@AhmedMoustafa When we are upgrading the OS on a HA pair, f or active/passive firewalls, must upgrade the passive peer first, suspend the active peer (fail over), update the active peer, and then return that peer to a functional state (fail back). To prevent fail over during the upgrade of the HA peers, must make sure preemption is disabled before proceeding with the upgrade. We only need to disable preemption on one peer in the pair. You can check the upgrade steps in the link below. https://docs.paloaltonetworks.com/pan-os/9-0/pan-os-new-features/upgrade-to-pan-os-90/upgrade-the-firewall-to-pan-os-90/upgrade-an-ha-firewall-pair-to-pan-os-90.html
... View more