PAN-OS - Firewall Upgrade Readiness Checks
PAN-OS by Palo Alto Networks Pack.#
This Playbook is part of theSupported versions
Supported Cortex XSOAR versions: 6.10.0 and later.
This playbook uses the PAN-OS integration to check NGFW device conditions that can affect its readiness to perform a PAN-OS upgrade. Included checks examine the following:
- Available disk space for the target version (base image + release image)
- Presence of any uncommitted configuration changes
- Whether device has an active support license
- Whether NTP is configured and synced
- Whether the latest App/Threat dynamic update is installed
- For devices in HA groups, if devices in the group have:
- App/Threat, AntiVirus, and GlobalProtect Client are at the same level and compatible for HA failover
- Running configuration synchronized among peers
Playbook output includes a register of the checks performed, a brief description, and their result.
NOTE: This playbook is intended for use with a single PAN-OS Integration Instance.
#
DependenciesThis playbook uses the following sub-playbooks, integrations, and scripts.
#
Sub-playbooksThis playbook does not use any sub-playbooks.
#
Integrations- Panorama
#
Scripts- JsonToTable
- PAN-OS-GetAvailablePANOSSoftware
- PAN-OS-GetDeviceDiskSpace
- Set
#
Commands- pan-os
- pan-os-check-dynamic-updates-status
- pan-os-platform-get-system-info
#
Playbook InputsName | Description | Default Value | Required |
---|---|---|---|
targetDevice | Serial Number of the firewall to check upgrade readiness for. | Required | |
targetVersion | The target PAN-OS version to check upgrade readiness for. | Required |
#
Playbook OutputsPath | Description | Type |
---|---|---|
ReadinessChecks | List of upgrade readiness checks performed and their result (Passed/Failed). | unknown |