- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
11-05-2023 10:56 PM
Hi All,
Our current setup is We have Active/Passive on main dc and standalone fw on DR site. Configured as Cluster.
It is identified that the DR site is affected by a certain CVE, and it is recommended for upgrade. But we also wish to upgrade the Active/Passive Main DC firewall.
I cannot find any articles on how to upgrade an Firewall Cluster, Can you share any tips on what approach upgrade for this setup?
Would there be no effect bearing if for example the Active/Passive Firewall is running on 10.1.0 then the DR Stand alone site is running on 10.1.0 version?
Thanks
11-06-2023 05:29 AM
Upgrade passive, reboot passive.
Upgrade active, reboot active.
What is your current version and what is goal version?
11-06-2023 05:39 AM - edited 11-06-2023 05:40 AM
are your DC and DR clustered (via HA4)? If yes, all members of the cluster should be on the same PAN-OS. If the DR is simply a copy (managed by Panorama or not doesn't really matter), it won't matter if the DR is upgraded way ahead of the normal DC
to upgrade the HA cluster, i'd recommend the following:
- disable preempt
- suspend the primary firewall (this triggers a failover to the secondary, this is a good 'double check' to see if your secondary is passing traffic as expected. if this part fails, troubleshoot connectivity on the secondary before going forward with the upgrade)
- install your desired PAN-OS on the primary
- make primary active again and suspend secondary
- check if everything's still working as expected
- upgrade secondary
- enable preempt again if you had it enabled
if the 'distance' between current and future PAN-OS is too great, you'll have to repeat this process a few times i.e. coming from 9.1 to 10.1 you'll have to do a layover on 10.0 for both peers before moving on to 10.1.
https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-upgrade <- the upgrade guide
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!