How to downgrade PAN-OS on the Firewall
8142
Created On 07/23/23 18:18 PM - Last Modified 03/15/25 00:28 AM
Objective
To downgrade the PAN-OS version to the previous one.
Environment
- Palo Alto Firewalls
- Supported PAN-OS
- Downgrade
Procedure
- The downgrade information is documented in the Upgrade/Downgrade guide. This article provides some caveats asked by customers.
- In case of downgrade from 10.1, Determine the downgrade path. This information is the reverse path of upgrade documented in PAN-OS Upgrade Guide.
- Review the release notes for each preferred release, to identify relevant issues.
- Review the Upgrade/Downgrade considerations to identify features that can have an impact and potentially cause issues.
- In the example of downgrade from PAN-OS 10.0.latest and then PAN-OS 9.1.latest.
- Download the base version of each major release (e.g 10.0.0) and install and reboot on the current preferred release (which keeps changing with time) of each major release in the downgrade path.
- Follow these actions to reach the desired version:
- Download base image 10.0.0
- Download 10.0.latest install and reboot
- Download base image 9.1.0
- Download 9.1.latest install and reboot
IMPORTANT:
- Save a backup of the current configuration file before each downgrade, export it, and save it externally.
- Export the device state if the Firewall is managed by Panorama.
- After each reboot, verify auto-commit has been successfully completed using the "show jobs all" command
- (PA-52xx) When transitioning from PAN-OS 10.1 to PAN-OS 10.0 inspect the status of the raid disks using the "show system raid detail" command.
NOTE: Raid rebuild might occur and the estimate time to complete is ~6.5 hours