: Upgrade the VM-Series for NSX During a Maintenance Window
Focus
Focus

Upgrade the VM-Series for NSX During a Maintenance Window

Table of Contents

Upgrade the VM-Series for NSX During a Maintenance Window

Use Panorama to upgrade the VM-Series firewall NSX edition during a maintenance window.
For the VM-Series Firewall NSX edition, use Panorama to upgrade the software version on the firewalls.
  1. Review the VM-Series for VMware NSX upgrade paths.
  2. Allocate additional hardware resources to your VM-Series firewall.
    Verify that enough hardware resources are available to the VM-Series firewall. Refer to the VM-Series System Requirements to see the new resource requirements for each VM-Series model. Allocate additional hardware resources before continuing the upgrade process. The process for assigning additional hardware resources differs on each hypervisor.
  3. Save a backup of the current configuration file on each managed firewall that you plan to upgrade.
    Although the firewall will automatically create a backup of the configuration, it is a best practice to create a backup prior to upgrade and store it externally.
    1. Select DeviceSetupOperations and click Export Panorama and devices config bundle. This option is used to manually generate and export the latest version of the configuration backup of Panorama and of each managed device.
    2. Save the exported file to a location external to the firewall. You can use this backup to restore the configuration if you have problems with the upgrade.
  4. Check the Release Notes to verify the Content Release version required for the PAN-OS version.
    The firewalls you plan to upgrade must be running the Content Release version required for the PAN-OS version.
    1. Select PanoramaDevice DeploymentDynamic Updates.
    2. Check for the latest updates. Click Check Now (located in the lower left-hand corner of the window) to check for the latest updates. The link in the Action column indicates whether an update is available. If a version is available, the Download link displays.
    3. Click Download to download a selected version. After successful download, the link in the Action column changes from Download to Install.
    4. Click Install and select the devices on which you want to install the update. When the installation completes, a check mark displays in the Currently Installed column.
  5. Deploy software updates to selected firewalls.
    If your firewalls are configured in HA, make sure to clear the Group HA Peers check box and upgrade one HA peer at a time.
    1. Select PanoramaDevice DeploymentSoftware.
    2. Check for the latest updates. Click Check Now (located in the lower left-hand corner of the window) to check for the latest updates. The link in the Action column indicates whether an update is available.
      (PAN-OS 11.0.5 and later 11.0 releases) By default, the preferred releases and the corresponding base releases are displayed. To view the preferred releases only, disable (clear) the Base Releases checkbox. Similarly, to view the base releases only, disable (clear) the Preferred Releases checkbox.
    3. Review the File Name and click Download. Verify that the software versions that you download match the firewall models deployed on your network. After successful download, the link in the Action column changes from Download to Install.
    4. Click Install and select the devices on which you want to install the software version.
    5. Select Reboot device after install, and click OK.
    6. If you have devices configured in HA, clear the Group HA Peers check box and upgrade one HA peer at a time.
  6. Verify the software and Content Release version running on each managed device.
    1. Select PanoramaManaged Devices.
    2. Locate the device(s) and review the content and software versions on the table.