- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
02-12-2025 02:52 AM
so 1 reboot 🙂
(starting from 10.1 you can skip up to 3 major versions, so you don't need to install 11.0)
02-12-2025 03:53 AM - edited 02-12-2025 03:55 AM
Hello @watkfr
As @reaper mnetioned you can skip up to 3 version when you upgrade a individual firewall.
"When upgrading HA firewalls across multiple feature PAN-OS releases, you must upgrade each HA peer to the same feature PAN-OS release on your upgrade path before continuing. For example, you are upgrading HA peers from PAN-OS 10.2 to PAN-OS 11.1. You must upgrade both HA peers to PAN-OS 11.0 before you can continue upgrading to the target PAN-OS 11.1 release. When HA peers are two or more feature releases apart, the firewall with the older release installed enters a suspended state with the message Peer version too old. "
So, according with the above statement from TECH DOCS, you will need first to upgrade both HA peers to 11.0.x and after that to 11.1.x.
If the firewall with older release enters to suspend state before the other peer to be fully functional, then you will have service interruption.
Even PAN-OS 11.0 it's end of support, you still need to use it as transitional state.
1. download 11.0.0
2. download 11.0.4-h6 (the latest preferred release from 11.0) + install
3. reboot the first firewall
4. repeat steps 1-2 for second firewall and reboot second firewall
4. download 11.1.0
5. download 11.1.4-h7 (the latest preferred release from 11.1) + install
6. second reboot for first firewall
7. repeat steps 5-6 for second firewall
8. second reboot for the second firewall
Each HA peer will have 2 reboots.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!