: Upgrade/Downgrade Considerations
Focus
Focus

Upgrade/Downgrade Considerations

Table of Contents

Upgrade/Downgrade Considerations

Upgrade/downgrade considerations for SD-WAN Plugin releases.
The following tables list the features that have upgrade or downgrade impact. Make sure you understand all upgrade and downgrade considerations before you upgrade to or downgrade from an SD-WAN plugin release. For additional information about the SD-WAN plugin releases, refer to the PAN-OS Release Notes.
SD-WAN Plugin 3.2 Upgrade/Downgrade Considerations
Feature
Upgrade Considerations
Downgrade Considerations
PAN-233120
None
When you attempt to downgrade from Panorama 11.1.0 to Panorama 10.1.11 directly, the SD-WAN plugin version does not get downgraded to the compatible version automatically. Due to this, the Panorama will throw a commit failure.
Workaround
: To downgrade from Panorama 11.1.0 to Panorama 10.1.11:
  1. First, downgrade from Panorama 11.1.0 (with SD-WAN plugin version 3.2.0) to 11.0.2-h2 (with SD-WAN plugin version 3.1.1)
  2. Then, downgrade from Panorama 11.0.2-h2 (with SD-WAN plugin version 3.1.1) to Panorama 10.1.11 (with SD-WAN plugin version 2.2.4)
SD-WAN IKEv2 Certificate-based Authentication Support
The existing devices in the SD-WAN configuration will continue to use the pre-shared key (PSK) and would not automatically change to certificate-based authentication. If you want to change the authentication type to
certificate
, follow these steps:
  • Delete the VPN cluster
  • Import the certificates (manually or bulk import)
  • Change the
    Authentication
    type to
    Certificate
    (either manually or through CSV import of devices)
  • reconfigure the devices in the new cluster
  • If the VPN cluster is configured as a pre-shared key (PSK), then downgrade will be allowed.
  • If the VPN clusters are created with certificate-based authentication and the downgrade version does not support IKEv2 certificate authentication, the downgrade won't be allowed. To proceed with the downgrade:
    • Delete the VPN cluster. SD-WAN device authentication will automatically change to PSK on downgrade.
    • After downgrade, configure the new cluster and add the SD-WAN devices to it.
SD-WAN Plugin 3.1 Upgrade/Downgrade Considerations
Feature
Upgrade Considerations
Downgrade Considerations
You cannot upgrade directly to SD-WAN plugin 3.1.2 from any plugin version earlier than 3.1.1. If you are running SD-WAN plugin 3.1.0 or an earlier plugin version on your firewall, you must upgrade to SD-WAN plugin 3.1.1 before you upgrade to SD-WAN plugin 3.1.2.
None
DDNS/Dynamic IP addressing using FQDN
When upgrading to SD-WAN plugin 3.1.1, SD-WAN branches configured with dynamic IP addressing using FQDN didn't work. Instead, upgrade to SD-WAN plugin 3.1.2. You must first Commit on Panorama and then Push to devices.
None
SD-WAN Plugin 2.2 Upgrade/Downgrade Considerations
Feature
Upgrade Considerations
Downgrade Considerations
After you upgrade to SD-WAN plugin release 2.2.6, you won't be able to change the existing VPN cluster name.
None.
PLUG-11223
(
HA deployments only
) When you upgrade from an earlier SD-WAN plugin release to 2.2.5 followed by
Commit
and
Commit All
, the key ID will change if it was generated using the firewall that has a higher serial number.
None.
For a Panorama virtual appliance, you must increase the memory allocated to the Panorama management server to 64GB. This is required to avoid commit failures on successful upgrade to SD-WAN Plugin 2.2.
None.
Review the minimum supported PAN-OS versions before upgrading your firewalls leveraging SD-WAN.
Panorama plugin for SD-WAN 2.2 supports the following minimum PAN-OS versions for managed firewalls.
  • PAN-OS 10.0—
    10.0.8
  • PAN-OS 10.1—
    10.1.4
None.
Prisma Access Hub Support
To downgrade the SD-WAN Plugin from 2.2.0 to 2.1.0:
  1. Use the UI to delete all of the Prisma Access hub onboarding.
  2. Delete the BGP local address pool subnet.
  3. Commit the configuration.
  4. Downgrade the SD-WAN Plugin to 2.1.0.
SD-WAN Devices
For SD-WAN devices (
Panorama
SD-WAN
Devices
) in a high availability (HA) configuration, you must enter a unique Site name for each HA peer when adding the SD-WAN device to the Panorama management server. The SD-WAN plugin 2.2 requires that all devices have a unique Site name.
On upgrade to SD-WAN plugin 2.2, commits on Panorama fail if two SD-WAN devices have the same Site name.
None.
SD-WAN Plugin 2.1 Upgrade/Downgrade Considerations
Feature
Upgrade Considerations
Downgrade Considerations
To upgrade from SD-WAN Plugin 2.0.2 or earlier 2.0 versions to 2.1.0, complete the following steps during a maintenance timeframe:
  1. Upgrade to SD-WAN Plugin 2.1.0.
  2. Make a small configuration change of your choice in the SD-WAN cluster configuration. For example, change the SD-WAN hub priority and change it back.
  3. Issue a local Panorama Commit.
  4. Push the configuration to all devices in the VPN cluster at once. On the Push Scope Selection, select
    Force Template Values
    .
  5. Reboot all SD-WAN hubs. If the hubs are an HA pair, follow the HA reboot procedure.
None
SD-WAN Plugin 2.0 Upgrade/Downgrade Considerations
Feature
Upgrade Considerations
Downgrade Considerations
To upgrade from SD-WAN Plugin 2.0.x to 2.0.3, complete the following steps during a maintenance timeframe:
  1. Upgrade to SD-WAN Plugin 2.0.3.
  2. Make a small configuration change of your choice in the SD-WAN cluster configuration. For example, change the SD-WAN hub priority and change it back.
  3. Issue a local Panorama Commit.
  4. Push the configuration to all devices in the VPN cluster at once. On the Push Scope Selection, select
    Force Template Values
    .
  5. Reboot all SD-WAN hubs. If the hubs are an HA pair, follow the HA reboot procedure.
None
Downgrading the Panorama management server and managed firewalls that currently leverage features that were introduced in PAN-OS 10.0.3 (or later version) or SD-WAN plugin 2.0.1 (or later version) can cause stability issues if you downgrade from the following versions:
  • PAN-OS 10.0.3 or a later version to PAN-OS 10.0.2 or an earlier release with SD-WAN plugin 2.0.1 or later version installed.
  • SD-WAN plugin version 2.0.1 or a later version to SD-WAN plugin 2.0.0.
Workaround
: Before you upgrade to PAN-OS 10.0.3 or SD-WAN plugin 2.0.1, save and export your Panorama and firewall configurations. Then, if you need to downgrade PAN-OS or the SD-WAN plugin to a previous version:
  1. Downgrade the PAN-OS or SD-WAN plugin version on Panorama and managed firewalls.
  2. Select
    Panorama
    Setup
    Operations
    and
    Import named Panorama configuration snapshot
    .
  3. Load named Panorama configuration snapshot
    .
  4. Commit and Push
    .
If you did not export and save a Panorama and managed firewall configuration prior to upgrading to PAN-OS 10.0.3 or SD-WAN plugin 2.0.1, then— before you can successfully downgrade to PAN-OS 10.0.2 (or an earlier version) or SD-WAN plugin 2.0.0—you must remove any feature options or configurations that were introduced in PAN-OS 10.0.3 or in SD-WAN plugin 2.0.1.
Remove Private AS
None
If you change the
Remove Private AS
setting, commit to all SD-WAN cluster nodes, and subsequently downgrade to an SD-WAN Plugin version earlier than 2.0.2, then all configuration related to
Remove Private AS
must be done outside of the SD-WAN plugin or directly on the firewalls.
Full Mesh and DDNS
None
If you downgrade from SD-WAN Plugin 2.0.1 to an earlier plugin version, the VPN Cluster will not support a mesh configuration or a DDNS configuration. If you had configured a VPN mesh configuration, then you must move the cluster to a Hub-Spoke configuration, configure a hub if you didn't have one,
Remove DDNS Configuration
, commit on Panorama, and then push the configuration to your firewalls.  If you cannot change the VPN cluster to a Hub-Spoke configuration, then you must delete the entire cluster, commit on Panorama, and then push the configuration to your firewalls before you downgrade. 

Recommended For You