You cannot download PA-220 firmware from a public mirror. It requires a valid Support Contract and login credentials.
Firmware Baseline – PA-220 Edge Firewalls
All PA-220 units must remain on PAN-OS 10.1.6-h3 until Q3 2024 due to a critical CVE fix (CVSS 9.8) in the management web interface. pa-220 firmware
Auto-update: Disabled.
Approved upgrade path: Only via signed images from the Palo Alto Support Portal.
Next scheduled upgrade: November 2024 (to PAN-OS 11.0.2) You cannot download PA-220 firmware from a public mirror
Even with perfect planning, things go wrong. Here are the top PA-220 firmware issues and fixes. Auto-update: Disabled
You have three methods: GUI (Web Interface), CLI, or Panorama. We will cover the most common method: GUI.
To extend the life of your PA-220:
If you need the latest threat prevention signatures or cloud-delivered security features, you will need to move to PAN-OS 10.1 or 10.2.