Install Updates for Panorama with an Internet Connection
Verify that the updates you plan to install are appropriate for your Panorama deployment.
|
Refer to the
Release Notes
for the minimum content release version required for a Panorama software release. If you intend to
upgrade Log Collectors and firewalls
to a particular release, you must first upgrade Panorama to that (or a later) release.
For a Panorama virtual appliance that runs on an ESXi server, ensure that the server meets the requirements (see
Setup Prerequisites for the Panorama Virtual Appliance).
|
Save a backup of the current Panorama configuration file that you can use to restore the configuration if you have problems with the upgrade.
Although Panorama automatically creates a backup configuration, best practice is to create and externally store a backup before you upgrade.
|
Save named Panorama configuration snapshot (
Panorama > Setup > Operations), enter a Name for the configuration, and click OK.
Export named Panorama configuration snapshot, select the Name of the configuration you just saved, click OK, and save the exported file to a location that is external to Panorama.
|
(
As needed
) Install content updates.
If Panorama is not running the minimum content versions required for the Panorama release to which you intend to upgrade, you must update content versions to the minimum (or later) versions before you install the software updates. Refer to the
Release Notes
for the minimum content release version you must install for a Panorama release.
Palo Alto Networks highly recommends that Panorama, Log Collectors, and all managed firewalls run the same content release version. Additionally, we recommend that you schedule automatic, recurring updates so that you are always running the latest content versions (
Step 7).
|
Check Now
(
Panorama > Dynamic Updates) for the latest updates. If the value in the Action column is
Download, an update is available.
Ensure that Panorama is running the same but not a later content release version than is running on managed firewalls and Log Collectors.
(
As needed
) Before you update the content release version on Panorama, be sure to
upgrade managed firewalls
and then Log Collectors (see
Deploy an Update to Log Collectors when Panorama is Internet-connected) to the same (or a later) content release version.
If you do not need to install content updates at this time, then skip ahead to
Step 4.
Install content updates in the following sequence. When an installation completes, the Currently Installed column displays a check mark.
Download
and
Install
the Applications or Applications and Threats update. Regardless of your subscription, Panorama installs and needs only the Applications content update, not the Threats content. For details, see
Panorama, Log Collector, and Firewall Version Compatibility.
Download
and
Install
any other updates (Antivirus, WildFire, or URL Filtering) as needed, one at a time, and in any sequence.
|
Determine the software upgrade path.
You cannot skip installation of any major release versions in the path to your target release. For example, if you intend to upgrade from Panorama 6.0.13 to Panorama 7.1.3, you must:
Download and install Panorama 6.1.0 and reboot.
Download and install Panorama 7.0.1 and reboot (7.0.1 is the base image for the 7.0 release; not 7.0.0).
Download Panorama 7.1.0.
Optionally, install this base image and reboot before you install the target maintenance release.
Download and install Panorama 7.1.3 and reboot.
|
Check which version has a check mark in the Currently Installed column (
Panorama > Software) and proceed as follows:
If a Panorama 7.0 release is currently installed, skip ahead to
Step 6
to upgrade to a Panorama 7.1 release.
If a release earlier than Panorama 7.0 is installed, proceed to
Step 5
and follow the upgrade path to Panorama 7.0.1 before you upgrade to a Panorama 7.1 release.
We highly recommend that you review the known issues and changes to default behavior in the
Release Notes
and upgrade/downgrade considerations in the
New Features Guide
for each release through which you pass as part of your upgrade path.
|
Use the upgrade path identified in
Step 4
to upgrade to a Panorama 7.0 release.
|
Repeat the following procedure until the appliance is running a Panorama 7.0 release—do not skip installation of any major release version in the path to your target Panorama 7.1 release.
Check Now (
Panorama > Software) for the latest updates. If an update is available, the Action column displays
Download.
For each release in your upgrade path,
Download
the model-specific file for the release version to which you are upgrading. For example, to upgrade an M-Series appliance to Panorama 7.0.1, download the
Panorama_m-7.0.1
image; to upgrade a Panorama virtual appliance to Panorama 7.0.1, download the
Panorama_pc-7.0.1
image.
After a successful download, the Action column changes from
Download
to Install for the downloaded image.
By default, you can download a maximum of two software or content updates of each type on a Panorama appliance and if you download a third update of the same type, Panorama will delete the update for the earliest version of that type. If you need to upload more than two software updates or content updates of a single type, use the
set max-num-images count <
number
>
CLI command to increase the maximum.
Install
the software update.
If prompted to reboot, click
Yes. If you see a
CMS Login
prompt, press Enter without typing a username or password. When the Panorama login prompt appears, enter the username and password you specified during initial configuration.
If you are not prompted to reboot,
Reboot Panorama
from the Device Operations section (
Panorama > Setup > Operations).
Repeat these steps for each release in your upgrade path.
|
Install Panorama 7.1.
|
Check Now (
Panorama > Software) for the latest updates. If an update is available, the Action column displays
Download.
If you are upgrading to a Panorama 7.1 maintenance release (a release other than the Panorama 7.1.0 base image), first download the Panorama 7.1.0 release.
Locate and
Download
the model-specific file for the release version to which you are upgrading. For example, to upgrade an M-Series appliance to Panorama 7.1.0, download the
Panorama_m-7.1.0
image; to upgrade a Panorama virtual appliance to Panorama 7.1.0, download
Panorama_pc-7.1.0
.
After a successful download, the Action column changes from
Download
to Install for the downloaded image.
(
Required for the target release; optional for the base-image—PAN-OS 7.1.0 release—if upgrading to a maintenance release
) Install the downloaded image and then reboot.
Install the image.
As a best practice, when upgrading to a Panorama 7.1 maintenance release (Panorama 7.1.1 or later release), install the Panorama 7.1.0 base image and reboot the appliance before you download and install the maintenance release.
After the installation completes successfully, reboot using one of the following methods:
If prompted to reboot, click
Yes. If you see a
CMS Login
prompt, press Enter without typing a username or password. When the Panorama login prompt appears, enter the username and password you specified during initial configuration.
If you are not prompted to reboot,
Reboot Panorama
from the Device Operations section (
Panorama > Setup > Operations).
(
Required only if upgrading to a PAN-OS 7.1 maintenance release
) After completing the above steps for the PAN-OS 7.1.0 base image, repeat steps
1
through
3
to upgrade to the target maintenance release.
|
(
Best Practice
) Schedule recurring, automatic content updates.
Panorama does not synchronize content update schedules across HA peers. You must perform this task on both the active and passive Panorama.
|
In the header row for each update type (
Panorama > Dynamic Updates), the
Schedule
is initially set to
None. Perform the remaining steps for each update type.
Click
None
and select the update frequency (
Recurrence). The frequency options depend on the update type.
Select the schedule action:
Download And Install
(
Best Practice
)—Panorama automatically installs updates after downloading them.
Download Only
—You must manually install updates after Panorama downloads them.
Based on the
best practices for the security posture
of your organization, configure a delay (
Threshold) after an update becomes available before Panorama downloads the update.
Click
OK
to save your changes.
Select
Commit > Commit to Panorama
and
Commit
your changes.
|
(
Only if upgrading from a release earlier than Panorama 5.1 to a Panorama 5.1 or later release running on an ESXi server
) Configure the Panorama virtual appliance settings on the VMware ESXi server.
|
After Panorama reboots, complete the following tasks:
Access the VMware vSphere Client and select go to the
Virtual Machines
tab.
Right-click the Panorama virtual appliance and select
Power > Power Off.
Right-click the Panorama virtual appliance again and
Edit Settings
as follows:
Select the
Hardware
tab and allocate
Memory
based on how many firewalls Panorama manages:
1–10 managed firewalls: 4GB
11–50 managed firewalls: 8GB
51–1,000 managed firewalls: 16GB
Set the
SCSI Controller
to
LSI Logic Parallel.
Go to the
Options
tab, select
General Options, set the
Guest Operating System
to
Linux, and set the
Version
to
Other Linux (64-bit).
Click
OK.
Right-click the Panorama virtual appliance and select
Power > Power On.
|