Upgrading the VM-Series firewall allows you to increase the capacity on the
firewall. Capacity is defined in terms of the number of sessions, rules,
security zones, address objects, IPSec VPN tunnels, and SSL VPN tunnels that the
VM-Series firewall is optimized to handle. When you apply a new capacity license
on the VM-Series firewall, the model number and the associated capacities are
implemented on the firewall.
Verify the
VM-Series System Requirements for
your firewall model before you upgrade. If your firewall has less than 5.5GB
memory, the capacity (number of sessions, rules, security zones, address
objects, etc) on the firewall will be limited to that of the VM-50 Lite.
This process is similar to that of upgrading a pair of hardware-based firewalls
that are in an HA configuration. During the capacity upgrade process, session
synchronization continues, if you have it enabled. To avoid downtime when
upgrading firewalls that are in a high availability (HA) configuration, update
one HA peer at a time.
Don't make configuration changes to the firewalls during the upgrade process.
During the upgrade process, configuration sync is automatically disabled
when a capacity mismatch is detected and is then reenabled when both HA
peers have matching capacity licenses.
If the firewalls in the HA pair have different major software versions (such
as 9.1 and 9.0) and different capacities, both devices will enter the
Suspended HA state. Therefore, it's recommended that you make sure both
firewalls are running the same version of PAN-OS before upgrading
capacity.