
      <dc:date>2017-03-24T08:53:33Z</dc:date>
    </item>
    <item>
      <title>Re: Best Practices for PAN-OS Upgrade without downtime</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/best-practices-for-pan-os-upgrade-without-downtime/m-p/149329#M49778</link>
      <description>&lt;P&gt;I always switchover to passive first, then upgrade previously active one. That way you know both are working before upgrade.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 24 Mar 2017 09:17:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/best-practices-for-pan-os-upgrade-without-downtime/m-p/149329#M49778</guid>
      <dc:creator>santonic</dc:creator>
      <dc:date>2017-03-24T09:17:03Z</dc:date>
    </item>
    <item>
      <title>Re: Best Practices for PAN-OS Upgrade without downtime</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/best-practices-for-pan-os-upgrade-without-downtime/m-p/149330#M49779</link>
      <description>&lt;P&gt;True.. Same way you can test by upgrading passive first, rebooting and failing over. If there is an issue you back to old code on the previously active and rolling back on the second box. Really couple;e ways to do it&amp;nbsp;and i think all of them are correct :0&lt;/P&gt;</description>
      <pubDate>Fri, 24 Mar 2017 09:22:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/best-practices-for-pan-os-upgrade-without-downtime/m-p/149330#M49779</guid>
      <dc:creator>TranceforLife</dc:creator>
      <dc:date>2017-03-24T09:22:04Z</dc:date>
    </item>
    <item>
      <title>Re: Best Practices for PAN-OS Upgrade without downtime</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/best-practices-for-pan-os-upgrade-without-downtime/m-p/149513#M49799</link>
      <description>&lt;P&gt;Thank you all ...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 25 Mar 2017 07:45:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/best-practices-for-pan-os-upgrade-without-downtime/m-p/149513#M49799</guid>
      <dc:creator>NetworkGeek</dc:creator>
      <dc:date>2017-03-25T07:45:53Z</dc:date>
    </item>
    <item>
      <title>Re: Best Practices for PAN-OS Upgrade without downtime</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/best-practices-for-pan-os-upgrade-without-downtime/m-p/197151#M58629</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/37163"&gt;@TranceforLife&lt;/a&gt;&lt;/P&gt;&lt;P&gt;Did you suspend that passive firewall before upgrading it?&lt;/P&gt;</description>
      <pubDate>Fri, 26 Jan 2018 17:33:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/best-practices-for-pan-os-upgrade-without-downtime/m-p/197151#M58629</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2018-01-26T17:33:13Z</dc:date>
    </item>
    <item>
      <title>Re: Best Practices for PAN-OS Upgrade without downtime</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/best-practices-for-pan-os-upgrade-without-downtime/m-p/197185#M58630</link>
      <description>&lt;P&gt;I always Failover to the passive Palo, then I go back to what I consider the "Primary" palo and upgrade it, once it comes up and everything is running on it, I fail back to it.&amp;nbsp; I run that for a day or two and then I upgrade the passive node.&lt;/P&gt;</description>
      <pubDate>Fri, 26 Jan 2018 20:12:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/best-practices-for-pan-os-upgrade-without-downtime/m-p/197185#M58630</guid>
      <dc:creator>markk96</dc:creator>
      <dc:date>2018-01-26T20:12:09Z</dc:date>
    </item>
    <item>
      <title>Re: Best Practices for PAN-OS Upgrade without downtime</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/best-practices-for-pan-os-upgrade-without-downtime/m-p/197189#M58633</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/30178"&gt;@markk96&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;so you upgrade the primary first, and are you saying the firewall you are upgrading is in the suspend mode? Do you run into any issues leaving them out of synch for that long?&lt;/P&gt;</description>
      <pubDate>Fri, 26 Jan 2018 20:39:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/best-practices-for-pan-os-upgrade-without-downtime/m-p/197189#M58633</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2018-01-26T20:39:49Z</dc:date>
    </item>
    <item>
      <title>Re: Best Practices for PAN-OS Upgrade without downtime</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/best-practices-for-pan-os-upgrade-without-downtime/m-p/197191#M58635</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/18719"&gt;@jdprovine&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Suspend mode only takes the PAN out of the HA as a viable unit to fail over to.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/56810"&gt;@NetworkGeek&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Also the VPN downtime is very minimal. I used to updrade a pair of 2050's while I was VPN'ed into them with Global Protect. Maybe lost 1-2 pings at most and never dropped from VPN.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Fri, 26 Jan 2018 20:45:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/best-practices-for-pan-os-upgrade-without-downtime/m-p/197191#M58635</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2018-01-26T20:45:36Z</dc:date>
    </item>
    <item>
      <title>Re: Best Practices for PAN-OS Upgrade without downtime</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/best-practices-for-pan-os-upgrade-without-downtime/m-p/197194#M58637</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/27580"&gt;@OtakarKlier&lt;/a&gt;&lt;/P&gt;&lt;P&gt;The only reason I bring it up is because TAC said that the best practice was to suspend the firewall that you are upgrading and I never had, mostly because I start the upgrade with the passive node. I wouldn't thinking that not suspending the passive node before upgrading it would cause the upgrade from&amp;nbsp; 7.1.13 to 7.1.14 would make it fail.&lt;/P&gt;</description>
      <pubDate>Fri, 26 Jan 2018 20:49:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/best-practices-for-pan-os-upgrade-without-downtime/m-p/197194#M58637</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2018-01-26T20:49:33Z</dc:date>
    </item>
    <item>
      <title>Re: Best Practices for PAN-OS Upgrade without downtime</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/best-practices-for-pan-os-upgrade-without-downtime/m-p/197195#M58638</link>
      <description>&lt;P&gt;Correct.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1. Suspend the Primary&lt;/P&gt;&lt;P&gt;2. Upgrade the Primary and Reboot&lt;/P&gt;&lt;P&gt;3. Suspend the Secondary so it fails back to the Primary.&lt;/P&gt;&lt;P&gt;4. Make sure Production is working fine on the new code.&lt;/P&gt;&lt;P&gt;5. Upgrade the Secondary.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I never have any issues leaving the OS mismatched for a couple of days.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 26 Jan 2018 20:50:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/best-practices-for-pan-os-upgrade-without-downtime/m-p/197195#M58638</guid>
      <dc:creator>markk96</dc:creator>
      <dc:date>2018-01-26T20:50:08Z</dc:date>
    </item>
    <item>
      <title>Re: Best Practices for PAN-OS Upgrade without downtime</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/best-practices-for-pan-os-upgrade-without-downtime/m-p/197197#M58639</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/27580"&gt;@OtakarKlier&lt;/a&gt;&lt;/P&gt;&lt;P&gt;I just read your message about doing the PA upgrade while on the vpn, I have always wanted to try that but I have never been brave enough too.&lt;/P&gt;</description>
      <pubDate>Fri, 26 Jan 2018 20:51:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/best-practices-for-pan-os-upgrade-without-downtime/m-p/197197#M58639</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2018-01-26T20:51:40Z</dc:date>
    </item>
    <item>
      <title>Re: Best Practices for PAN-OS Upgrade without downtime</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/best-practices-for-pan-os-upgrade-without-downtime/m-p/197199#M58640</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;If you suspend the device (i usually dont but understand why TAC would say so) make sure to make it active again or verify that it is active prior to upgrading the second one otherwise everything will go down during the reboot since one PAN is rebooting and the other is suspended. I had to learn this the hard way when another admin suspended a device and didtn make it active again :(.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Fri, 26 Jan 2018 20:55:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/best-practices-for-pan-os-upgrade-without-downtime/m-p/197199#M58640</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2018-01-26T20:55:11Z</dc:date>
    </item>
    <item>
      <title>Re: Best Practices for PAN-OS Upgrade without downtime</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/best-practices-for-pan-os-upgrade-without-downtime/m-p/197204#M58642</link>
      <description>&lt;P&gt;I have never had any issue making the suspended Palo active again before I upgrade it, that is what I always do.&amp;nbsp; I make sure they both see one is active and one is passive.&amp;nbsp; Then I start my upgrade and reboot.&lt;/P&gt;</description>
      <pubDate>Fri, 26 Jan 2018 21:04:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/best-practices-for-pan-os-upgrade-without-downtime/m-p/197204#M58642</guid>
      <dc:creator>markk96</dc:creator>
      <dc:date>2018-01-26T21:04:17Z</dc:date>
    </item>
    <item>
      <title>Re: Best Practices for PAN-OS Upgrade without downtime</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/best-practices-for-pan-os-upgrade-without-downtime/m-p/197206#M58644</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/30178"&gt;@markk96&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When I have left it mismatched for no more than 12 hours it won't let me commit changes&lt;/P&gt;</description>
      <pubDate>Fri, 26 Jan 2018 21:12:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/best-practices-for-pan-os-upgrade-without-downtime/m-p/197206#M58644</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2018-01-26T21:12:40Z</dc:date>
    </item>
    <item>
      <title>Re: Best Practices for PAN-OS Upgrade without downtime</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/best-practices-for-pan-os-upgrade-without-downtime/m-p/197207#M58645</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/27580"&gt;@OtakarKlier&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I do a suspend when I fail the primary over to upgrade it and then again on the secondary when I fail back to the primary. But in the past I have not had to suspend the secondary when I go to upgrade it when it is already in the passive position.&lt;/P&gt;</description>
      <pubDate>Fri, 26 Jan 2018 21:15:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/best-practices-for-pan-os-upgrade-without-downtime/m-p/197207#M58645</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2018-01-26T21:15:08Z</dc:date>
    </item>
    <item>
      <title>Re: Best Practices for PAN-OS Upgrade without downtime</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/best-practices-for-pan-os-upgrade-without-downtime/m-p/197208#M58646</link>
      <description>&lt;P&gt;I use Panorama, I have not had any issues commiting to them after leaving them mismatched for 24 hours.&lt;/P&gt;</description>
      <pubDate>Fri, 26 Jan 2018 21:17:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/best-practices-for-pan-os-upgrade-without-downtime/m-p/197208#M58646</guid>
      <dc:creator>markk96</dc:creator>
      <dc:date>2018-01-26T21:17:18Z</dc:date>
    </item>
  </channel>
</rss>

