I explain my scenario:
We need a cluster A/P in 8.0.x. We had issues upgrading when the LACP didnt come up in the passive node jumping to 8.1.10.
So in the last try we realised that jumping to base 8.1.0 the LACP interfaces were up. So we will do this upgrade path:
Customer has UIA 8.1.6 version
My questions are:
-What would you do with Panorama and UserId agent. Can we upgrade them before FWs. Is working Panorama and UIA in 9.0, and FWs in 8.0.x?
-How do you organize this in order to upgrade all platfom?
always upgrade panorama first, else you lose managagement until the firewalls are up-to-date
then do the userID agents, lastly do the firewalls
if you do them in lockstep (a-b-a-b-a-b) your upgrade path should go smoothly
you don't need to install 9.0.0 (you do need to download it), you can directly go to 9.0.9-h1 (unless you have a older platform)
Your Panorama should be the same version (or higher) of your FWs, so you Panorama should be 9.0.10.
As for your FWs. I would strongly recommend (confirm) that you require the 9.0.9HF-1... does it solve your issue.
Else, if you are not certain, then I would recommend that you keep your FWs at 9.0.10 as well.
I would NOT recommend keeping FWs at 8.0 level, per PANW recommendations.
The 8.0.x has gone end of life, as of about 1 year ago (Oct 2019)
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!