Upgrade a Standalone Firewall to PAN-OS 8.0

Review the PAN-OS 8.0 Release Notes and then use the following procedure to upgrade a firewall not in an HA configuration to PAN-OS 8.0.
If your firewalls are configured to forward samples to a WF-500 appliance for analysis, you must upgrade the WildFire appliance to PAN-OS 8.0 before you upgrade the forwarding firewalls.
Ensure the firewall is connected to a reliable power source. A loss of power during an upgrade can make the firewall unusable.
  1. Save a backup of the current configuration file.
    Although the firewall automatically creates a configuration backup, it is a best practice to create and externally store a backup before you upgrade.
    1. Select
      Device
      Setup
      Operations
      and click
      Export named configuration snapshot
      .
      fw-export-named-config-snapshot.png
    2. Select the XML file that contains your running configuration (for example,
      running-config.xml
      ) and click
      OK
      to export the configuration file.
      export-running-config.png
    3. Save the exported file to a location external to the firewall. You can use this backup to restore the configuration if you have problems with the upgrade.
  2. Ensure that the firewall is running the latest content release version. Refer to the Release Notes for the minimum content release version you must install for a PAN-OS 8.0 release. Make sure to follow the Best Practices for Application and Threat ContentUpdates
    1. Select
      Device
      Dynamic Updates
      and check which
      Applications
      or
      Applications and Threats
      to determine which update is Currently Installed.
      fw-content-updates.png
    2. If the firewall is not running the minimum required update or a later version,
      Check Now
      to retrieve a list of available updates.
    3. Locate and
      Download
      the content release version you intend to install. After you successfully download a content update file, the link in the Action column changes from
      Download
      to
      Install
      for that release version.
    4. Install
      the update.
  3. You cannot skip installation of any feature release versions in the path from the currently running PAN-OS version to PAN-OS 8.0.
    Review the known issues and changes to default behavior in the Release Notes and upgrade/downgrade considerations in the New Features Guide for each release through which you pass as part of your upgrade path.
  4. Upgrade to PAN-OS 8.0.
    If your firewall does not have internet access from the management port, you can download the software image from the PaloAltoNetworks Support Portal and then manually
    Upload
    it to your firewall.
    1. Select
      Device
      Software
      and click
      Check Now
      to display the latest PAN-OS updates.
    2. Locate and
      Download
      PAN-OS 8.0.0.
    3. After you download the image (or, for a manual upgrade, after you upload the image),
      Install
      the image.
      As a best practice, when upgrading to a PAN-OS 8.0 release, install the PAN-OS 8.0.0 base image and reboot the firewall before you download and install a PAN-OS 8.0 maintenance release.
    4. After the installation completes successfully, reboot using one of the following methods:
      • If you are prompted to reboot, click
        Yes
        .
      • If you are not prompted to reboot, select
        Device
        Setup
        Operations
        and click
        Reboot Device
        .
  5. Verify that the firewall is passing traffic.
    Select
    Monitor
    Session Browser
    .
    session-browser.png

Related Documentation