Showing results for 
Show  only  | Search instead for 
Did you mean: 


L1 Bithead

Hi All,


PA3020 and PA200 are used to form an IPSEC tunnel. Would there be any compatibility issue if we upgrade PA3020 to PANOS 9.1.12-h4 while keeping PA200 on PANOS 8.1.21?

Any known issues if we upgrade PA3020 to PanOS 9.1.12-h4? PA3020 Current PanOS: 8.1.20-h1


Community Team Member

Hi @ongkai ,


That shouldn't be a problem.  That said, please always check the release notes for known issues on the new OS version:

PAN-OS 9.1.12 Known Issues





LIVEcommunity team member, CISSP
Please help out other users and “Accept as Solution” if a post helps solve your problem !

Read more about how and why to accept solutions.

L6 Presenter

We just upgraded a couple PA-3020s from 8.1.20-h1 to 9.1.12 (we were advised by support not to go to the hotfix if we didn't have a problem). No problems with our IPSec tunnels after the upgrade.


Something that did bite us though.... 9.1 uses a new PAN-DB URL Filter provider and license, and the existing URL database is deleted on the upgrade. We use URL Filter block on "unknown" and "not-resolved" categories (default is allow). That meant that after the upgrade the PA could not download the new license or initial database... Had to find and change until the database was initialized.

  • 2 replies
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!