<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Firewall cloning for DR in Next-Generation Firewall Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/firewall-cloning-for-dr/m-p/539877#M1173</link>
    <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/238781"&gt;@Charlie80&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Yes, moving cluster 2 to the new device group and template will work.&amp;nbsp; The Policies and Objects will be replaced.&amp;nbsp; The Network and Device configuration may or may not be replaced.&amp;nbsp; It depends if anything is currently overridden on the NGFWs.&amp;nbsp; You may have to select Force Template Values.&amp;nbsp; You will get a warning that you may break connectivity because template have IP addresses, etc.&amp;nbsp; You should have Automated Commit Recovery enabled.&amp;nbsp; With any production cutover, you will need to do your due diligence to prevent outages.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Cluster 1 will not be impacted if you do not make any changes to the device group or templates.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;</description>
    <pubDate>Mon, 24 Apr 2023 09:17:04 GMT</pubDate>
    <dc:creator>TomYoung</dc:creator>
    <dc:date>2023-04-24T09:17:04Z</dc:date>
    <item>
      <title>Firewall cloning for DR</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/firewall-cloning-for-dr/m-p/539674#M1171</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;I have a Panorama that manage 2 cluster. Each one have a dedicated Device-Group and Template.&lt;/P&gt;
&lt;P&gt;Now the cluster 2 must be recycled as a DR of the cluster 1.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;My idea is to reassign the cluster 2 to the same DG and Templ of the cluster 1. Should works, right?&lt;/P&gt;
&lt;P&gt;As far as I know if I move the cluster 2 on the same DG/templ the Panorama "add" the new conf . How I can "force" to replace the entire conf with the Cluster 1conf on cluster 2? &lt;/P&gt;
&lt;P&gt;Am I forgetting something?&lt;/P&gt;
&lt;P&gt;There is any impact on the cluster 1 (like outage etc)?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Note. of course the Cluster 2 data plane interface will be moved in the DR Vlan to avoid the duplicated address&lt;/P&gt;</description>
      <pubDate>Fri, 21 Apr 2023 08:18:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/firewall-cloning-for-dr/m-p/539674#M1171</guid>
      <dc:creator>Charlie80</dc:creator>
      <dc:date>2023-04-21T08:18:39Z</dc:date>
    </item>
    <item>
      <title>Re: Firewall cloning for DR</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/firewall-cloning-for-dr/m-p/539877#M1173</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/238781"&gt;@Charlie80&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Yes, moving cluster 2 to the new device group and template will work.&amp;nbsp; The Policies and Objects will be replaced.&amp;nbsp; The Network and Device configuration may or may not be replaced.&amp;nbsp; It depends if anything is currently overridden on the NGFWs.&amp;nbsp; You may have to select Force Template Values.&amp;nbsp; You will get a warning that you may break connectivity because template have IP addresses, etc.&amp;nbsp; You should have Automated Commit Recovery enabled.&amp;nbsp; With any production cutover, you will need to do your due diligence to prevent outages.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Cluster 1 will not be impacted if you do not make any changes to the device group or templates.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;</description>
      <pubDate>Mon, 24 Apr 2023 09:17:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/firewall-cloning-for-dr/m-p/539877#M1173</guid>
      <dc:creator>TomYoung</dc:creator>
      <dc:date>2023-04-24T09:17:04Z</dc:date>
    </item>
  </channel>
</rss>

