Upgrade SD-WAN Plugin with Compatible PAN-OS Release
Before upgrading the SD-WAN plugin, you need to take the backup of the
configuration file, generate a technical support file, and install a compatible content
release version.
It’s imperative to ensure that an existing network infrastructure remains up to
date and is capable of upgrading its features to unlock new functionalities. The SD-WAN upgrade guide helps the network administrators to upgrade the
Panorama management server and Palo Alto Networks firewalls that are compatible with the
SD-WAN plugin release.
It is important that you have a proper upgrade or downgrade plan before starting actual
upgrade or downgrade procedure. Refer the valid upgrade and downgrade paths for your
currently installed SD-WAN plugin
version.
Before proceeding with the upgrade process, ensure the following:
Take a backup of all the configurations on each device.
You have administrator access to the Palo Alto Networks devices.
Prerequisites
Before you upgrade the Panorama HA pair, it's important to save the configuration
files, create a technical support file, and check for the compatible content release
version for your device.
Back up Your Configuration File
Make a backup of the current configuration file. It's recommended to make a
backup of your current Panorama and firewall configurations:
Your firewall and the Panorama running a specific PAN-OS version must contain the
minimum content release (Applications and Threats)
version that’s compatible with the PAN-OS version.
Use the following workflow to download and install the content release version
that’s compatible with the PAN-OS version:
For the firewall, select DeviceDynamic Updates and for Panorama select PanoramaDynamic Updates to check the version information of the
Applications and Threats.
Check Now to retrieve a list of available
updates.
Locate and Download the appropriate content release
version. After you successfully download a content update file, the link in
the Action column changes from Download to
Install for that content release version.
Install the update on the Palo Alto Networks
devices.
Important Considerations for Upgrading Panorama
The following are the important considerations for upgrading the SD-WAN plugin version on your Panorama management server:
(HA Deployments only) Both the active and passive Panorama must
have the same Panorama software and SD-WAN plugin
versions.
(HA Deployments only) Maintain the same HA states for both Panorama
and Palo Alto Networks Next-Generation Firewalls after upgrade and before
commit or commit all, so that the configuration changes
are minimal.
Always ensure that the Panorama software version is higher than the PAN-OS
version.
(HA Deployments only) You must upgrade both active and passive
Panorama HA pairs simultaneously.
After completing the SD-WAN plugin upgrade, you must
perform a commit force through the CLI command (in configuration mode)
on the Panorama devices. If you perform commit all instead of commit
force, then you will lose all the SD-WAN configurations
on that device.