- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
06-04-2026 01:58 PM
Does any successfully perform their HA firewall upgrades in this manner?
1. Upgrade the Seconday(passive) firewall.
2. Make Secondary firewall Active.
3. Wait 1 or more days.
4. Upgrade the Primary(now passive) firewall.
5. Make the Primary firewall active.
It would bring us a lot more comfort knowing that we can easily switch to a different firewall (on the older version) in the event of an issue caused by the upgrade. Will HA syncs still work(sessions, configs, etc) This could be for minor or major versions.
06-10-2026 01:47 PM
Hi @jambulo ,
Yes, I have upgraded an HA pair in that order, except I did not wait 1 or more days. The HA pair will remain in an active/passive state as long as the PAN-OS version is <= one major version away. "When HA peers are two or more feature releases apart, the firewall with the older release installed enters a suspended state with the message Peer version too old." https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-upgrade/upgrade-pan-os/upgrade-the-firewall-pan...
Once you upgrade 1 NGFW, expect the Running Configuration and the PAN-OS Version status to turn red in the High Availability widget on the dashboard. This is normal as the new version may modify the running configuration. Do not sync the config. Most of the time when you upgrade the 2nd NGFW, the running config will show synced again. Everything else in the widget should show green except the passive NGFW will show yellow.
So, in summary your process will work but I would not make changes on the NGFW during the mismatch because the config sync probably will not work.
Thanks,
Tom
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!

