Product

Everything Night Agent does

One tool for every way you run Palo Alto — from a single branch firewall to a Panorama-managed estate — with the checks, backups and reporting that make an upgrade defensible after the fact.

Upgrade modes

Pick the shape of your deployment

Each mode runs the sequence appropriate to it. An HA pair is not a single firewall run twice, and Panorama is not a firewall at all.

Single firewall

A standalone, non-HA firewall from start to finish.

Pre-flight checks, config backup, pre-upgrade snapshot, content update, software upgrade with reboot, then a post-upgrade snapshot and comparison.

Optional pre-checks Content update included Live progress with streaming log

HA pair (active/passive)

Both units, in the right order, with preemption handled.

Preemption is disabled for the duration and restored afterwards. The primary is upgraded first and must rejoin and re-sync before the secondary is touched, so one unit is always passing traffic.

Pre-checks on both units, side by side Configurable wait between units Preemption restored automatically

Azure VM-Series HA

The same flow, plus the Azure public-IP cutover.

On Azure the public IP moves with the active unit. Night Agent verifies the firewall can authenticate to Azure, then waits for the IP re-association to finish before continuing — not just for PAN-OS failover.

Azure HA credential test in pre-checks Waits for real IP cutover Configurable failover timeout

Multi-firewall batch

Many firewalls, sequential or in parallel.

Add a list of firewalls, run pre-checks across all of them, then upgrade one at a time with optional stop-on-failure, or in parallel with a concurrency limit.

Parallel or sequential Stop-on-failure option Per-device status table

Panorama

The management appliance itself, single or HA.

Panorama has no dataplane and no vsys, so it gets its own check set: managed-device connectivity, log collectors, free space on the image partition, and HA state. Managed firewalls keep passing traffic throughout.

Purpose-built Panorama checks Managed devices verified before and after HA pairs supported

Pre-flight checks

What gets verified before anything changes

Checks run first and can stop the upgrade. You can also run them on their own, any time, without committing to an upgrade — useful the week before a maintenance window.

On a firewall

  • NTP synchronisation
  • Candidate configuration state
  • Expired licenses and support status
  • Active jobs and configuration locks
  • Management and dataplane CPU
  • Control and data plane clock sync
  • Dynamic update status
  • Free disk space for the target image
  • Upgrade path validity
  • Known vulnerabilities in the current version

On a Panorama

A Panorama has no dataplane and no vsys, so most firewall checks simply don't apply. It gets its own set rather than a borrowed one.

  • Confirms the target really is a Panorama
  • Managed device connectivity
  • HA state
  • NTP sync, candidate config, active jobs, CPU
  • Log collector connectivity (advisory)
  • Free space on the image partition (advisory)
  • Managed device version spread (advisory)

Free space is measured in gigabytes, not percent

A partition sitting at 78 percent used sounds fine and can still be far too small for a 600–900 MB image. Night Agent checks the actual free space against the actual image, which is the number that decides whether the download succeeds.

Day to day

The parts you use between upgrades

Device inventory

Save the firewalls you manage — nickname, client, role, HA pairing — so you're not retyping IPs. Credentials are optional and encrypted at rest.

Scheduling

Queue an upgrade for a maintenance window in your own time zone. Daylight saving is handled per region, not by the server clock.

Email notifications

Get told when a run starts, when it finishes, and — critically — when it's paused waiting on you to confirm something.

Live status

A phase stepper and a streaming log, so you can see which step is running and what the device actually said.

Run history

Every run kept with its status, duration, logs and downloadable snapshots. Re-open any past upgrade's report.

Cancel and confirm

Abort a run in progress. When something needs a human decision, the run pauses and waits for you instead of guessing.

The hard parts

Where hand-rolled upgrade scripts break

These are the failure modes that cost you a maintenance window. Each one is handled explicitly.

PAN-OS closes your API session mid-install

Long installs routinely outlive the session that started them. A naive script sees the connection drop and reports failure on an upgrade that is actually running fine. Night Agent reconnects, finds the job again, and keeps tracking it through the reboot.

A job that is pending is not a job that is finished

PAN-OS reports three job states, and only one of them means done. Treating "pending" as complete ends the wait early and reboots into an unfinished install. Night Agent waits for the real terminal state.

Retries that track the wrong job

After a retry there are two install jobs on the device, and the older one failed. Matching the first result you find reports the failure again. Night Agent always follows the newest job.

HA preemption at the worst moment

Preemption is disabled before the upgrade begins and restored afterwards — but only if it was enabled to start with, so a pair that intentionally runs without it stays that way.

Azure failover isn't finished when PAN-OS says so

On VM-Series the public IP has to move at the Azure layer too. Night Agent waits for that re-association to actually complete rather than assuming it followed the HA state change.

Something genuinely needs a human

When a decision can't be made safely on your behalf, the run pauses and emails you instead of guessing. It waits an hour, then fails cleanly rather than hanging forever.

See Night Agent on your own firewalls

Enter your email and we'll send you a license key and a download link straight away. No sales call, no card.

Start your free trial

14-day trial · No card required