Upgrade a ZTP Firewall
Table of Contents
10.1
Expand all | Collapse all
-
-
- Upgrade Panorama with an Internet Connection
- Upgrade Panorama Without an Internet Connection
- Install Content Updates Automatically for Panorama without an Internet Connection
- Upgrade Panorama in an HA Configuration
- Migrate Panorama Logs to the New Log Format
- Upgrade Panorama for Increased Device Management Capacity
- Downgrade from Panorama 10.1
- Troubleshoot Your Panorama Upgrade
-
- What Updates Can Panorama Push to Other Devices?
- Schedule a Content Update Using Panorama
- Panorama, Log Collector, Firewall, and WildFire Version Compatibility
- Upgrade Log Collectors When Panorama Is Internet-Connected
- Upgrade Log Collectors When Panorama Is Not Internet-Connected
- Upgrade a WildFire Cluster from Panorama with an Internet Connection
- Upgrade a WildFire Cluster from Panorama without an Internet Connection
- Upgrade Firewalls When Panorama Is Internet-Connected
- Upgrade Firewalls When Panorama Is Not Internet-Connected
- Upgrade a ZTP Firewall
- Revert Content Updates from Panorama
-
Upgrade a ZTP Firewall
Automatically upgrade your a ZTP firewall.
After you successfully add a ZTP firewall to
the Panorama™ management server, configure the target PAN-OS version
of the ZTP firewall. Panorama checks whether PAN-OS version installed
on the ZTP firewall is greater than or equal to the configured target
PAN-OS version after it successfully connects to Panorama for the
first time. If the PAN-OS version installed on the ZTP firewall
is less than the target PAN-OS version, then the ZTP firewall enters
an upgrade cycle until target PAN-OS version is installed.
- Log in to the Panorama Web Interface as an admin user.
- SelectandPanoramaDevice DeploymentUpdatesCheck Nowfor the latest PAN-OS releases.
- Selectand select one or more ZTP firewalls.PanoramaManaged DevicesSummary
- Reassociatethe selected ZTP firewall(s).
- Check (enable)Auto Push on 1st Connect.
- In theTo SW Versioncolumn, select the target PAN-OS version for the ZTP firewall.
- ClickOKto save your configuration changes.
- SelectCommitandCommit to Panorama.
- Power on the ZTP firewall.When the ZTP firewall connects to Panorama for the first time, it automatically upgrades to the PAN-OS version you selected. If you are upgrading to a PAN-OS maintenance release, the base PAN-OS image is installed first before the target maintenance release is installed.For example, you configured the targetTo SW Versionfor the managed firewall as PAN-OS 10.1.5. On first connection to Panorama, PAN-OS 10.1.0 is installed on the managed firewall first. After PAN-OS 10.1.0 successfully installs, the firewall is automatically upgraded to the target PAN-OS 10.1.5 release.
- Verify the ZTP firewall software upgrade.
- Selectand navigate to the ZTP firewall(s).PanoramaManaged DevicesSummary
- Verify theSoftware Versioncolumn displays the correct target PAN-OS release.
- For all future PAN-OS upgrades, see Upgrade Firewalls Using Panorama.