- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
03-06-2022 09:16 AM
Hi,
I have the following situation, a HA cluster managed by panorama. For testing purpose I would like to downgrade it to an 8.1.21 release. Coming from 9.1.12 release.
Couple of question:
Should I always perform upgrades / downgrades from Panorama, I they are panorama managed?
(upgrading cluster I did without panorama using Ansible script and manual approach using webgui)
When you downgrade a firewall it always asks what version you would like to use (running-config or autosave configs)
Most documentation says use the autosave of the previous version if it is still on the device, in this case I do not have the autosave for the version 8.1.21. When I using the running config I will convert it to compatible 8.1.21?
Regarding the configs when managed by panorama there is nothing in the config besides the mgt IP's and panorama, when I do a named configuration export. Only the system state will show the configs received from panorama.
Using webui downgrade I was able to get back to 9.0 release. Going to 8.1 failed and I had to revert to 9.0 again using the debug swm command.
When downgrading will the palo fetch the config from panorama? (normally push only (new to panorama)
Trying to understand how the downgrade would work and why it failed for the 8.1
Tnx
03-10-2022 04:39 AM
no requirement to perform the up/downgrades from panorama
when no autosave is available, the running config will be converted (including the shared panorama config). if unsupported features have been configured, the conversion may fail
03-10-2022 04:39 AM
no requirement to perform the up/downgrades from panorama
when no autosave is available, the running config will be converted (including the shared panorama config). if unsupported features have been configured, the conversion may fail
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!