<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: HA Active/Passive upgrade question in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/ha-active-passive-upgrade-question/m-p/197982#M58812</link>
    <description>&lt;P&gt;So big thank you, I actually figured it out - because I couldn't see a 2nd IP, I wasn't sure one was configured, but after trying the next sequential IP after the primary, I was able to get logged into the secondary FW's management IP - I was just confused since it didn't reference that at ALL anywhere in the setup/config.&lt;BR /&gt;&lt;BR /&gt;Thanks for the help, much apreciated!&lt;/P&gt;</description>
    <pubDate>Wed, 31 Jan 2018 17:57:37 GMT</pubDate>
    <dc:creator>JohPalmer</dc:creator>
    <dc:date>2018-01-31T17:57:37Z</dc:date>
    <item>
      <title>HA Active/Passive upgrade question</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ha-active-passive-upgrade-question/m-p/197956#M58799</link>
      <description>&lt;P&gt;Hey PA Guru's!&amp;nbsp; &amp;nbsp;I have a question I haven't really seen on the KB's and documentation on HA upgrades, and wanted to get some insight.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I currently have a pair of PA-3050's we're looking to upgrade, and i've reviewed the docs on the recommended procedures here:&amp;nbsp;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;A href="https://www.paloaltonetworks.com/documentation/80/pan-os/newfeaturesguide/upgrade-to-pan-os-80/upgrade-the-firewall-to-pan-os-80/upgrade-an-ha-firewall-pair-to-pan-os-80" target="_blank"&gt;https://www.paloaltonetworks.com/documentation/80/pan-os/newfeaturesguide/upgrade-to-pan-os-80/upgrade-the-firewall-to-pan-os-80/upgrade-an-ha-firewall-pair-to-pan-os-80&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;and here:&lt;BR /&gt;&lt;BR /&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Featured-Articles/Best-Practices-for-PAN-OS-Upgrade/ta-p/111045" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Featured-Articles/Best-Practices-for-PAN-OS-Upgrade/ta-p/111045&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In this case, we are upgrading from 7.0.11 to 8.0.5.&amp;nbsp; We did a successful upgrade on this on a stand-alone firewall last week without any issues.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My question is, when you upgrade a system in an HA Pair where you need to do it in stages, how can you specify which firewall you want to upgrade?&amp;nbsp; I understand the instructions, but they don't seem to specify this item.&amp;nbsp; For example:&lt;BR /&gt;&lt;BR /&gt;PA-1 (current primary)&lt;BR /&gt;PA-2 (current backup)&lt;BR /&gt;&lt;BR /&gt;disable pre-empt&lt;BR /&gt;suspend local device (either with CLI or GUI steps)&lt;BR /&gt;&lt;BR /&gt;My question comes in at this point - As the firewall will now fail over to the backup device, and each FW does not have its own individual IP to log into (as compared to VVRP style failover setups, or other A/P designs where each device has its own IP), how can you clearly specify that you want to upgrade, reboot, upgrade again, reboot, just PA-1?&amp;nbsp;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;I am likely just missing something right in front of my face on this, but I'd rather ask and find out I'm blind, than charge ahead and hope it just 'works'.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Any assistance would be greatly appreciated!&lt;/P&gt;</description>
      <pubDate>Wed, 31 Jan 2018 16:29:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ha-active-passive-upgrade-question/m-p/197956#M58799</guid>
      <dc:creator>JohPalmer</dc:creator>
      <dc:date>2018-01-31T16:29:10Z</dc:date>
    </item>
    <item>
      <title>Re: HA Active/Passive upgrade question</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ha-active-passive-upgrade-question/m-p/197968#M58803</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/78672"&gt;@JohPalmer&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Is there a reason that you don't have individual IPs assigned to the management interface on the firewalls? That would really be the proper way of doing things without having to console into both devices.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 31 Jan 2018 16:46:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ha-active-passive-upgrade-question/m-p/197968#M58803</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2018-01-31T16:46:01Z</dc:date>
    </item>
    <item>
      <title>Re: HA Active/Passive upgrade question</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ha-active-passive-upgrade-question/m-p/197973#M58806</link>
      <description>&lt;P&gt;Hey there -&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm new to the environment where these are (also been a bit since i managed PAN FW's).&amp;nbsp; If they do have individual IP's, where would they be set so I can confirm?&lt;BR /&gt;&lt;BR /&gt;and in the off chance that they don't have, would I just need to upgrade them each individually and fail them over on reboot, and hope things work? &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&amp;nbsp; &amp;nbsp;(trying to be a bit more cautious than that)&lt;/P&gt;</description>
      <pubDate>Wed, 31 Jan 2018 17:15:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ha-active-passive-upgrade-question/m-p/197973#M58806</guid>
      <dc:creator>JohPalmer</dc:creator>
      <dc:date>2018-01-31T17:15:43Z</dc:date>
    </item>
    <item>
      <title>Re: HA Active/Passive upgrade question</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ha-active-passive-upgrade-question/m-p/197974#M58807</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/78672"&gt;@JohPalmer&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;It would be under Device &amp;gt; Setup&amp;nbsp; and then under the 'Interfaces' tab you should have a listing for 'Mangement'. If they don't have individual IP addresses then the only device that you could work on without plugging into the console cable would be the active device. I would recommend simply configuring the management interfaces with unique IPs before you perform the update.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 31 Jan 2018 17:19:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ha-active-passive-upgrade-question/m-p/197974#M58807</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2018-01-31T17:19:54Z</dc:date>
    </item>
    <item>
      <title>Re: HA Active/Passive upgrade question</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ha-active-passive-upgrade-question/m-p/197976#M58808</link>
      <description>&lt;P&gt;Looking at the section for Device &amp;gt; Setup, the Management interface only has one IP address listed.&amp;nbsp; Checking through the CLI under the 'deviceconfig' tree, that's also showing only one management IP.&amp;nbsp; The only other IP's&amp;nbsp; (aside from gateway, DNS servers, NTP) are the HA IP's (which use 1.1.1.1 and 1.1.1.2 for the peering IP's), nothing to distinguish the FW's from each other.&lt;/P&gt;</description>
      <pubDate>Wed, 31 Jan 2018 17:25:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ha-active-passive-upgrade-question/m-p/197976#M58808</guid>
      <dc:creator>JohPalmer</dc:creator>
      <dc:date>2018-01-31T17:25:57Z</dc:date>
    </item>
    <item>
      <title>Re: HA Active/Passive upgrade question</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ha-active-passive-upgrade-question/m-p/197977#M58809</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/78672"&gt;@JohPalmer&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;You would only see the one IP address since you are only looking at the active firewalls configuration. If you were to console into the other device there should be another management IP address present that is different from the one you just looked at.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 31 Jan 2018 17:28:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ha-active-passive-upgrade-question/m-p/197977#M58809</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2018-01-31T17:28:08Z</dc:date>
    </item>
    <item>
      <title>Re: HA Active/Passive upgrade question</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ha-active-passive-upgrade-question/m-p/197979#M58810</link>
      <description>&lt;P&gt;So, it looks like the answer is I'll need to go on-site and console into both and get the deviceconfig sections to get the IP's?&lt;/P&gt;</description>
      <pubDate>Wed, 31 Jan 2018 17:36:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ha-active-passive-upgrade-question/m-p/197979#M58810</guid>
      <dc:creator>JohPalmer</dc:creator>
      <dc:date>2018-01-31T17:36:04Z</dc:date>
    </item>
    <item>
      <title>Re: HA Active/Passive upgrade question</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ha-active-passive-upgrade-question/m-p/197981#M58811</link>
      <description>&lt;P&gt;Also, as I'm on 7.0.11 on this HA Pair, there's not an interfaces tab under Device &amp;gt; Setup &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 31 Jan 2018 17:50:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ha-active-passive-upgrade-question/m-p/197981#M58811</guid>
      <dc:creator>JohPalmer</dc:creator>
      <dc:date>2018-01-31T17:50:32Z</dc:date>
    </item>
    <item>
      <title>Re: HA Active/Passive upgrade question</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ha-active-passive-upgrade-question/m-p/197982#M58812</link>
      <description>&lt;P&gt;So big thank you, I actually figured it out - because I couldn't see a 2nd IP, I wasn't sure one was configured, but after trying the next sequential IP after the primary, I was able to get logged into the secondary FW's management IP - I was just confused since it didn't reference that at ALL anywhere in the setup/config.&lt;BR /&gt;&lt;BR /&gt;Thanks for the help, much apreciated!&lt;/P&gt;</description>
      <pubDate>Wed, 31 Jan 2018 17:57:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ha-active-passive-upgrade-question/m-p/197982#M58812</guid>
      <dc:creator>JohPalmer</dc:creator>
      <dc:date>2018-01-31T17:57:37Z</dc:date>
    </item>
    <item>
      <title>Re: HA Active/Passive upgrade question</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ha-active-passive-upgrade-question/m-p/198015#M58822</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/78672"&gt;@JohPalmer&lt;/a&gt;&amp;nbsp; FYI if you plan on being able to synchronize between the two firewalls you will need to move them both to 7.1.x before upgrading them to 8.0.x.&amp;nbsp; They will not synchronize&amp;nbsp;2 revisions down, only 1.&amp;nbsp; We asked support about this and that is what they told us.&lt;/P&gt;&lt;P&gt;Your path should be 7.0.11&amp;nbsp;-&amp;gt; 7.1.0 -&amp;gt; 8.0.0 -&amp;gt; &amp;nbsp;8.0.5&amp;nbsp; (we were recommended by our SEs to go to 8.0.7, Panorama has not had a problem with this but we have not moved our firewalls yet.).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Brian&lt;/P&gt;</description>
      <pubDate>Wed, 31 Jan 2018 20:23:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ha-active-passive-upgrade-question/m-p/198015#M58822</guid>
      <dc:creator>BrianRa</dc:creator>
      <dc:date>2018-01-31T20:23:13Z</dc:date>
    </item>
    <item>
      <title>Re: HA Active/Passive upgrade question</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ha-active-passive-upgrade-question/m-p/198021#M58824</link>
      <description>&lt;P&gt;Good information to have actually.&amp;nbsp; I may need to update our plan to move up versions to 7.1, test, then move up to 8.0 and test, then jump to the final.&lt;/P&gt;</description>
      <pubDate>Wed, 31 Jan 2018 20:43:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ha-active-passive-upgrade-question/m-p/198021#M58824</guid>
      <dc:creator>JohPalmer</dc:creator>
      <dc:date>2018-01-31T20:43:15Z</dc:date>
    </item>
    <item>
      <title>Re: HA Active/Passive upgrade question</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ha-active-passive-upgrade-question/m-p/198028#M58826</link>
      <description>&lt;P&gt;Supposedly with the active on 7.1.x and the passive on 8.0.x you can tell them to fail over and the passive will pickup without any problems.&lt;/P&gt;</description>
      <pubDate>Wed, 31 Jan 2018 20:58:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ha-active-passive-upgrade-question/m-p/198028#M58826</guid>
      <dc:creator>BrianRa</dc:creator>
      <dc:date>2018-01-31T20:58:06Z</dc:date>
    </item>
  </channel>
</rss>

