PaloAlto firewall HA upgrade

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

PaloAlto firewall HA upgrade

L0 Member

Hi

I am new to Palo Alto firewalls. I need to upgrade the firmware on PA-3220 firewalls in A-P HA . Firewalls doesn't have management ports connected to network and they are remote. It looks like i need management port access of individual firewall to upgrade the firmware. Is it possible to upgrade without management port access? if so, how do you do that? if it is required, can i use any other ports for management connectivity of the firewall for firmware upgrade?

 

Thanks

3 REPLIES 3

L4 Transporter

Recommended HA Interface Assignments

HA Function Recommended Interface Purpose
HA1 (Control Link) Management Port or Ethernet1/1 – Ethernet1/9 Synchronizes configuration, heartbeats, and failover messages
HA1 Backup (Optional) Ethernet1/10 – Ethernet1/12 Backup for HA1 in case of failure
HA2 (Data Link) Ethernet1/10 – Ethernet1/12 Synchronizes session tables, forwarding tables, and objects
HA2 Backup (Optional) Ethernet1/9 – Ethernet1/12 Backup for HA2 if the primary link fails
HA3 (Packet Forwarding Sync, for Active-Active HA only) Ethernet1/10 – Ethernet1/12 Syncs packets in Active-Active mode
Best Regards,
Suresh

Hi

What would be the dedicated HA management interface when we do the upgrade. That interface IP shouldn't sync across the devices. can we use any ports other than mgmt port?

 

Thanks

Cyber Elite
Cyber Elite

You need mgmt port to access specific device.

Only active firewall can be accessed through dataplane ports.

 

Procedure:

Upgrade passive

Reboot passive

Wait until passive returns from reboot and is functional

Upgrade active

Reboot active

If you have preemtion enabled then active role will migrate back to the firewall it was initially.

Principal Architect @ Cloud Carib Ltd
Palo Alto Networks certified from 2011
  • 362 Views
  • 3 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!