Install/Upgrade SD-WAN Plugin with Compatible PAN-OS Release
Table of Contents
11.0
Expand all | Collapse all
-
-
- Upgrade Panorama with an Internet Connection
- Upgrade Panorama Without an Internet Connection
- Install Content Updates Automatically for Panorama without an Internet Connection
- Upgrade Panorama in an HA Configuration
- Migrate Panorama Logs to the New Log Format
- Upgrade Panorama for Increased Device Management Capacity
- Upgrade Panorama and Managed Devices in FIPS-CC Mode
- Downgrade from Panorama 11.0
- Troubleshoot Your Panorama Upgrade
-
- What Updates Can Panorama Push to Other Devices?
- Schedule a Content Update Using Panorama
- Panorama, Log Collector, Firewall, and WildFire Version Compatibility
- Upgrade Log Collectors When Panorama Is Internet-Connected
- Upgrade Log Collectors When Panorama Is Not Internet-Connected
- Upgrade a WildFire Cluster from Panorama with an Internet Connection
- Upgrade a WildFire Cluster from Panorama without an Internet Connection
- Upgrade Firewalls When Panorama Is Internet-Connected
- Upgrade Firewalls When Panorama Is Not Internet-Connected
- Upgrade a ZTP Firewall
- Revert Content Updates from Panorama
-
Install/Upgrade SD-WAN Plugin with Compatible PAN-OS Release
Before upgrading the SD-WAN plugin, you need to take the backup of the configuration
file, generate a technical support file, and install a compatible content release
version.
Where Can I Use This? | What Do I Need? |
---|---|
|
|
It’s imperative to ensure that an existing network infrastructure remains up to
date and is capable of upgrading its features to unlock new functionalities. The SD-WAN
upgrade guide helps the network administrators to upgrade the Panorama management server
and Palo Alto Networks firewalls that are compatible with the SD-WAN plugin release.
It is important that you have a proper upgrade or downgrade plan before starting actual
upgrade or downgrade procedure. Refer the valid upgrade and downgrade paths for your currently installed SD-WAN
plugin version.
Before proceeding with the upgrade process, ensure the following:
- Take a backup of all the configurations on each device.
- Refer Panorama Plugin Compatibility Matrix to review the features introduced in each version of the Panorama plugin for SD-WAN.
- You have administrator access to the Palo Alto Networks devices.
Prerequisites
Before you upgrade the Panorama HA pair, it's important to save the configuration
files, create a technical support file, and check for the compatible content release
version for your device.
Back up Your Configuration File
Make a backup of the current configuration file. It's recommended to make a
backup of your current Panorama and firewall configurations:
- Take the backup of the Panorama and firewall configurations before upgrading the device.
- Save and export Panorama and firewall configurations to restore that backup.
- Save and export firewall configurations to revert to that backup.
If you have problems with the upgrade, you can use these backups to
restore the configuration by loading the configuration backup on the
firewall managed by the Panorama management server.
Generate a Technical Support File
It's important to generate the technical support file for debugging purposes.
- Select DeviceSupport and Generate Tech Support File. The technical support file must be generated on both the HA pair for debugging purposes.It may take a few minutes to generate a technical support file and the time taken to generate would vary.
- Click Yes when prompted to generate the tech support file.
- Click Download Tech Support File to save it in the firewall or Panorama.
Install Compatible Content Release Version
Ensure that each firewall and Panorama HA pair is running the latest content
release (Applications and Threats) version.
All the firewalls and the Panorama must have the same
version of Applications and Threats downloaded and
installed for the upgrade to be successful.
Refer to the corresponding Release Notes for the minimum content
release (such as, Applications and Threats) version you
must install for a corresponding PAN-OS release. Make sure to follow the best practices for applications and threat
content updates.
Your firewall and the Panorama running a specific PAN-OS version must contain the
minimum content release (Applications and Threats)
version that’s compatible with the PAN-OS version.
Use the following workflow to download and install the content release version
that’s compatible with the PAN-OS version:
- For the firewall, select DeviceDynamic Updates and for Panorama select PanoramaDynamic Updates to check the version information of the Applications and Threats.
- Check Now to retrieve a list of available updates.
- Locate and Download the appropriate content release version. After you successfully download a content update file, the link in the Action column changes from Download to Install for that content release version.
- Install the update on the Palo Alto Networks devices.
Important Considerations for Upgrading Panorama
The following are the important considerations for upgrading the SD-WAN plugin
version on your Panorama management server:
- (HA Deployments only) Both the active and passive Panorama must have the same Panorama software and SD-WAN plugin versions.
- (HA Deployments only) Maintain the same HA states for both Panorama and Palo Alto Networks Next-Generation Firewalls after upgrade and before commit or commit all, so that the configuration changes are minimal.
- Always ensure that the Panorama software version is higher than the PAN-OS version.
- For MongoDB synchronization status for an SD-WAN plugin version, refer to MongoDB Synchronization Status with SD-WAN Database Collections.
- (HA Deployments only) You must upgrade both active and passive Panorama HA pairs simultaneously.
- After completing the SD-WAN plugin upgrade, you must perform a commit force through the CLI command (in configuration mode) on the Palo Alto Networks device. If you perform commit all instead of commit force, then you will lose all the SD-WAN configurations on that device.
After the upgrade is complete, note the changes after the
upgrade.