1. Major Releases
PAN-OS 10.2
PAN-OS 11.0
PAN-OS 11.1
PAN-OS 11.2
A major release introduces:
New features
Support for new firewall models
Architectural changes
New integrations and capabilities
2. Maintenance Releases
11.1.0 → initial release
11.1.1
11.1.2
11.1.3
11.1.4
Maintenance releases contain:
Bug fixes
Performance improvements
Stability enhancements
Security fixes
3. Hotfix Releases
11.1.4-h1
Hotfixes are targeted fixes for:
Critical bugs
Security vulnerabilities
High-impact customer issues
Firewall upgrades cycle – Formal document to follow.
Emergency Patch Process
Shadowing of engineers for upgrades – Khoa to shadow DK for next upgrade
Create a Standard Change Template for firewall upgrades – Minor – H2-H3 – Manny to initiate this request
For critical CVEs:
Day 0
• Advisory released
• Security team evaluates exposure
Day 1–3
• Upgrade test region
• Validate production configuration
Day 4–7
• Upgrade internet-facing firewalls
• Upgrade Panorama
Day 8–14
• Upgrade remaining production devices
For severe management-plane or Global Protect vulnerabilities, compress this timeline to 24–72 hours.
Recommended Production Standards
• Maintenance releases bi-annually
- Move to preferred version, stay on same train
- Ex. Current Ver – 11.2.10-h10 – Ended preferred version
- Upgrade to latest hotfix 11.3.13-h5
- Test 30 days, adopt new Preferred Version
• Major release every 18–24 months
o Move to the next major train release only if:
Obtained preferred-release status
Wait till Prisma Access is on X.Y version
Reach at least X.Y.h4-8 hotfix maturity
Been in production elsewhere for several months
In PAN-OS, the version format is:
X.Y.Z[-hN]
Where:
-
X = Major release
- Introduces significant platform changes, new capabilities, or architectural updates.
- Example: 10.x → 11.x → 12.x.
-
Y = Feature (or major/minor) release
- Introduces new features, hardware support, and enhancements within the same major version.
- Examples: 11.1, 11.2, 12.1. Since PAN-OS 12.1, Palo Alto Networks refers to these as major versions in its updated release terminology.
-
Z = Maintenance release
- This is the maintenance code you are asking about.
-
Primarily contains:
- Bug fixes
- Security vulnerability fixes
- Stability improvements
- Performance improvements
- It does not typically introduce new features.
-
Examples:
- 11.1.0 = Base release
- 11.1.1 = First maintenance release
- 11.1.8 = Eighth maintenance release
- 11.1.16 = Sixteenth maintenance release
-
-hN = Hotfix
- Example: 11.1.8-h3
- A targeted build that fixes specific high-priority bugs or security issues on top of a maintenance release.
- Hotfixes are cumulative for that maintenance release.
Example
| Version | Meaning |
|---|---|
| 11.2.0 | Base release of the 11.2 feature version |
| 11.2.3 | Third maintenance release |
| 11.2.3-h2 | Second hotfix for maintenance release 11.2.3 |
| 12.1.8 | Eighth maintenance release for PAN-OS 12.1 |
Upgrade best practice
Palo Alto Networks generally recommends:
-
Running a preferred/recommended maintenance release rather than the initial
.0base release. - During upgrades, use the latest maintenance release in each required upgrade path to benefit from accumulated fixes and improved stability
No comments:
Post a Comment