<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Asking for best practice regarding editing multiple interfaces of a FW HA pair which is managed by Panorama in Panorama Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/panorama-discussions/asking-for-best-practice-regarding-editing-multiple-interfaces/m-p/534138#M1407</link>
    <description>&lt;P&gt;Works like charm. Thanks Tom.&lt;/P&gt;</description>
    <pubDate>Mon, 13 Mar 2023 05:39:18 GMT</pubDate>
    <dc:creator>Yevgeny_Libov</dc:creator>
    <dc:date>2023-03-13T05:39:18Z</dc:date>
    <item>
      <title>Asking for best practice regarding editing multiple interfaces of a FW HA pair which is managed by Panorama</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/asking-for-best-practice-regarding-editing-multiple-interfaces/m-p/533944#M1400</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;We have a FW HA pair which we want to put under Panorama's management.&lt;BR /&gt;However, this pair will have to undergo interfaces editing in a few weeks - putting individual interfaces in aggregate interfaces.&lt;BR /&gt;If there was no Panorama, I would have edited the FW settings via CLI, commited, and it would have got replicated to the other FW.&lt;/P&gt;
&lt;P&gt;I have some experience with Panorama and FW HA management. The templates of each node would be placed under the same template stack.&lt;BR /&gt;When working Panorama what I want to do with the interfaces might be more challenging as the settings must be edited on the templates.&lt;/P&gt;
&lt;P&gt;My questions are:&lt;BR /&gt;• Should I edit each FW template separately, commit to panorama and push to devices? I assume this would be most labor intense but the cleanest. This is very inconvenient and time consuming, of course. &lt;BR /&gt;• Is there a way to edit interfaces on the primary FW node, and push it to update Panorama template settings? I assume that not.&lt;BR /&gt;• Is it recommended in a case of HA pair to completely remove network management from Panorama?&lt;/P&gt;
&lt;P&gt;I'm asking for a good solution.&lt;BR /&gt;Than you.&lt;/P&gt;</description>
      <pubDate>Fri, 10 Mar 2023 10:41:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/asking-for-best-practice-regarding-editing-multiple-interfaces/m-p/533944#M1400</guid>
      <dc:creator>Yevgeny_Libov</dc:creator>
      <dc:date>2023-03-10T10:41:35Z</dc:date>
    </item>
    <item>
      <title>Re: Asking for best practice regarding editing multiple interfaces of a FW HA pair which is managed by Panorama</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/asking-for-best-practice-regarding-editing-multiple-interfaces/m-p/533948#M1401</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/278524"&gt;@Yevgeny_Libov&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Here is a good document on migrating a standalone HA pair to Panorama -&amp;gt; &lt;A href="https://docs.paloaltonetworks.com/panorama/10-2/panorama-admin/manage-firewalls/transition-a-firewall-to-panorama-management/migrate-a-firewall-ha-pair-to-panorama-management" target="_blank"&gt;https://docs.paloaltonetworks.com/panorama/10-2/panorama-admin/manage-firewalls/transition-a-firewall-to-panorama-management/migrate-a-firewall-ha-pair-to-panorama-management&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;There are some best practices that we can learn from it.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Should I edit each FW template separately?&amp;nbsp; HA pairs should be in one template to guarantee the same config on both.&amp;nbsp; You can manage IP addresses for HA connections locally as the doc says or use template variables.&lt;/LI&gt;
&lt;LI&gt;Is there a way to edit interfaces on the primary FW node, and push it to update Panorama template settings?&amp;nbsp; You can do this when you initially add the NGFWs to Panorama.&amp;nbsp; After that, the config is the same, regardless of Panorama or local.&lt;/LI&gt;
&lt;LI&gt;Is it recommended in a case of HA pair to completely remove network management from Panorama?&amp;nbsp; No.&amp;nbsp; HA pairs can be easily managed from Panorama.&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;Here are a few things to consider:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Config sync can be enabled after the pair is added to Panorama.&amp;nbsp; Then local changes will be synchronized.&amp;nbsp; Panorama changes are pushed to each NGFW individually and not synced.&lt;/LI&gt;
&lt;LI&gt;You will need to decide:
&lt;UL class="lia-list-style-type-circle"&gt;
&lt;LI&gt;Will you also managed Network and Device config from Panorama?&amp;nbsp; If so, don't skip the Force Template values step.&amp;nbsp; Also, enable Automated Commit Recovery 1st.&lt;/LI&gt;
&lt;LI&gt;What settings will be managed locally?&amp;nbsp; The management interface is an obvious example.&amp;nbsp; I like managing everything else from Panorama.&lt;/LI&gt;
&lt;LI&gt;What settings will be common across other NGFWs?&amp;nbsp; This will determine device group hierarchy and template stack configurations.&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;The Beacon free course Managing Firewalls at Scale has some excellent guidance on the last bullet.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;</description>
      <pubDate>Fri, 10 Mar 2023 11:56:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/asking-for-best-practice-regarding-editing-multiple-interfaces/m-p/533948#M1401</guid>
      <dc:creator>TomYoung</dc:creator>
      <dc:date>2023-03-10T11:56:51Z</dc:date>
    </item>
    <item>
      <title>Re: Asking for best practice regarding editing multiple interfaces of a FW HA pair which is managed by Panorama</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/asking-for-best-practice-regarding-editing-multiple-interfaces/m-p/533960#M1402</link>
      <description>&lt;P&gt;Hi Tom, many thanks.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I've followed the manual before and an additional manual for adding the HA pair, but haven't followed in the correct order.&lt;BR /&gt;I will try to follow this one step by step (and take what is necessary from the one which instructs how to use variables).&lt;BR /&gt;&lt;BR /&gt;I would like to know your opinion on how to manage network settings from Panorama for an HA pair (Active-Passive). I didn't find it in your answer or the guide.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;Under STEP 7, section 6: "Select the template stack for the first firewall, add the second firewall, select OK&lt;BR /&gt;and Commit to Panorama to add it to the same template stack as the HA peer."&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;This step adds both device templates under the same template stack.&lt;BR /&gt;However, how do I manage the network settings? When I was experimenting with this, when in Panorama I attempted to change network settings under template stack, I have had limited edit options, or it was in a Read Only state.&lt;BR /&gt;I had to select the FW template in order to have full edit capability, so here I wander: Should I edit each device template separately?&lt;BR /&gt;This doesn't make sense and I'm probably missing something.&lt;/P&gt;
&lt;P&gt;About managing the HA from Device Groups when both FW are associated under the the device groups, this works well.&lt;BR /&gt;&lt;BR /&gt;Edit: I think I partly understand what I've been missing:&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="ph cmd"&gt;"Select the template stack for the first firewall, add the second firewall, select &lt;/SPAN&gt;OK &lt;SPAN class="ph cmd"&gt;and &lt;/SPAN&gt;Commit to Panorama &lt;LI-WRAPPER&gt;&lt;SPAN class="ph cmd"&gt;to add it to the same template stack as the HA peer."&lt;BR /&gt;I want to understand please: The end result of this is a single template stack with both devices added, and a single template assigned to it, which belongs to one of the devices, right?&lt;BR /&gt;&lt;/SPAN&gt;&lt;/LI-WRAPPER&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 10 Mar 2023 15:15:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/asking-for-best-practice-regarding-editing-multiple-interfaces/m-p/533960#M1402</guid>
      <dc:creator>Yevgeny_Libov</dc:creator>
      <dc:date>2023-03-10T15:15:17Z</dc:date>
    </item>
    <item>
      <title>Re: Asking for best practice regarding editing multiple interfaces of a FW HA pair which is managed by Panorama</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/asking-for-best-practice-regarding-editing-multiple-interfaces/m-p/533966#M1403</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/278524"&gt;@Yevgeny_Libov&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You wrote "This step adds both device templates under the same template stack."&amp;nbsp; This is incorrect.&amp;nbsp; The step actually adds both devices to&amp;nbsp;&lt;EM&gt;different&lt;/EM&gt; template stacks.&amp;nbsp; Once you are done with the steps in the document, you can actually &lt;EM&gt;delete&lt;/EM&gt; the device group, template, and template stack created by importing the 2nd NGFW (step 7 #2 and #5).&amp;nbsp; &lt;STRONG&gt;At the end of the document, you should have both NGFWs in 1 template stack with 1 template.&lt;/STRONG&gt;&amp;nbsp; You do not need separate templates for each NGFW in an HA pair.&amp;nbsp; Unique settings such as management IP or HA link IPs should be (1) managed locally (no config in Panorama), (2) overridden locally, or (3) use template variables.&amp;nbsp; Everything else should be the same.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Correct.&amp;nbsp; The device is associated with the template stack, and not the template.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Apr 2023 10:51:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/asking-for-best-practice-regarding-editing-multiple-interfaces/m-p/533966#M1403</guid>
      <dc:creator>TomYoung</dc:creator>
      <dc:date>2023-04-21T10:51:49Z</dc:date>
    </item>
    <item>
      <title>Re: Asking for best practice regarding editing multiple interfaces of a FW HA pair which is managed by Panorama</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/asking-for-best-practice-regarding-editing-multiple-interfaces/m-p/534011#M1405</link>
      <description>&lt;P&gt;Hi Tom,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Yes, you are right. I continued researching this and editing my reply, and between my edits you made this comment.&lt;BR /&gt;Thank you for correcting me while I was making my mind &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;I will follow up the steps and add the HA to Panorama at the beginning of next week and will report on results.&lt;/P&gt;</description>
      <pubDate>Fri, 10 Mar 2023 20:09:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/asking-for-best-practice-regarding-editing-multiple-interfaces/m-p/534011#M1405</guid>
      <dc:creator>Yevgeny_Libov</dc:creator>
      <dc:date>2023-03-10T20:09:20Z</dc:date>
    </item>
    <item>
      <title>Re: Asking for best practice regarding editing multiple interfaces of a FW HA pair which is managed by Panorama</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/asking-for-best-practice-regarding-editing-multiple-interfaces/m-p/534138#M1407</link>
      <description>&lt;P&gt;Works like charm. Thanks Tom.&lt;/P&gt;</description>
      <pubDate>Mon, 13 Mar 2023 05:39:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/asking-for-best-practice-regarding-editing-multiple-interfaces/m-p/534138#M1407</guid>
      <dc:creator>Yevgeny_Libov</dc:creator>
      <dc:date>2023-03-13T05:39:18Z</dc:date>
    </item>
  </channel>
</rss>

