<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: upgrade of PA-500 in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/upgrade-of-pa-500/m-p/308643#M80060</link>
    <description>&lt;P&gt;Best practice, is to fail traffic to the passive as the first step after disabling pre-empt(personally I have it off all the time anyway.)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Then step through each iteration, switching firewalls at each step to confirm the upgrade is successful and traffic still passes.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;From what you say you have upgraded the passive all the way in one go. You could disable pre-empt now and fail the traffic over and see if it works but your more likely to see and issue.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Better option would be to downgrade the passive and then fail over to it and do one step at a time on each. That way they are only ever one version different be it Major, Minor or Increment.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 30 Jan 2020 08:18:27 GMT</pubDate>
    <dc:creator>RobinClayton</dc:creator>
    <dc:date>2020-01-30T08:18:27Z</dc:date>
    <item>
      <title>upgrade of PA-500</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/upgrade-of-pa-500/m-p/308627#M80058</link>
      <description>&lt;P&gt;when in process of upgrading OS for pa-500 active/passive pair, on the passive devic i upgraded from 7.115 -- 8.0.0(download)--&amp;gt;8.0.20(install) --&amp;gt;8.1.0(download) --&amp;gt;8.1.12(install)&amp;nbsp;&lt;/P&gt;&lt;P&gt;now passive device is 2 major os version ahed , looking for ideas how can I perform upgrade on active ideas. now if i enable HA , i think one device being ahead of 2 major os version and preemption enabled it will cause all sort&amp;nbsp; of weird issues any smart ideas other then downgrading passive device .?&lt;/P&gt;</description>
      <pubDate>Thu, 30 Jan 2020 06:27:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/upgrade-of-pa-500/m-p/308627#M80058</guid>
      <dc:creator>Ritika</dc:creator>
      <dc:date>2020-01-30T06:27:57Z</dc:date>
    </item>
    <item>
      <title>Re: upgrade of PA-500</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/upgrade-of-pa-500/m-p/308643#M80060</link>
      <description>&lt;P&gt;Best practice, is to fail traffic to the passive as the first step after disabling pre-empt(personally I have it off all the time anyway.)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Then step through each iteration, switching firewalls at each step to confirm the upgrade is successful and traffic still passes.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;From what you say you have upgraded the passive all the way in one go. You could disable pre-empt now and fail the traffic over and see if it works but your more likely to see and issue.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Better option would be to downgrade the passive and then fail over to it and do one step at a time on each. That way they are only ever one version different be it Major, Minor or Increment.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 30 Jan 2020 08:18:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/upgrade-of-pa-500/m-p/308643#M80060</guid>
      <dc:creator>RobinClayton</dc:creator>
      <dc:date>2020-01-30T08:18:27Z</dc:date>
    </item>
    <item>
      <title>Re: upgrade of PA-500</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/upgrade-of-pa-500/m-p/308785#M80095</link>
      <description>&lt;P&gt;as long as one device is at a higher version, it will be 'non-functional' and the lower version member will be active&amp;nbsp;&lt;/P&gt;&lt;P&gt;preemption will not interfere here&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;the only way to change that is by suspending the passive member, so you can upgrade it while the already ugraded member takes the traffic&lt;/P&gt;&lt;P&gt;as soon as you unsuspend the lower version member it will take on the active role&lt;/P&gt;</description>
      <pubDate>Thu, 30 Jan 2020 21:18:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/upgrade-of-pa-500/m-p/308785#M80095</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2020-01-30T21:18:16Z</dc:date>
    </item>
  </channel>
</rss>

