<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>article Nominated Discussion: How to Replace a FW in an A/P Cluster in General Articles</title>
    <link>https://live.paloaltonetworks.com/t5/general-articles/nominated-discussion-how-to-replace-a-fw-in-an-a-p-cluster/ta-p/533176</link>
    <description>&lt;DIV class="lia-message-template-content-zone"&gt;
&lt;P&gt;&lt;SPAN&gt;This Nominated Discussion Article is based on the post "&lt;/SPAN&gt;&lt;FONT color="#FF6600"&gt;&lt;STRONG&gt;&lt;A href="https://live.paloaltonetworks.com/t5/general-topics/adding-a-firewall-back-into-a-ap-cluster-that-has-outdated/m-p/533131" target="_blank" rel="noopener"&gt;Adding a firewall back into a AP cluster that has outdated network and device settings&lt;/A&gt;&lt;/STRONG&gt;&lt;/FONT&gt;&lt;SPAN&gt;" by&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/163507"&gt;@AlanDeBoer&lt;/a&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp; and responded to by &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/15603"&gt;@Raido_Rattameister&lt;/a&gt;&lt;/SPAN&gt;&lt;SPAN&gt;. Read on to see the solution!&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;Hi All,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'm curious if anyone can provide an article or just some basic steps of adding a firewall back into a AP cluster that has "outdated" network and device settings.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Firewall-02 was moved to a new location and has a new IP scheme for the network and device settings.&lt;/P&gt;
&lt;P&gt;Firewall-01 will be physically moved and needs to rejoin the cluster, but it does have outdated IP settings.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'm assuming the first step is to power up 01 without any copper/fiber connected and console into 01 and update the device management IP first.&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;P&gt;Solution:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Step 1 - Take config backup from both firewalls (Device &amp;gt; Setup &amp;gt; Operations).&lt;/P&gt;
&lt;P&gt;Step 2 - Make sure that "Device Priority" of&amp;nbsp;&lt;SPAN&gt;Firewall-02 is lower than&amp;nbsp;Firewall-01 to make sure&amp;nbsp;Firewall-02 stays active firewall.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Step 3 - Cabling (at minimum HA1 cable).&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Step 4 - Click "Sync to peer" in Firewall-02 (Dashboard &amp;gt; High Availability widget).&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;If you click "Sync to peer" on&amp;nbsp;Firewall-01 you will push old nic scheme from&amp;nbsp;Firewall-01 to&amp;nbsp;Firewall-02 and your network will go down!&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;In addition, mgmt IP change as you pointed out.&lt;/SPAN&gt;&lt;/P&gt;
&lt;/DIV&gt;</description>
    <pubDate>Fri, 03 Mar 2023 21:04:07 GMT</pubDate>
    <dc:creator>JayGolf</dc:creator>
    <dc:date>2023-03-03T21:04:07Z</dc:date>
    <item>
      <title>Nominated Discussion: How to Replace a FW in an A/P Cluster</title>
      <link>https://live.paloaltonetworks.com/t5/general-articles/nominated-discussion-how-to-replace-a-fw-in-an-a-p-cluster/ta-p/533176</link>
      <description>&lt;DIV class="lia-message-template-content-zone"&gt;
&lt;P&gt;&lt;SPAN&gt;This Nominated Discussion Article is based on the post "&lt;/SPAN&gt;&lt;FONT color="#FF6600"&gt;&lt;STRONG&gt;&lt;A href="https://live.paloaltonetworks.com/t5/general-topics/adding-a-firewall-back-into-a-ap-cluster-that-has-outdated/m-p/533131" target="_blank" rel="noopener"&gt;Adding a firewall back into a AP cluster that has outdated network and device settings&lt;/A&gt;&lt;/STRONG&gt;&lt;/FONT&gt;&lt;SPAN&gt;" by&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/163507"&gt;@AlanDeBoer&lt;/a&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp; and responded to by &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/15603"&gt;@Raido_Rattameister&lt;/a&gt;&lt;/SPAN&gt;&lt;SPAN&gt;. Read on to see the solution!&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;Hi All,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'm curious if anyone can provide an article or just some basic steps of adding a firewall back into a AP cluster that has "outdated" network and device settings.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Firewall-02 was moved to a new location and has a new IP scheme for the network and device settings.&lt;/P&gt;
&lt;P&gt;Firewall-01 will be physically moved and needs to rejoin the cluster, but it does have outdated IP settings.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'm assuming the first step is to power up 01 without any copper/fiber connected and console into 01 and update the device management IP first.&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;P&gt;Solution:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Step 1 - Take config backup from both firewalls (Device &amp;gt; Setup &amp;gt; Operations).&lt;/P&gt;
&lt;P&gt;Step 2 - Make sure that "Device Priority" of&amp;nbsp;&lt;SPAN&gt;Firewall-02 is lower than&amp;nbsp;Firewall-01 to make sure&amp;nbsp;Firewall-02 stays active firewall.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Step 3 - Cabling (at minimum HA1 cable).&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Step 4 - Click "Sync to peer" in Firewall-02 (Dashboard &amp;gt; High Availability widget).&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;If you click "Sync to peer" on&amp;nbsp;Firewall-01 you will push old nic scheme from&amp;nbsp;Firewall-01 to&amp;nbsp;Firewall-02 and your network will go down!&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;In addition, mgmt IP change as you pointed out.&lt;/SPAN&gt;&lt;/P&gt;
&lt;/DIV&gt;</description>
      <pubDate>Fri, 03 Mar 2023 21:04:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-articles/nominated-discussion-how-to-replace-a-fw-in-an-a-p-cluster/ta-p/533176</guid>
      <dc:creator>JayGolf</dc:creator>
      <dc:date>2023-03-03T21:04:07Z</dc:date>
    </item>
  </channel>
</rss>

