- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
03-17-2019 01:21 PM
@DPWorld ,
Man you're gonna have a fun time.
Ensure that you have downloaded the following PAN-OS images. You might want to do so locally to a laptop or something you'll actually be doing the upgrade from, depending on how much free space you have on the device you might run out of space.
Basic install practices remain the same, ensure you have free disk space, ensure you disable preempt, take a backup of your configuration.
You'll then perform the upgrade like so.
You should be okay with upgrading just a single HA member through all steps before moving to the next, but you are moving through a lot of images. I would recommend that you actually break (not suspend) HA temporarily to ensure that the one you are in the middle of upgrading doesn't become active. This would envolve ensuring all cables are unplugged so that even if the device becomes "active" it isn't actually processing any traffic.
I've put this entire upgrade path on the latest recommended upgrade model which didn't really become a thing until 8.0; not knowing to model of firewall you are upgrading or your comfort in trully verifying disk space I would recommend you follow this model instead of the old model which would be fewer steps to avoid any issues.
03-17-2019 01:21 PM
@DPWorld ,
Man you're gonna have a fun time.
Ensure that you have downloaded the following PAN-OS images. You might want to do so locally to a laptop or something you'll actually be doing the upgrade from, depending on how much free space you have on the device you might run out of space.
Basic install practices remain the same, ensure you have free disk space, ensure you disable preempt, take a backup of your configuration.
You'll then perform the upgrade like so.
You should be okay with upgrading just a single HA member through all steps before moving to the next, but you are moving through a lot of images. I would recommend that you actually break (not suspend) HA temporarily to ensure that the one you are in the middle of upgrading doesn't become active. This would envolve ensuring all cables are unplugged so that even if the device becomes "active" it isn't actually processing any traffic.
I've put this entire upgrade path on the latest recommended upgrade model which didn't really become a thing until 8.0; not knowing to model of firewall you are upgrading or your comfort in trully verifying disk space I would recommend you follow this model instead of the old model which would be fewer steps to avoid any issues.
03-19-2019 02:31 PM
Thank you @BPry 🙂
Really appricate your help
08-10-2022 11:17 AM - edited 08-10-2022 11:19 AM
I have tried this after running a factory reset on a PA-3020 and reverting back to 6.0.8. The latest maintenance release is now 6.1.22. I tried to upgrade to 7.0.1 and got the following error: "Failed to install PanOS_3000-7.0.1 with the following errors. SW version is 7.0.1 Error: Upgrading from 6.1.21 to 7.0.1 requires a content version of 497 or greater and found 451-2337. Failed to install version 7.0.1 type panos" I tried from 6.1.22 as well and got the same error. This particular firewall is in a secure, offline location, so dynamic updates are not possible. The oldest dynamic update on the website today is only a month old, and 6.1.21/22 doesn't even recognize the file as valid. How is one supposed to acquire content version 497?
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!