Palo Alto Cluster Upgrade

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

Palo Alto Cluster Upgrade

L1 Bithead

Hi All,

 

Our current setup is We have Active/Passive on main dc and standalone fw on DR site. Configured as Cluster.

 

It is identified that the DR site is affected by a certain CVE, and it is recommended for upgrade. But we also wish to upgrade the Active/Passive Main DC firewall.

 

I cannot find any articles on how to upgrade an Firewall Cluster, Can you share any tips on what approach upgrade for this setup?

 

Would there be no effect bearing if for example the Active/Passive Firewall is running on 10.1.0 then the DR Stand alone site is running on 10.1.0 version?

 

Thanks

2 REPLIES 2

Cyber Elite
Cyber Elite

Upgrade passive, reboot passive.

Upgrade active, reboot active.

 

What is your current version and what is goal version?

Enterprise Architect, Security @ Cloud Carib Ltd
Palo Alto Networks certified from 2011

Cyber Elite
Cyber Elite

are your DC and DR clustered (via HA4)? If yes, all members of the cluster should be on the same PAN-OS. If the DR is simply a copy (managed by Panorama or not doesn't really matter), it won't matter if the DR is upgraded way ahead of the normal DC

 

to upgrade the HA cluster, i'd recommend the following:

 

- disable preempt

- suspend the primary firewall (this triggers a failover to the secondary, this is a good 'double check' to see if your secondary is passing traffic as expected. if this part fails, troubleshoot connectivity on the secondary before going forward with the upgrade)

- install your desired PAN-OS on the primary

- make primary active again and suspend secondary

- check if everything's still working as expected

- upgrade secondary

- enable preempt again if you had it enabled

 

if the 'distance' between current and future PAN-OS is too great, you'll have to repeat this process a few times i.e. coming from 9.1 to 10.1 you'll have to do a layover on 10.0 for both peers before moving on to 10.1. 

 

https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-upgrade <- the upgrade guide

Tom Piens
PANgurus - Strata specialist; config reviews, policy optimization
  • 439 Views
  • 2 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!