Upgrade path 5020 from OS 6.0.7 to 8.08 what steps need to be taken?

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

Upgrade path 5020 from OS 6.0.7 to 8.08 what steps need to be taken?

L0 Member

So I have a 5020 that is on OS 6.07 and would like to bring it up to the current 8.0.8 OS. What incremental OS's do I need?

 

Thank you

3 REPLIES 3

Cyber Elite
Cyber Elite

@svusdrsena

Per the new installation guide, you'll need to do a lot of steps to get to 8.0.8. Your upgrade path would be this:

6.0.7 > 6.0.15

6.0.15 > 6.1.0

6.1.0 > 6.1.19

6.1.19 > 7.0.1

7.0.1 > 7.0.19

7.0.19 > 7.1.0

7.1.0 > 7.1.15

7.1.15 > 8.0.0

8.0.0 > 8.0.8

 

 

 

@BPry you actually don't have to run the base images, just download them. Because of that, @svusdrsena can follow a shorter path to upgrade from 6.0.7 to 8.0.8:

 

6.1.0 (download only)

6.1.19 (download and install, reboot to this version)

 

7.0.1 (download only)

7.0.19 (download and install, reboot to this version)

 

7.1.0 (download only)

7.1.15 (download and install, reboot to this version)

 

8.0.0 (download only)

8.0.8 (download and install, final reboot).

 

Edit: Make sure that rules are updated on the firewall to reflect the change in Application-Default as a service type as detailed here:

https://live.paloaltonetworks.com/t5/Configuration-Articles/PAN-OS-7-1-Policy-behavior-change-applic...

 

Edit 2: I sit corrected. @BPry is absolutely correct here, the recommendation is indeed to upgrade and install each of the versions. Here's one copy of that directive for reference (about halfway down):

https://www.paloaltonetworks.com/documentation/80/pan-os/newfeaturesguide/upgrade-to-pan-os-80/upgra...

@gwesson,

This has actually recently changed and why I recommend the update as I did. While @svusdrsena would likely be fine following the old recommended path, esspecially on the 5020 platform, it is no longer recommended to only download the base image. 

The new recommended upgrade path is to download and install the base image before installing the latest maintenance release so that the firewall does not need to explode both the base image and the maintenance image to build an install package. This recommendation was announced in late July of last year. 

  • 2337 Views
  • 3 replies
  • 1 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!