- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
08-30-2018 07:48 PM
Hello,
Thanks in advance!
08-31-2018 02:05 AM
hi @Farzana
yes, you can bring the first fiirewall up to the final version before you start work on the second
09-01-2018 06:58 AM
As long as you only upgrade to the next major version I would recommend it the way you describe.
For example if you planned to go from 7.0.2 up to 8.0.10, then you should upgrade both firewalls to 7.1.x before you do the next step to 8.0.x.
09-03-2018 04:16 PM
Thank you both.
After upgrading the Primary firewall and make it functional again, will it not prompt about the mismatch of the IOS version on the peers in HA. Will The HA work? Will it allow me to suspend the secondary from the HA pair so that primary which will run on new version can take over?
09-03-2018 05:55 PM
Yes, the firewalls will show a PAN-OS mismatch but the firewallcluster (including session sync and so on) wil work perfectly fine.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!