Panorama, Log Collector, Firewall, and WildFire Version Compatibility
Table of Contents
PAN.OS 11.1 & Later
Expand all | Collapse all
-
-
- Upgrade Panorama with an Internet Connection
- Upgrade Panorama Without an Internet Connection
- Install Content Updates Automatically for Panorama without an Internet Connection
- Upgrade Panorama in an HA Configuration
- Migrate Panorama Logs to the New Log Format
- Upgrade Panorama for Increased Device Management Capacity
- Upgrade Panorama and Managed Devices in FIPS-CC Mode
- Downgrade from Panorama 11.1
- Troubleshoot Your Panorama Upgrade
-
- What Updates Can Panorama Push to Other Devices?
- Schedule a Content Update Using Panorama
- Panorama, Log Collector, Firewall, and WildFire Version Compatibility
- Upgrade Log Collectors When Panorama Is Internet-Connected
- Upgrade Log Collectors When Panorama Is Not Internet-Connected
- Upgrade a WildFire Cluster from Panorama with an Internet Connection
- Upgrade a WildFire Cluster from Panorama without an Internet Connection
- Upgrade Firewalls When Panorama Is Internet-Connected
- Upgrade Firewalls When Panorama Is Not Internet-Connected
- Upgrade a ZTP Firewall
- Revert Content Updates from Panorama
-
Panorama, Log Collector, Firewall, and WildFire Version Compatibility
PAN-OS® 11.1 version compatibility for Panorama™, Log
Collectors, firewalls, and WildFire®.
For best results, adhere to the following Panorama™
compatibility guidelines:
- Install the same Panorama release on both the Panorama management server and the Dedicated Log Collectors.
- Panorama must be running the same or a later PAN-OS version than the firewall it manages. See Panorama Management Compatibility for more information.Before upgrading firewalls to PAN-OS 11.0, you must first upgrade Panorama to 11.0.
- Dedicated Log Collectors must be running the same or later PAN-OS version than the managed firewalls forwarding logs.
- Panorama running PAN-OS 11.1 can manage WildFire® appliances and WildFire appliance clusters that are running the same or an earlier PAN-OS release. See Panorama Management Compatibility for more information.It is recommended that the Panorama management server, Wildfire appliances, and Wildfire appliance clusters run the same PAN-OS release.
- The content release version on the Panorama management server must be the same (or earlier) version as the content release version on any Dedicated Log Collectors or managed firewalls. See Panorama Management Compatibility for more information.Palo Alto Networks® recommends installing the same Applications database version on Panorama as on the Dedicated Log Collectors and firewalls.Regardless whether your subscriptions include the Applications database or Applications and Threats database, Panorama installs only the Applications database. Panorama and Dedicated Log Collectors do not enforce policy rules so they do not need the threat signatures from the Threats database. The Applications database contains threat metadata (such as threat IDs and names) that you use on Panorama and Dedicated Log Collectors when defining policy rules to push to managed firewalls and when interpreting threat information in logs and reports. However, firewalls require the full Applications and Threats database to match the identifiers recorded in logs with the corresponding threat, URL, or application names. Refer to the Release Notes for the minimum content release version required for a Panorama release.