Panorama HA Pair and Managed Log Collectors Upgrade Process - Clarification

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Palo Alto Networks Approved
Palo Alto Networks Approved
Community Expert Verified
Community Expert Verified

Panorama HA Pair and Managed Log Collectors Upgrade Process - Clarification

L3 Networker

Hello All, 

 

Planning an upgrade of a Panorama HA pair in management-only mode with two dedicated log collectors to PAN-OS 11.1.x from PAN-OS 10.2.x 

 

To assist with the explanation below: 

  • Unit A - Panorama Active Unit 
  • Unit B - Panorama Passive Unit 

 

First, after reviewing the upgrade documentation (Upgrade Panorama in an HA Configuration ) for Panorama and the log collectors, I understand the upgrade procedure as: 

  • Unit B is upgraded first referencing Upgrade Panorama Without an Internet Connection
  • Failover from A to B post-upgrade of unit B. 
  • Unit A is then upgraded. 
  • Log collectors are then upgraded simultaneously. 
  • Full commit and push from unit A post-upgrade after the log collectors have been upgraded. The push is to all managed devices. 

My confusion arises from Upgrade Panorama Without an Internet Connection referencing the need to update the log collectors during the unit B upgrade process, which if you follow the thread would result in the log collectors being updated before unit A is upgraded. Is this an incorrect interpretation?

 

Second, if moving from version 10.2.x to 11.1.x, can I still skip PAN-OS versions on the log collectors (meaning the upgrade path would be directly 10.2.x to 11.1.x)? 

 

Lastly, what happens to logs sent to log collectors when they are in the process of upgrading? Per Upgrade Log Collectors When Panorama Is Not Internet-Connected: log collectors must be upgraded simultaneously

 

Any insight into these queries is much appreciated! 

 

Cheers,

 

Nohash4u 

 

Panorama

1 accepted solution

Accepted Solutions

Cyber Elite

- follow the process of upgrading panorama fully (both peers) before starting the collectors (there is a possibility of running the primary panorama upgraded and then upgrading the collectors before upgrading passive panorama, but why risk it)

- you can skip directly from 10.2. to 11.1

- while the log collector is unavailable, logs are queued on the firewalls until the collector is available again. unless your log volume is enormous, or the backbone between firewall and collector is already taxed (so log transfer is limited) you shouldnt lose any logs. there may be a bit of a delay in receiving 'live' logs while the firewall works through the backlog

Tom Piens
PANgurus - Strata & Prisma Access specialist

View solution in original post

2 REPLIES 2

Cyber Elite

- follow the process of upgrading panorama fully (both peers) before starting the collectors (there is a possibility of running the primary panorama upgraded and then upgrading the collectors before upgrading passive panorama, but why risk it)

- you can skip directly from 10.2. to 11.1

- while the log collector is unavailable, logs are queued on the firewalls until the collector is available again. unless your log volume is enormous, or the backbone between firewall and collector is already taxed (so log transfer is limited) you shouldnt lose any logs. there may be a bit of a delay in receiving 'live' logs while the firewall works through the backlog

Tom Piens
PANgurus - Strata & Prisma Access specialist

@reaper many thanks for the quick reply, and clarification! 

 

Cheers

  • 1 accepted solution
  • 2096 Views
  • 2 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!