- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
02-27-2025 01:30 AM
Hi
I am new to Palo Alto firewalls. I need to upgrade the firmware on PA-3220 firewalls in A-P HA . Firewalls doesn't have management ports connected to network and they are remote. It looks like i need management port access of individual firewall to upgrade the firmware. Is it possible to upgrade without management port access? if so, how do you do that? if it is required, can i use any other ports for management connectivity of the firewall for firmware upgrade?
Thanks
02-27-2025 02:52 AM
HA Function | Recommended Interface | Purpose |
---|---|---|
HA1 (Control Link) | Management Port or Ethernet1/1 – Ethernet1/9 | Synchronizes configuration, heartbeats, and failover messages |
HA1 Backup (Optional) | Ethernet1/10 – Ethernet1/12 | Backup for HA1 in case of failure |
HA2 (Data Link) | Ethernet1/10 – Ethernet1/12 | Synchronizes session tables, forwarding tables, and objects |
HA2 Backup (Optional) | Ethernet1/9 – Ethernet1/12 | Backup for HA2 if the primary link fails |
HA3 (Packet Forwarding Sync, for Active-Active HA only) | Ethernet1/10 – Ethernet1/12 | Syncs packets in Active-Active mode |
02-27-2025 03:06 AM
Hi
What would be the dedicated HA management interface when we do the upgrade. That interface IP shouldn't sync across the devices. can we use any ports other than mgmt port?
Thanks
02-27-2025 05:26 AM
You need mgmt port to access specific device.
Only active firewall can be accessed through dataplane ports.
Procedure:
Upgrade passive
Reboot passive
Wait until passive returns from reboot and is functional
Upgrade active
Reboot active
If you have preemtion enabled then active role will migrate back to the firewall it was initially.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!