Best Practices for PAN-OS Upgrade without downtime

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Palo Alto Networks Approved
Palo Alto Networks Approved
Community Expert Verified
Community Expert Verified

Best Practices for PAN-OS Upgrade without downtime

L2 Linker

Hello all,

 

i have Active /passive firewalls

 

how can i upgrade PAN-OS without downtime ??

 

1-when i upgrade active , it will reboot then passive will be active ..

 

2- When i upgrade the new active is it will be back to old active again ?? what about OS mismatching is it have any impact on HA

 

3- If both devices will be for VPN ? Tunnel will be down with failover ?

17 REPLIES 17

@markk96

 

When I have left it mismatched for no more than 12 hours it won't let me commit changes

@OtakarKlier

 

I do a suspend when I fail the primary over to upgrade it and then again on the secondary when I fail back to the primary. But in the past I have not had to suspend the secondary when I go to upgrade it when it is already in the passive position.

I use Panorama, I have not had any issues commiting to them after leaving them mismatched for 24 hours.

  • 15853 Views
  • 17 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!