Wednesday, June 24, 2026

Palo Alto PAN-OS - Major Release, Maintenance Releases, Hotfix Releases

 1. Major Releases
PAN-OS 10.2
PAN-OS 11.0
PAN-OS 11.1
PAN-OS 11.2

A major release introduces:

New features
Support for new firewall models
Architectural changes
New integrations and capabilities


2. Maintenance Releases
11.1.0 → initial release
11.1.1
11.1.2
11.1.3
11.1.4


Maintenance releases contain:
Bug fixes
Performance improvements
Stability enhancements
Security fixes


3. Hotfix Releases
11.1.4-h1

Hotfixes are targeted fixes for:
Critical bugs
Security vulnerabilities
High-impact customer issues




Firewall upgrades cycle – Formal document to follow.

Emergency Patch Process

Shadowing of engineers for upgrades – Khoa to shadow DK for next upgrade
Create a Standard Change Template for firewall upgrades – Minor – H2-H3 – Manny to initiate this request

For critical CVEs:
Day 0
Advisory released 
Security team evaluates exposure 
Day 1–3
Upgrade test region 
Validate production configuration 
Day 4–7
Upgrade internet-facing firewalls 
Upgrade Panorama 
Day 8–14
Upgrade remaining production devices 

For severe management-plane or Global Protect vulnerabilities, compress this timeline to 24–72 hours.


Recommended Production Standards
Maintenance releases bi-annually
         Move to preferred version, stay on same train
        - Ex. Current Ver – 11.2.10-h10 – Ended preferred version
                -  Upgrade to latest hotfix 11.3.13-h5
        -   Test 30 days, adopt new Preferred Version


Major release every 18–24 months
o Move to the next major train release only if:
Obtained preferred-release status
Wait till Prisma Access is on X.Y version
Reach at least X.Y.h4-8 hotfix maturity
Been in production elsewhere for several months



In PAN-OS, the version format is:

X.Y.Z[-hN]

Where:

  • X = Major release
    • Introduces significant platform changes, new capabilities, or architectural updates.
    • Example: 10.x → 11.x → 12.x.
  • Y = Feature (or major/minor) release
    • Introduces new features, hardware support, and enhancements within the same major version.
    • Examples: 11.1, 11.2, 12.1. Since PAN-OS 12.1, Palo Alto Networks refers to these as major versions in its updated release terminology.
  • Z = Maintenance release
    • This is the maintenance code you are asking about.
    • Primarily contains:
      • Bug fixes
      • Security vulnerability fixes
      • Stability improvements
      • Performance improvements
    • It does not typically introduce new features.
    • Examples:
      • 11.1.0 = Base release
      • 11.1.1 = First maintenance release
      • 11.1.8 = Eighth maintenance release
      • 11.1.16 = Sixteenth maintenance release
  • -hN = Hotfix
    • Example: 11.1.8-h3
    • A targeted build that fixes specific high-priority bugs or security issues on top of a maintenance release.
    • Hotfixes are cumulative for that maintenance release.

Example

VersionMeaning
11.2.0Base release of the 11.2 feature version
11.2.3Third maintenance release
11.2.3-h2Second hotfix for maintenance release 11.2.3
12.1.8Eighth maintenance release for PAN-OS 12.1

Upgrade best practice

Palo Alto Networks generally recommends:

  • Running a preferred/recommended maintenance release rather than the initial .0 base release.
  • During upgrades, use the latest maintenance release in each required upgrade path to benefit from accumulated fixes and improved stability

No comments:

Post a Comment

PALO ALTO FIREWALL STUDY GUIDE

PALO ALTO FIREWALL STUDY GUIDE 1. Palo Alto Networks Firewall Overview What is Palo Alto Firewall? A Palo Alto Networks Next-Generation Fire...