Enhanced Security Measures in Place:   To ensure a safer experience, we’ve implemented additional, temporary security measures for all users.

PANos version on Panorama vs the PANos version on a firewall

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

PANos version on Panorama vs the PANos version on a firewall

L2 Linker

Good Day,

 

I would like to know if I am running PANos 7.0.11 on a Palo Alto firewall what version software should Panorama be running?

3 accepted solutions

Accepted Solutions

Community Team Member

Hi @Lance,

 

Some examples to clarify :

 

Panorama 7.0 can manage Firewall PANOS 6.0.3+ or 6.1 or 7.0

Panorama 7.1can manage Firewall PANOS 6.1.3+ or 7.0 or 7.1

 

Panorama can manage firewalls running PAN-OS versions that match the Panorama version or are earlier than the Panorama version. The exception is that Panorama 6.1 and later versions cannot push configurations to firewalls running PAN-OS 6.0.0 through 6.0.3. Panorama cannot manage firewalls that run a later PAN-OS version than the Panorama version. For example, Panorama 6.0 cannot manage firewalls running PAN-OS 7.0. For versions within the same feature release, although Panorama can manage firewalls running a later version of PAN-OS, we recommend that Panorama run the same version or a later version. For example, if Panorama runs 7.0.3, it is recommended that all managed firewalls run PAN-OS 7.0.3 or earlier versions.

 

Full details here :

https://www.paloaltonetworks.com/documentation/71/panorama/panorama_adminguide/panorama-overview/pla...

 

Cheers !

-Kim.

LIVEcommunity team member, CISSP
Cheers,
Kiwi
Please help out other users and “Accept as Solution” if a post helps solve your problem !

Read more about how and why to accept solutions.

View solution in original post

L3 Networker

Lance,

 

We managed 7.0.X PAN OS for a while with Panorama 7.1.X without major problems.  There are some feature changes between the two so our Panorama pushes did not always equate to the same thing on the firewalls.

In the future we will be keeping Panorama on the same major revision as the firewalls with the exception of testing a major release before we push it to the production firewalls.

You will want to run the same minor release or newer on Panorama.

 

Brian

View solution in original post

Same here... currently I have 7.1.8 on my Panorama and my four firewalls have 7.0.14. No issues.

-Brad

View solution in original post

3 REPLIES 3

Community Team Member

Hi @Lance,

 

Some examples to clarify :

 

Panorama 7.0 can manage Firewall PANOS 6.0.3+ or 6.1 or 7.0

Panorama 7.1can manage Firewall PANOS 6.1.3+ or 7.0 or 7.1

 

Panorama can manage firewalls running PAN-OS versions that match the Panorama version or are earlier than the Panorama version. The exception is that Panorama 6.1 and later versions cannot push configurations to firewalls running PAN-OS 6.0.0 through 6.0.3. Panorama cannot manage firewalls that run a later PAN-OS version than the Panorama version. For example, Panorama 6.0 cannot manage firewalls running PAN-OS 7.0. For versions within the same feature release, although Panorama can manage firewalls running a later version of PAN-OS, we recommend that Panorama run the same version or a later version. For example, if Panorama runs 7.0.3, it is recommended that all managed firewalls run PAN-OS 7.0.3 or earlier versions.

 

Full details here :

https://www.paloaltonetworks.com/documentation/71/panorama/panorama_adminguide/panorama-overview/pla...

 

Cheers !

-Kim.

LIVEcommunity team member, CISSP
Cheers,
Kiwi
Please help out other users and “Accept as Solution” if a post helps solve your problem !

Read more about how and why to accept solutions.

L3 Networker

Lance,

 

We managed 7.0.X PAN OS for a while with Panorama 7.1.X without major problems.  There are some feature changes between the two so our Panorama pushes did not always equate to the same thing on the firewalls.

In the future we will be keeping Panorama on the same major revision as the firewalls with the exception of testing a major release before we push it to the production firewalls.

You will want to run the same minor release or newer on Panorama.

 

Brian

Same here... currently I have 7.1.8 on my Panorama and my four firewalls have 7.0.14. No issues.

-Brad
  • 3 accepted solutions
  • 17863 Views
  • 3 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!