🔥 Join our exclusive online training: "Mastering Palo Alto Firewalls: Comprehensive Training in Operation and Management." 🚀 Prepare confidently for the PCNSA exam with expert guidance and hands-on exercises. Reserve your spot now and benefit from Early Bird discounts and bonusses! 💻 Learn more and register at netsums.com/training
Question Richaro, I have version 10.1.6-h8, can I update to version 11.1.5-h1 or I have to update with in-line version like 10.1.6-h9 for example? Per security bulletin (CVE-2024-9474), they recommened PA440 to be on version 10.1.14-h6 or later. Some says that 11.1.5-h1 may not be compatibled or support on PA440 and PA220 or it's better to wait for 10.1.6-h9 to release.
Hi. You can go directly to 11.1., no problem. I have PA-440 running 11.2, I have no problem with it. The PA-220 became very slow from version 9 to 10 to administer (commits take forever). I would keep that in mind before going to 11.1.
In order to export the current configuration, you need to go to Device -> Setup -> Operations and Export Named Configuration Snapshot. Tô export the support file, go to Device -> Support and generate the file first, than download it.
Hi Keramet, the validation process seems to be only relevant to VM running on cloud services. For this tutorial I started a Palo Alto VM on Azure. I don't see the validate option on hardware-based firewalls, so if you don't work with PA-VM, you don't need to worry about the validation process.
🔥 Join our exclusive online training: "Mastering Palo Alto Firewalls: Comprehensive Training in Operation and Management." 🚀 Prepare confidently for the PCNSA exam with expert guidance and hands-on exercises. Reserve your spot now and benefit from Early Bird discounts and bonusses! 💻 Learn more and register at netsums.com/training
I have had the right address when I meet you here. Many thanks
You're welcome, thank you also for the comment!
In pre-check once you download the software, you are also supposed to check/perform dynamic updates to the latest. Then go for install the software
Question Richaro, I have version 10.1.6-h8, can I update to version 11.1.5-h1 or I have to update with in-line version like 10.1.6-h9 for example? Per security bulletin (CVE-2024-9474), they recommened PA440 to be on version 10.1.14-h6 or later. Some says that 11.1.5-h1 may not be compatibled or support on PA440 and PA220 or it's better to wait for 10.1.6-h9 to release.
Hi. You can go directly to 11.1., no problem. I have PA-440 running 11.2, I have no problem with it. The PA-220 became very slow from version 9 to 10 to administer (commits take forever). I would keep that in mind before going to 11.1.
Do you need a support account to do this?
Hi. Yes, you won't get updates without a valid license.
Hi how to take backup and bundle device before upgrade
In order to export the current configuration, you need to go to Device -> Setup -> Operations and Export Named Configuration Snapshot. Tô export the support file, go to Device -> Support and generate the file first, than download it.
@@netsums thankyou
No worries. :-)
What is validate ? I dont understand
Hi Keramet, the validation process seems to be only relevant to VM running on cloud services. For this tutorial I started a Palo Alto VM on Azure. I don't see the validate option on hardware-based firewalls, so if you don't work with PA-VM, you don't need to worry about the validation process.