- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
11-02-2023 11:21 AM
Does anyone know how to downgrade a WF appliance to a previous feature release? We're just getting started with the WF-500B and our appliances arrived loaded with version 10.2.2 but we have to deploy them in a 10.1.11 environment (with other PA NGFWs and Panorama).
So far, I haven't found solid documentation on an appliance downgrade procedure. Running the "request system software check" command shows only the current (10.2.2) and newer releases. But earlier releases are available for download at the customer support portal. I downloaded 10.1.0 and 10.1.11 WF images, then SCP'd both to a WF-500B. I then initiated the install with "request system software install version 10.1.11" command. Output on the job id appeared to show a successful install:
admin@wf-500b-50> show jobs id 8
Enqueued Dequeued ID Type Status Result Completed
------------------------------------------------------------------------------------------------------------------------------
2023/11/02 12:44:05 12:44:05 8 SWInstall FIN OK 12:45:40
Warnings:
Details:Loading into software manager
Successfully loaded image into software manager
Software installation successfully completed. Please reboot to switch to the new version.
Upon reboot however, the WF-500B booted to a maintenance recovery tool. The message read: "ATTENTION: A critical error has been detected preventing proper boot up of the device. Please contact Palo Alto Networks to resolve this issue."
The Entry Reason for this error read: "SecureBoot file verification failure". Further detail on the error message states "ErrorCode: SecureBoot Integrity file check failure[1]"
Fortunately, there was an option in the recovery menu to reinstall 10.2.2. After doing so, the appliance booted successfully but we're back where we started (on 10.2 code). Not sure how to proceed from here and Palo support has yet to provide a solution.
11-08-2023 07:59 AM
Hi @ParentS ,
Unfortunately, WF-500B runs a native code of 10.2.2 and cannot be downgraded from there. Here is a compatibility matrix for WF devices.
WF-500B running 10.2 and firewalls running 10.1 is not a problem. WF follows the same "PAN-OS management requirement" as Panorama. The firewalls reporting to WF, must be running equal or lower PAN-OS version. Same as Panorama - devices managed by Panorama must be running an equal or lower PAN-OS version (this of course applies to WF devices managed by Panorama too).
The potential problem would be Panorama being 10.1 and having issues with managing the 10.2 WF-500B. In this scenario you would have to do the following:
- Configure the WF-500B appliances locally
- Upgrade Panorama to be to 10.2.6 (preferred release) in order to manage the WF devices. Firewalls can stay on 10.1 for as long as needed
- Migrate WF applianced to Panorama
Panorama will be in 10.2, WF in 10.2, and your firewalls can remain in 10.1.
11-08-2023 07:59 AM
Hi @ParentS ,
Unfortunately, WF-500B runs a native code of 10.2.2 and cannot be downgraded from there. Here is a compatibility matrix for WF devices.
WF-500B running 10.2 and firewalls running 10.1 is not a problem. WF follows the same "PAN-OS management requirement" as Panorama. The firewalls reporting to WF, must be running equal or lower PAN-OS version. Same as Panorama - devices managed by Panorama must be running an equal or lower PAN-OS version (this of course applies to WF devices managed by Panorama too).
The potential problem would be Panorama being 10.1 and having issues with managing the 10.2 WF-500B. In this scenario you would have to do the following:
- Configure the WF-500B appliances locally
- Upgrade Panorama to be to 10.2.6 (preferred release) in order to manage the WF devices. Firewalls can stay on 10.1 for as long as needed
- Migrate WF applianced to Panorama
Panorama will be in 10.2, WF in 10.2, and your firewalls can remain in 10.1.
11-15-2023 04:04 AM
Thanks Jay! Much appreciated. Sounds like we'll have to upgrade Pano if we want to manage the WF clusters centrally.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!