- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
03-24-2017 12:41 AM
Hello all,
i have Active /passive firewalls
how can i upgrade PAN-OS without downtime ??
1-when i upgrade active , it will reboot then passive will be active ..
2- When i upgrade the new active is it will be back to old active again ?? what about OS mismatching is it have any impact on HA
3- If both devices will be for VPN ? Tunnel will be down with failover ?
01-26-2018 01:15 PM
I do a suspend when I fail the primary over to upgrade it and then again on the secondary when I fail back to the primary. But in the past I have not had to suspend the secondary when I go to upgrade it when it is already in the passive position.
01-26-2018 01:17 PM
I use Panorama, I have not had any issues commiting to them after leaving them mismatched for 24 hours.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!