Enhanced Security Measures in Place:   To ensure a safer experience, we’ve implemented additional, temporary security measures for all users.

PA5220 to Version 10.25

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

PA5220 to Version 10.25

L2 Linker

Good Day to All,

 

I have a Firewall PA 5220 running on A/A setup. 

 

Initially it is running on 8.1.4 version and just recently we have upgraded to 9.1.16 version.

 

Since 9.1.16 version will be EOS by Dec 13, 2023 we plan to upgrade it to 10.2 version.

 

Questions:

1. Is PA5220 capable of being upgraded to 10.2.5* preferred version?

2. What would be the version hops we need to take before we can have and end version of 10.2.5?

3. Is it possible to Upgrade the Active-Secondary up to 10.2.5 version first then after which Active-Primary to 10.2.5? <-- For this since our last upgrade to the 9.1.16 we tried to upgrade Active-Secondary to 9.1.16 but encountered "Mismatch/Unknown" on the application threats widget.

4. Or is it advisable to upgrade each firewall one hop at a time?

 

regards

Nicko

 

1 accepted solution

Accepted Solutions

Cyber Elite
Cyber Elite

Hi @NickoKristian ,

 

Here are your answers:

 

  1. Yes.  https://docs.paloaltonetworks.com/compatibility-matrix/supported-os-releases-by-model/palo-alto-netw...
  2. Follow the upgrade path from 9.1 to 10.2 here -> https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-upgrade/upgrade-pan-os/upgrade-the-firewall-pan....
  3. No.  Each NGFW must be upgraded to the next version one after the other -> https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-upgrade/upgrade-pan-os/upgrade-the-firewall-pan....  The NGFWs will remain an HA pair with one PAN-OS major release difference.  Two major releases different will cause the older NGFW to enter a suspended state.
  4. Yes.  Also, do not worry about any mismatches or config not synced errors when the PAN-OS is different.  Upgrading the other NGFW to the same PAN-OS usually fixes those errors.  Obviously, make sure the config is synced before you begin.

Thanks,

 

Tom

Help the community: Like helpful comments and mark solutions.

View solution in original post

1 REPLY 1

Cyber Elite
Cyber Elite

Hi @NickoKristian ,

 

Here are your answers:

 

  1. Yes.  https://docs.paloaltonetworks.com/compatibility-matrix/supported-os-releases-by-model/palo-alto-netw...
  2. Follow the upgrade path from 9.1 to 10.2 here -> https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-upgrade/upgrade-pan-os/upgrade-the-firewall-pan....
  3. No.  Each NGFW must be upgraded to the next version one after the other -> https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-upgrade/upgrade-pan-os/upgrade-the-firewall-pan....  The NGFWs will remain an HA pair with one PAN-OS major release difference.  Two major releases different will cause the older NGFW to enter a suspended state.
  4. Yes.  Also, do not worry about any mismatches or config not synced errors when the PAN-OS is different.  Upgrading the other NGFW to the same PAN-OS usually fixes those errors.  Obviously, make sure the config is synced before you begin.

Thanks,

 

Tom

Help the community: Like helpful comments and mark solutions.
  • 1 accepted solution
  • 1106 Views
  • 1 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!