<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: HA on a PA-450 using Strata Cloud Manager in Next-Generation Firewall Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/ha-on-a-pa-450-using-strata-cloud-manager/m-p/616340#M4968</link>
    <description>&lt;P&gt;I am writing a reply to this, because I REALLY tried to follow along with the steps, but could not understand.&lt;/P&gt;
&lt;P&gt;I needed to open a TAC case to get this simple configuration done.&amp;nbsp; (Argh, if only tech documentation could be written much clearer. :P)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;So, in basic terms, create your folder structure as you would for NGFW FWs.&lt;/P&gt;
&lt;P&gt;For me, I ignore putting anything in the highest (parent) folder of &lt;STRONG&gt;All Firewalls.&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I created a folder (&lt;STRONG&gt;LIB Firewalls&lt;/STRONG&gt;) in SCM, and put 2 FWs in that folder (FW-A and FW-B)&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="SCantwell_0-1730984764522.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/63843iE1A4352B39A26A72/image-size/medium?v=v2&amp;amp;px=400" role="button" title="SCantwell_0-1730984764522.png" alt="SCantwell_0-1730984764522.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;I created my variable and interfaces in the parent &lt;STRONG&gt;LIB Firewalls&lt;/STRONG&gt; folder. (not shown here)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;But real clarification is to go to the actual FW-DEVICE (&lt;STRONG&gt;FW-A and FW-B&lt;/STRONG&gt;).&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="SCantwell_1-1730984808101.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/63844i8C29C22315C88842/image-size/medium?v=v2&amp;amp;px=400" role="button" title="SCantwell_1-1730984808101.png" alt="SCantwell_1-1730984808101.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This is my "before" picture&amp;nbsp; (I want to have eth1/3 and eth1/4 used for HA)&amp;nbsp; &lt;/P&gt;
&lt;P&gt;Notice that eth 3 and eth 4 show as Not Configured.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="SCantwell_2-1730984845856.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/63845i603F6CFD512CE6C2/image-size/medium?v=v2&amp;amp;px=400" role="button" title="SCantwell_2-1730984845856.png" alt="SCantwell_2-1730984845856.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I clicked on ethernet1/3&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="SCantwell_3-1730984916648.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/63846iD093395C6FEAC772/image-size/medium?v=v2&amp;amp;px=400" role="button" title="SCantwell_3-1730984916648.png" alt="SCantwell_3-1730984916648.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;When you add your interfaces (which will be only for HA in my example ), you are presented with the &lt;STRONG&gt;ADD&lt;/STRONG&gt; Ethernet window,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="SCantwell_4-1730984953665.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/63847i0D3C12C64AA6E64B/image-size/medium?v=v2&amp;amp;px=400" role="button" title="SCantwell_4-1730984953665.png" alt="SCantwell_4-1730984953665.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;(Viola!) this is where you see the mysterious Interface Type with a radio button of Default.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You do not need to do anything anything, just hit OK, and the interface is now created (in the device folder itself).&amp;nbsp; &lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Do this for your 2nd interface...and......&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;(This is my "after".&amp;nbsp; Notice that now eth 3 and eth 4 currently show Auto (for Link Status)&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="SCantwell_5-1730985007818.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/63848i7B6EAE725BFF7760/image-size/medium?v=v2&amp;amp;px=400" role="button" title="SCantwell_5-1730985007818.png" alt="SCantwell_5-1730985007818.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Now you can come back to Configuration Scope for the parent folder (&lt;STRONG&gt;LIB Firewalls) &lt;/STRONG&gt;and finish your configuration for HA with variables or IPs or whatever you need.&lt;BR /&gt;&lt;BR /&gt;Thanks to Rae A (at TAC), who was wonderful and helped me in about 3 minutes.&amp;nbsp; &lt;span class="lia-unicode-emoji" title=":face_with_tongue:"&gt;😛&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 07 Nov 2024 13:14:59 GMT</pubDate>
    <dc:creator>S.Cantwell</dc:creator>
    <dc:date>2024-11-07T13:14:59Z</dc:date>
    <item>
      <title>HA on a PA-450 using Strata Cloud Manager</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/ha-on-a-pa-450-using-strata-cloud-manager/m-p/595753#M3622</link>
      <description>&lt;P&gt;I’m attempting to configure active/passive HA on a PA-450 using Strata Cloud Manager as per this guide: &lt;A href="https://docs.paloaltonetworks.com/ngfw/administration/high-availability/set-up-activepassive-ha/configure-active-passive-ha" target="_blank"&gt;https://docs.paloaltonetworks.com/ngfw/administration/high-availability/set-up-activepassive-ha/configure-active-passive-ha&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;I’m aware a PA-450 doesn’t have dedicated HA ports, however when using Panorama I can set Eth1/7 &amp;amp; Eth1/8 to HA mode as shown in the image below and it works fine:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="JamesWoodhouse1_0-1724423694145.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/61688iA34AAA342FF58D85/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="JamesWoodhouse1_0-1724423694145.png" alt="JamesWoodhouse1_0-1724423694145.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;When using Strata Cloud Manager, HA mode is not an option on interface configuration.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="JamesWoodhouse1_1-1724423694146.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/61689iCEE3F611D7878AB7/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="JamesWoodhouse1_1-1724423694146.png" alt="JamesWoodhouse1_1-1724423694146.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Using the Strata HA workflow, I’m able to set HA-1 to use the management interface, but then unable to list data interfaces as candidate for HA-2,&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="JamesWoodhouse1_2-1724423694148.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/61690iDF98C2DFC2A06C43/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="JamesWoodhouse1_2-1724423694148.png" alt="JamesWoodhouse1_2-1724423694148.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I’ve ensured that data interfaces are configured and set to L3 mode on each firewall in the pair.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;Does anyone have any experience with this please?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 23 Aug 2024 14:36:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/ha-on-a-pa-450-using-strata-cloud-manager/m-p/595753#M3622</guid>
      <dc:creator>James.Woodhouse1</dc:creator>
      <dc:date>2024-08-23T14:36:35Z</dc:date>
    </item>
    <item>
      <title>Re: HA on a PA-450 using Strata Cloud Manager</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/ha-on-a-pa-450-using-strata-cloud-manager/m-p/595767#M3624</link>
      <description>&lt;P&gt;The 'Interface Type' needs to be Default to be used for HA configuration in SCM. This needs to be configured in SCM at the Configuration Scope of each HA firewall.&lt;/P&gt;
&lt;P&gt;That is what worked for me.&lt;/P&gt;</description>
      <pubDate>Fri, 23 Aug 2024 16:13:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/ha-on-a-pa-450-using-strata-cloud-manager/m-p/595767#M3624</guid>
      <dc:creator>MikeFreyman-WWT</dc:creator>
      <dc:date>2024-08-23T16:13:23Z</dc:date>
    </item>
    <item>
      <title>Re: HA on a PA-450 using Strata Cloud Manager</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/ha-on-a-pa-450-using-strata-cloud-manager/m-p/595786#M3626</link>
      <description>&lt;P&gt;Thanks Mike, I'll try that next week.&lt;BR /&gt;Just to confirm is the Interface type 'default' only for the interfaces intended for HA-1 &amp;amp; HA-2, or ALL other data interfaces as well?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 23 Aug 2024 17:22:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/ha-on-a-pa-450-using-strata-cloud-manager/m-p/595786#M3626</guid>
      <dc:creator>James.Woodhouse1</dc:creator>
      <dc:date>2024-08-23T17:22:37Z</dc:date>
    </item>
    <item>
      <title>Re: HA on a PA-450 using Strata Cloud Manager</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/ha-on-a-pa-450-using-strata-cloud-manager/m-p/595789#M3627</link>
      <description>&lt;P&gt;Just the interfaces you want to use for HA.&lt;/P&gt;</description>
      <pubDate>Fri, 23 Aug 2024 17:46:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/ha-on-a-pa-450-using-strata-cloud-manager/m-p/595789#M3627</guid>
      <dc:creator>MikeFreyman-WWT</dc:creator>
      <dc:date>2024-08-23T17:46:03Z</dc:date>
    </item>
    <item>
      <title>Re: HA on a PA-450 using Strata Cloud Manager</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/ha-on-a-pa-450-using-strata-cloud-manager/m-p/596050#M3647</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/1320516705"&gt;@MikeFreyman-WWT&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;Thanks for the help, I finally got this working today after a bit of a journey!&lt;BR /&gt;(I'm attempting to use folders/snippets and variables from Day1)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Journey:&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Create 'base' snippet (interfaces, zones, router, &lt;U&gt;but excluding HA&lt;/U&gt;) and apply to top level 'branch' configuration scope
&lt;UL&gt;
&lt;LI&gt;Override variables on the firewall configuration scope&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Create 'HA' snippet for HA interfaces with the aim of applying on the firewall configuration scope
&lt;UL&gt;
&lt;LI&gt;&lt;FONT color="#FF0000"&gt;unable to set interface type to 'default' in snippet&lt;/FONT&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;FONT color="#FF0000"&gt;delete Snippet&lt;/FONT&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Set interfaces to 'default' at the firewall configuration scope&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Create variables in 'All firewalls' configuration scope (with the aim of using on the firewall configuration scope) for:
&lt;UL&gt;
&lt;LI&gt;$eth1-7-ip-ha&lt;/LI&gt;
&lt;LI&gt;$eth1-7-ip-subnet-mask-ha&lt;/LI&gt;
&lt;LI&gt;$eth1-8-ip-ha&lt;/LI&gt;
&lt;LI&gt;$eth1-8-ip-subnet-mask-ha&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Override variable values at the firewall configuration scope&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Create HA Group, PUSH
&lt;UL&gt;
&lt;LI&gt;&lt;FONT color="#FF0000"&gt;Receive Error, assuming due using one variable value (IP address) and applying to both HA peers&lt;/FONT&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Delete HA group&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Verify:&amp;nbsp; 'base' snippet (interfaces, zones, router) and apply to top level 'branch' configuration scope = yes )&lt;/LI&gt;
&lt;LI&gt;Verify: variable values for data interfaces applied at 'site' configuration scope = yes )&lt;/LI&gt;
&lt;LI&gt;Verify: HA interfaces [Eth1/7 &amp;amp; Eth1/8]&amp;nbsp; applied a 'firewall' configuration scope = yes)&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Create variables in 'All firewalls' configuration scope
&lt;UL&gt;
&lt;LI&gt;$eth1-7-ip-ha-branch1&lt;/LI&gt;
&lt;LI&gt;$eth1-8-ip-ha-branch1&lt;/LI&gt;
&lt;LI&gt;$eth1-7-ip-ha-branch2&lt;/LI&gt;
&lt;LI&gt;$eth1-8-ip-ha-branch2&lt;/LI&gt;
&lt;LI&gt;$eth1-7_8-ip-subnet-mask-ha-branch-all&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Create HA, &lt;FONT color="#FF0000"&gt;&lt;FONT color="#FF0000"&gt;received error upon (again assuming) using one variable [$eth1-7_8-ip-subnet-mask-ha-branch-all] in multiple [x4] places [HA control &amp;amp; data interfaces]&lt;BR /&gt;&lt;BR /&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="JamesWoodhouse1_0-1724770662336.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/61761i5A991F9A5AD76213/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="JamesWoodhouse1_0-1724770662336.png" alt="JamesWoodhouse1_0-1724770662336.png" /&gt;&lt;/span&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Delete HA group&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Delete variables in 'All firewalls' configuration scope
&lt;UL&gt;
&lt;LI&gt;$eth1-7_8-ip-subnet-mask-ha-branch-all&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Create variables in 'All firewalls' configuration scope
&lt;UL&gt;
&lt;LI&gt;$eth1-7-ip-subnet-mask-ha-branch1&lt;/LI&gt;
&lt;LI&gt;$eth1-8-ip-subnet-mask-ha-branch1&lt;/LI&gt;
&lt;LI&gt;$eth1-7-ip-subnet-mask-ha-branch2&lt;/LI&gt;
&lt;LI&gt;$eth1-8-ip-subnet-mask-ha-branch2&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Create HA, &lt;FONT color="#FF0000"&gt;error received again&lt;/FONT&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Convert Subnet masks to manual [255.255.255.252] e.g. not using variable), but retain variable for IPv4 address [ e.g. $eth1-7-ip-ha-branch1]&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Push, &lt;FONT color="#339966"&gt;Success&lt;/FONT&gt; !&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 27 Aug 2024 15:00:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/ha-on-a-pa-450-using-strata-cloud-manager/m-p/596050#M3647</guid>
      <dc:creator>James.Woodhouse1</dc:creator>
      <dc:date>2024-08-27T15:00:48Z</dc:date>
    </item>
    <item>
      <title>Re: HA on a PA-450 using Strata Cloud Manager</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/ha-on-a-pa-450-using-strata-cloud-manager/m-p/616340#M4968</link>
      <description>&lt;P&gt;I am writing a reply to this, because I REALLY tried to follow along with the steps, but could not understand.&lt;/P&gt;
&lt;P&gt;I needed to open a TAC case to get this simple configuration done.&amp;nbsp; (Argh, if only tech documentation could be written much clearer. :P)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;So, in basic terms, create your folder structure as you would for NGFW FWs.&lt;/P&gt;
&lt;P&gt;For me, I ignore putting anything in the highest (parent) folder of &lt;STRONG&gt;All Firewalls.&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I created a folder (&lt;STRONG&gt;LIB Firewalls&lt;/STRONG&gt;) in SCM, and put 2 FWs in that folder (FW-A and FW-B)&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="SCantwell_0-1730984764522.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/63843iE1A4352B39A26A72/image-size/medium?v=v2&amp;amp;px=400" role="button" title="SCantwell_0-1730984764522.png" alt="SCantwell_0-1730984764522.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;I created my variable and interfaces in the parent &lt;STRONG&gt;LIB Firewalls&lt;/STRONG&gt; folder. (not shown here)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;But real clarification is to go to the actual FW-DEVICE (&lt;STRONG&gt;FW-A and FW-B&lt;/STRONG&gt;).&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="SCantwell_1-1730984808101.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/63844i8C29C22315C88842/image-size/medium?v=v2&amp;amp;px=400" role="button" title="SCantwell_1-1730984808101.png" alt="SCantwell_1-1730984808101.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This is my "before" picture&amp;nbsp; (I want to have eth1/3 and eth1/4 used for HA)&amp;nbsp; &lt;/P&gt;
&lt;P&gt;Notice that eth 3 and eth 4 show as Not Configured.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="SCantwell_2-1730984845856.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/63845i603F6CFD512CE6C2/image-size/medium?v=v2&amp;amp;px=400" role="button" title="SCantwell_2-1730984845856.png" alt="SCantwell_2-1730984845856.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I clicked on ethernet1/3&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="SCantwell_3-1730984916648.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/63846iD093395C6FEAC772/image-size/medium?v=v2&amp;amp;px=400" role="button" title="SCantwell_3-1730984916648.png" alt="SCantwell_3-1730984916648.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;When you add your interfaces (which will be only for HA in my example ), you are presented with the &lt;STRONG&gt;ADD&lt;/STRONG&gt; Ethernet window,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="SCantwell_4-1730984953665.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/63847i0D3C12C64AA6E64B/image-size/medium?v=v2&amp;amp;px=400" role="button" title="SCantwell_4-1730984953665.png" alt="SCantwell_4-1730984953665.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;(Viola!) this is where you see the mysterious Interface Type with a radio button of Default.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You do not need to do anything anything, just hit OK, and the interface is now created (in the device folder itself).&amp;nbsp; &lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Do this for your 2nd interface...and......&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;(This is my "after".&amp;nbsp; Notice that now eth 3 and eth 4 currently show Auto (for Link Status)&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="SCantwell_5-1730985007818.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/63848i7B6EAE725BFF7760/image-size/medium?v=v2&amp;amp;px=400" role="button" title="SCantwell_5-1730985007818.png" alt="SCantwell_5-1730985007818.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Now you can come back to Configuration Scope for the parent folder (&lt;STRONG&gt;LIB Firewalls) &lt;/STRONG&gt;and finish your configuration for HA with variables or IPs or whatever you need.&lt;BR /&gt;&lt;BR /&gt;Thanks to Rae A (at TAC), who was wonderful and helped me in about 3 minutes.&amp;nbsp; &lt;span class="lia-unicode-emoji" title=":face_with_tongue:"&gt;😛&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 07 Nov 2024 13:14:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/ha-on-a-pa-450-using-strata-cloud-manager/m-p/616340#M4968</guid>
      <dc:creator>S.Cantwell</dc:creator>
      <dc:date>2024-11-07T13:14:59Z</dc:date>
    </item>
    <item>
      <title>Re: HA on a PA-450 using Strata Cloud Manager</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/ha-on-a-pa-450-using-strata-cloud-manager/m-p/1247462#M6657</link>
      <description>&lt;P&gt;For anyone that gets to the end of this thread and still sees no interfaces in the HA1 or HA2 Port pop-up menus, there appears to be a UI bug (among so very many) in Strata Cloud Manager. Click into the IPv4/IPv6 Address field below the HA1 Backup (Optional) Port field and enter any IP address (e.g. 1.1.1.1). Then erase it by clicking the X icon at the end of the field. This appears to force the UI to reevaluate the options available to it and your available interfaces will now show up from the pop-up menus. I'm not proud of how long it took me to figure this out, but at least I have a working HA config now. Thanks PA. =|&lt;/P&gt;</description>
      <pubDate>Wed, 04 Feb 2026 22:35:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/ha-on-a-pa-450-using-strata-cloud-manager/m-p/1247462#M6657</guid>
      <dc:creator>K.Allen598516</dc:creator>
      <dc:date>2026-02-04T22:35:09Z</dc:date>
    </item>
  </channel>
</rss>

