NGFW-ENGINEER · Question #23
An administrator plans to upgrade a pair of active/passive firewalls to a new PAN-OS release. The environment is highly sensitive, and downtime must be minimized. What is the recommended upgrade…
The correct answer is A. Suspend the active firewall to trigger a failover to the passive firewall. With traffic now running on. The Palo Alto Networks recommended HA upgrade procedure prioritizes continuity by keeping production traffic flowing throughout the process. The correct sequence is: (1) first upgrade the passive firewall (no traffic impact since it is standby), (2) suspend the active firewall…
Question
An administrator plans to upgrade a pair of active/passive firewalls to a new PAN-OS release. The environment is highly sensitive, and downtime must be minimized. What is the recommended upgrade process for minimal disruption in this high availability (HA) scenario?
Options
- ASuspend the active firewall to trigger a failover to the passive firewall. With traffic now running on
- BShut down the currently active firewall and upgrade it offline, allowing the passive firewall to
- CIsolate both firewalls from the production environment and upgrade them in a separate, offline
- DPush the new PAN-OS version simultaneously to both firewalls, having them upgrade and reboot
How the community answered
(42 responses)- A74% (31)
- B7% (3)
- C5% (2)
- D14% (6)
Explanation
The Palo Alto Networks recommended HA upgrade procedure prioritizes continuity by keeping production traffic flowing throughout the process. The correct sequence is: (1) first upgrade the passive firewall (no traffic impact since it is standby), (2) suspend the active firewall to force a controlled failover to the now-upgraded passive, (3) upgrade the formerly active firewall while it carries no traffic, then (4) restore the HA pair. This ensures traffic is always passing through an operational firewall and limits the actual production-impacting failover to a single brief, controlled event. Options B and C involve taking the active firewall offline abruptly or isolating both firewalls simultaneously, causing significant downtime. Option D risks both firewalls rebooting simultaneously, causing a total outage.
Topics
Community Discussion
No community discussion yet for this question.