Query on HA pair upgrade

Showing results for 
Show  only  | Search instead for 
Did you mean: 

Query on HA pair upgrade

L4 Transporter



We are using PAN-OS 7.0.2 which is end of life and wanting to upgrade to 7.1.17.
Can we upgrade one firewall through all the versions 7.0.2-->7.0.19-->7.1.0-->7.1.17 before moving on to another in the pair or do we have to bring both firewalls in pair on same version before making a move onto the next version in line?



Thanks in advance!


Cyber Elite
Cyber Elite

hi @Farzana


yes, you can bring the first fiirewall up to the final version before you start work on the second

Tom Piens
PANgurus - SASE and Strata specialist; (co)managed services, VAR and consultancy

L7 Applicator


As long as you only upgrade to the next major version I would recommend it the way you describe.

For example if you planned to go from 7.0.2 up to 8.0.10, then you should upgrade both firewalls to 7.1.x before you do the next step to 8.0.x.



Thank you both. 

After upgrading the Primary firewall and make it functional again, will it not prompt about the mismatch of the IOS version on the peers in HA. Will The HA work? Will it allow me to suspend the secondary from the HA pair  so that primary which will run on new version can take over?




Yes, the firewalls will show a PAN-OS mismatch but the firewallcluster (including session sync and so on) wil work perfectly fine.

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!