- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
06-18-2025 06:35 AM
I am upgrading all my controlled firewalls using Panorama. I am able to upload, install, and reboot my passive firewalls. But now I need to switch my active/passive firewalls. Is there a way to do this in Panorama? Before I would manually login (GUI or CLI) to each active firewall and use the suspend function to force fail-over.
If there is a way to do this or something similar in Panorama, please let me know. Thank you.
06-18-2025 06:01 PM
Hello @J.Healy
thanks for posting.
To my knowledge there is no way to trigger Firewall failover directly from Panorama. I think the technical reason for this is Panorama is primarily designed for central configuration and log management and not direct real time operations.
In the past when I was doing Firewall upgrades, I had exactly the same question as you. Having Firewall failover capability directly from Panorama was feature I was missing. I eventually limited Panorama triggered upgrades only for stand alone Firewalls. HA pairs, I used to upgrade directly from Firewalls.
Kind Regards
Pavel
06-19-2025 09:44 AM
Hi @J.Healy ,
Like you I use Panorama to upgrade my NGFWs because it saves me from having to download and install on each one. I still log in to each one to suspend and make functional because I make sure the standby is in a passive state before I fail over. In the long run, it would be good for Panorama to do it all with one click.
Upgrade HA Pair button:
You could even have it make the original one active again.
It is interesting that you can suspend the NGFW with SCM.
Thanks,
Tom
06-18-2025 06:01 PM
Hello @J.Healy
thanks for posting.
To my knowledge there is no way to trigger Firewall failover directly from Panorama. I think the technical reason for this is Panorama is primarily designed for central configuration and log management and not direct real time operations.
In the past when I was doing Firewall upgrades, I had exactly the same question as you. Having Firewall failover capability directly from Panorama was feature I was missing. I eventually limited Panorama triggered upgrades only for stand alone Firewalls. HA pairs, I used to upgrade directly from Firewalls.
Kind Regards
Pavel
06-19-2025 09:44 AM
Hi @J.Healy ,
Like you I use Panorama to upgrade my NGFWs because it saves me from having to download and install on each one. I still log in to each one to suspend and make functional because I make sure the standby is in a passive state before I fail over. In the long run, it would be good for Panorama to do it all with one click.
Upgrade HA Pair button:
You could even have it make the original one active again.
It is interesting that you can suspend the NGFW with SCM.
Thanks,
Tom
06-19-2025 01:03 PM
Thank you @PavelK. I was afraid you were going to say that. 🙂
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!