Upgrading PanOS from 9.1 to target version 10

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

Upgrading PanOS from 9.1 to target version 10

L3 Networker

Hello Bros'

               currently we are in the PanOS version 9.1.x and according to this link https://www.paloaltonetworks.com/services/support/end-of-life-announcements/end-of-life-summary this version will be EOL by 12/2023.

from this I can understand that the all version of 9.1 will be EOL, means I will have to move to the PanOS version 10.

If my above was correct, what is the current PanOS 10 target version, knowing that we have been so avoiding version 10 and it's AI capability because of bad history with our collaboration services that suffered alot of issues when we have tried to upgrade to PanOS10.

our collaboration services and call center from CIsco, so Any one had a similar environment with stable PanOS 10 installed.

any Ideas will be wilcommed.

TIA

MR
1 accepted solution

Accepted Solutions

Cyber Elite
Cyber Elite

You must go through 10.0 but don't stay there because 10.0 is end of life already.

Raido_Rattameister_0-1680452083941.png

 

You can go either to 10.1 or 10.2

 

Check release notes for both and "what's new" section to decide.

https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-release-notes

 

By the time you perform upgrade TAC suggested preferred release might have been changed. This is current state today.

 

Raido_Rattameister_1-1680452125662.png

 

 

I would not recommend to go below 10.2.4 as there are quite a few bugs fixed in this release (reports, userid etc) so you might want to wait until 10.2.4 becomes preferred before upgrade.

 

Raido_Rattameister_2-1680452158438.png

 

I have 10.1, 10.2 and 11 all working fine with CUCM. What issues did you encounter?

Enterprise Architect, Security @ Cloud Carib Ltd
Palo Alto Networks certified from 2011

View solution in original post

9 REPLIES 9

Cyber Elite
Cyber Elite

You must go through 10.0 but don't stay there because 10.0 is end of life already.

Raido_Rattameister_0-1680452083941.png

 

You can go either to 10.1 or 10.2

 

Check release notes for both and "what's new" section to decide.

https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-release-notes

 

By the time you perform upgrade TAC suggested preferred release might have been changed. This is current state today.

 

Raido_Rattameister_1-1680452125662.png

 

 

I would not recommend to go below 10.2.4 as there are quite a few bugs fixed in this release (reports, userid etc) so you might want to wait until 10.2.4 becomes preferred before upgrade.

 

Raido_Rattameister_2-1680452158438.png

 

I have 10.1, 10.2 and 11 all working fine with CUCM. What issues did you encounter?

Enterprise Architect, Security @ Cloud Carib Ltd
Palo Alto Networks certified from 2011

Hello @Raido_Rattameister  

                     Thank you so much for the detailed answer, I will contact the TAC for the upgrade and will attach your response.

Regarding the issues met, It was a for no reasons ip phone re-registering from time to another, and a similar issues for the Cisco Finesse call center CCX agents.

MR

L4 Transporter

I had a good experience with 9.1. However we've found all of the 10.1.x versions to be slow in terms of log viewing and reporting. Is 10.2 or 11 more spritely?

From ny side, i don't know I hope i get an answer to this too.

Way or another we are going to upgrade as the 9.1 will go EOL by end of 2023

MR

There seems to be very little comment in this forum regarding the pros and cons of each version.

Hi @Raido_Rattameister ,

 

I have some question to ask. I want to upgrade PanOS from 9.1.14-h4 to 10.1.16-h6. 

 

So the upgrade path will be like this right?

1) Upgrade to the latest preferred release for PanOS 9.1 which is 9.1.16 (download and install)

2) Download 10.0 (do not install)

3) Upgrade to 10.0 latest preferred release (download and install). 

4) Then proceed to upgrade to 10.1.16-h6 

 

is it correct? 

 

Another question is, what do you mean by "You must go through 10.0 but don't stay there because 10.0 is end of life already" ? Do you means we just have to download the version and do not install then just proceed to upgrade to 10.1.16? or we need to upgrade to 10.1 first? 

 

I refer to this below document:

Determine the Upgrade Path to PAN-OS 10.1 (paloaltonetworks.com)

 

Appreciate if you can help me to answer this. Thank you !

 

Regard,

Nurul

Yes upgrade path is correct.

By "You must go through 10.0 but don't stay there because 10.0 is end of life already" I mean that you can't go from 9.1.x to 10.1.x

You need to download and install 10.0.x in between but as initial post mentioned about going to version 10 I added this note that don't stay on 10 go to 10.1 or higher.

Enterprise Architect, Security @ Cloud Carib Ltd
Palo Alto Networks certified from 2011

Thats means, in my case, I still need to download and install the 10.0.X version prior to download 10.1? Or from latest preferred 9.1.X just go to 10.1? 

Apart form that, I have another question to ask. 

What does mean by "Download and install the latest preferred PAN-OS 9.1 maintenance release and reboot." ? For HA, do we need to suspend like we upgrade ?

NurulAfiqah_0-1686786681986.png

 

  • 1 accepted solution
  • 2294 Views
  • 9 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!