How to downgrade WF-500B?

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

How to downgrade WF-500B?

L1 Bithead

Does anyone know how to downgrade a WF appliance to a previous feature release?  We're just getting started with the WF-500B and our appliances arrived loaded with version 10.2.2 but we have to deploy them in a 10.1.11 environment (with other PA NGFWs and Panorama).
So far, I haven't found solid documentation on an appliance downgrade procedure. Running the "request system software check" command shows only the current (10.2.2) and newer releases. But earlier releases are available for download at the customer support portal. I downloaded 10.1.0 and 10.1.11 WF images, then SCP'd both to a WF-500B. I then initiated the install with "request system software install version 10.1.11" command. Output on the job id appeared to show a successful install:

admin@wf-500b-50> show jobs id 8

Enqueued Dequeued ID Type Status Result Completed
------------------------------------------------------------------------------------------------------------------------------
2023/11/02 12:44:05 12:44:05 8 SWInstall FIN OK 12:45:40
Warnings:

Details:Loading into software manager
Successfully loaded image into software manager
Software installation successfully completed. Please reboot to switch to the new version.


Upon reboot however, the WF-500B booted to a maintenance recovery tool. The message read: "ATTENTION: A critical error has been detected preventing proper boot up of the device. Please contact Palo Alto Networks to resolve this issue."

The Entry Reason for this error read: "SecureBoot file verification failure". Further detail on the error message states "ErrorCode: SecureBoot Integrity file check failure[1]"

Fortunately, there was an option in the recovery menu to reinstall 10.2.2. After doing so, the appliance booted successfully but we're back where we started (on 10.2 code). Not sure how to proceed from here and Palo support has yet to provide a solution.

1 accepted solution

Accepted Solutions

Community Team Member

Hi @ParentS ,

 

Unfortunately, WF-500B runs a native code of 10.2.2 and cannot be downgraded from there. Here is a compatibility matrix for WF devices.

 

WF-500B running 10.2 and firewalls running 10.1 is not a problem. WF follows the same "PAN-OS management requirement" as Panorama. The firewalls reporting to WF, must be running equal or lower PAN-OS version. Same as Panorama - devices managed by Panorama must be running an equal or lower PAN-OS version (this of course applies to WF devices managed by Panorama too).

The potential problem would be Panorama being 10.1 and having issues with managing the 10.2 WF-500B. In this scenario you would have to do the following:

- Configure the WF-500B appliances locally

- Upgrade Panorama to be to 10.2.6 (preferred release) in order to manage the WF devices. Firewalls can stay on 10.1 for as long as needed
- Migrate WF applianced to Panorama

 

Panorama will be in 10.2, WF in 10.2, and your firewalls can remain in 10.1.

LIVEcommunity team member
Stay Secure,
Jay
Don't forget to Like items if a post is helpful to you!

Please help out other users and “Accept as Solution” if a post helps solve your problem !

Read more about how and why to accept solutions.

View solution in original post

2 REPLIES 2

Community Team Member

Hi @ParentS ,

 

Unfortunately, WF-500B runs a native code of 10.2.2 and cannot be downgraded from there. Here is a compatibility matrix for WF devices.

 

WF-500B running 10.2 and firewalls running 10.1 is not a problem. WF follows the same "PAN-OS management requirement" as Panorama. The firewalls reporting to WF, must be running equal or lower PAN-OS version. Same as Panorama - devices managed by Panorama must be running an equal or lower PAN-OS version (this of course applies to WF devices managed by Panorama too).

The potential problem would be Panorama being 10.1 and having issues with managing the 10.2 WF-500B. In this scenario you would have to do the following:

- Configure the WF-500B appliances locally

- Upgrade Panorama to be to 10.2.6 (preferred release) in order to manage the WF devices. Firewalls can stay on 10.1 for as long as needed
- Migrate WF applianced to Panorama

 

Panorama will be in 10.2, WF in 10.2, and your firewalls can remain in 10.1.

LIVEcommunity team member
Stay Secure,
Jay
Don't forget to Like items if a post is helpful to you!

Please help out other users and “Accept as Solution” if a post helps solve your problem !

Read more about how and why to accept solutions.

Thanks Jay! Much appreciated. Sounds like we'll have to upgrade Pano if we want to manage the WF clusters centrally.

  • 1 accepted solution
  • 953 Views
  • 2 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!