Downgrading from PANOS-9.1.0-h3 to 9.0.4 -- access fails, logon

Reply
Highlighted
L2 Linker

Downgrading from PANOS-9.1.0-h3 to 9.0.4 -- access fails, logon

After Downgrading from PANOS-9.1.0-h3 to PANOS 9.0, in Azure, VM100 fails to accept logon. I've tried twice. Once to base 9.0 and another to 9.0.4 with base downloaded. Is this downgrade path not supported?

D. Elliott

Accepted Solutions
Highlighted
L4 Transporter

Re: Downgrading from PANOS-9.1.0-h3 to 9.0.4 -- access fails, logon

BTW...9.0.4 is available in Azure for direct install.  It might be cleaner to install 9.0.4 directly and restore your config.

View solution in original post


All Replies
Highlighted
L3 Networker

Re: Downgrading from PANOS-9.1.0-h3 to 9.0.4 -- access fails, logon

Hello @doug-elliott 

We did a downgrade from 9.1.x (don't know the exact details) to 9.0.6 (in Azure). Not sure if this can be compared to your situation, since the 9.1 was not configured at all (besides the mgn interface and the local admin user). Keep in mind that the default user (admin) might not be configured. In the deployment task we provided a different user name.

Highlighted
L1 Bithead

Re: Downgrading from PANOS-9.1.0-h3 to 9.0.4 -- access fails, logon

I ran into the same issue when I tried 9.1 down to 9.0.4.  What did work was 9.1 down to 9.0.6 then down to 9.0.4.  Not sure exactly why a straight shot down to 9.0.4 isn't working, but adding an intermediate step to 9.0.6 does.

 

 

Highlighted
L4 Transporter

Re: Downgrading from PANOS-9.1.0-h3 to 9.0.4 -- access fails, logon

BTW...9.0.4 is available in Azure for direct install.  It might be cleaner to install 9.0.4 directly and restore your config.

View solution in original post

L2 Linker

Re: Downgrading from PANOS-9.1.0-h3 to 9.0.4 -- access fails, logon

Thanks for the solution, I found this to be the way to go.  As a follow up to the other replies, I made another attempt to downgrade to 9.0.4 with another firewall (the HA partner) by downloading the base and attempting to install 9.0.4.  Same result.  9.1.0-h3 was installed as part of a solution template I used from Github.  For the replacement firewall, decided to deploy a single firewall at PANOS 9.0.4 and avoid the downgrade.  Much better idea so be careful with solution templates and what they deploy. 

 

Thanks for your responses.

D. Elliott
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!

The Live Community thanks you for your participation!