Downgrade a VM-Series Firewall to a Previous Release
Table of Contents
11.0 (EoL)
Expand all | Collapse all
-
-
- Upgrade Panorama with an Internet Connection
- Upgrade Panorama Without an Internet Connection
- Install Content Updates Automatically for Panorama without an Internet Connection
- Upgrade Panorama in an HA Configuration
- Migrate Panorama Logs to the New Log Format
- Upgrade Panorama for Increased Device Management Capacity
- Upgrade Panorama and Managed Devices in FIPS-CC Mode
- Downgrade from Panorama 11.0
- Troubleshoot Your Panorama Upgrade
-
- What Updates Can Panorama Push to Other Devices?
- Schedule a Content Update Using Panorama
- Panorama, Log Collector, Firewall, and WildFire Version Compatibility
- Upgrade Log Collectors When Panorama Is Internet-Connected
- Upgrade Log Collectors When Panorama Is Not Internet-Connected
- Upgrade a WildFire Cluster from Panorama with an Internet Connection
- Upgrade a WildFire Cluster from Panorama without an Internet Connection
- Upgrade Firewalls When Panorama Is Internet-Connected
- Upgrade Firewalls When Panorama Is Not Internet-Connected
- Upgrade a ZTP Firewall
- Revert Content Updates from Panorama
-
End-of-Life (EoL)
Downgrade a VM-Series Firewall to a Previous Release
How do I downgrade my VM-Series firewall?
Use
the following workflow to restore the configuration that was running
before you upgraded to a different feature release. Any changes
made since the upgrade are lost. Therefore, it is important to back
up your current configuration so you can restore those changes when
you return to the newer release.
Use the following procedure
to downgrade to a previous release.
- Save a backup of the current configuration file.Although the firewall automatically creates a backup of the configuration, it is a best practice to create a backup before you upgrade and store it externally.
- Export named configuration snapshot (DeviceSetupOperations).Select the XML file that contains your running configuration (for example, running-config.xml) and click OK to export the configuration file.Save the exported file to a location external to the firewall. You can use this backup to restore the configuration if you have problems with the downgrade.Install the previous feature release image.Autosave versions are created when you upgrade to a new release.
- Check Now (DeviceSoftware) for available images.(PAN-OS 11.0.5 and later 11.0 releases) By default, the preferred releases and the corresponding base releases are displayed. To view the preferred releases only, disable (clear) the Base Releases checkbox. Similarly, to view the base releases only, disable (clear) the Preferred Releases checkbox.Locate the image to which you want to downgrade. If the image is not already downloaded, then Download it.After the download completes, Install the image.Select a Config File for Downgrading, which the firewall will load after you reboot the device. In most cases, you should select the configuration that was saved automatically when you upgraded from the release to which you are now downgrading. For example, if you are running PAN-OS 9.1 and are downgrading to PAN-OS 9.0.3, select autosave-9.0.3.After the installation completes successfully, reboot using one of the following methods:
- If you are prompted to reboot, click Yes.
- If you are not prompted to reboot, go to Device Operations (DeviceSetupOperations) and Reboot Device.