Create a Software Update Grouping Rule
Focus
Focus
Next-Generation Firewall

Create a Software Update Grouping Rule

Table of Contents

Create a Software Update Grouping Rule

Create a software update grouping rule to upgrade the PAN-OS version for multiple firewalls.
Contact your account team to enable Cloud Management for NGFWs using Strata Cloud Manager.
Where Can I Use This?
What Do I Need?
  • NGFW (Managed by Strata Cloud Manager)
  • VM-Series, funded with Software NGFW Credits
  • AIOps for NGFW Premium license (use the Strata Cloud Manager app)
Create a software update grouping rule so you can group sets of firewalls and schedule PAN-OS software upgrades for sets of firewalls. A firewall can only be associated with a single software update grouping rule. When you create a new software update grouping rule, only firewalls not already associated with an existing software update grouping rule are displayed as
Target Devices
.
  1. Log in to
    Strata Cloud Manager
    .
  2. Select
    Workflows
    Upgrades
    NGFW - Scheduler
    Software Update Grouping Rules
    and
    Add Software Upgrade Grouping Rule
    .
  3. Configure the General settings for software update grouping rule.
    1. Enter a
      Name
      .
    2. (
      Optional
      ) Enter a
      Description
      for the software update grouping rule.
    3. Specify the
      Position
      of the update upgrade grouping rule.
      You can select
      Before
      or
      After
      an existing software update grouping rule. The position of the software update grouping rule determines which firewalls are
      Target Devices
      .
      Based on the rule position and Match Criteria, firewalls aren’t displayed as
      Target Devices
      if they’re already associated with a rule positioned before the rule you’re creating.
  4. Configure the Match Criteria to filter and specify target firewalls associated with the software update grouping rule.
    1. Specify the
      Folders
      the firewalls you want to target are associated with.
      • Any
        (default)—Include all folders and the associated firewalls.
      • Match
        —Select one or more folder names to match and include in the filtered target firewalls.
      • Exclude (Negate)
        —Select one or more folder names to match and exclude from the filtered target firewalls.
    2. Specify the firewall
      Models
      you want to target.
      All supported firewall models are listed and not just the firewall models associated with the filtered
      Folders
      .
      • Any
        (default)—Include all firewall models.
      • Match
        —Select one or more firewall models to match and include in the filtered target firewalls.
      • Exclude (Negate)
        —Select one or more firewall models to match and exclude from the filtered target firewalls.
    3. Specify one or more firewall
      Label
      you want to target.
      If you specify multiple labels, use the
      And
      ,
      Or
      , and
      Not
      operators to further filter the target firewalls.
    4. (
      Optional
      )
      Exclude Devices
      from the list of
      Target Devices
      .
    5. Review the list of
      Target Devices
      to confirm all the firewalls you want to include in the software update grouping rule are included.
      If not all the firewalls you want to include are listed, go back and modify the Match Criteria until all the firewalls you want included are listed as
      Target Devices
      .
  5. Save
    .

Recommended For You