<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Panorama-Local Config Merge in HA in Panorama Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/panorama-discussions/panorama-local-config-merge-in-ha/m-p/555540#M1788</link>
    <description>&lt;P&gt;We have a project to clean up the Panorama environment in order to manage changes from Panorama as much as possible. We have a pair of 3020 in A/P HA, already synced to Panorama with some local overrides. I performed the exact steps recommended by Palo on another HA set and it failed initially but was eventually fixed once we figured that "force template values" and sending to both firewalls will make them exactly the same as each other, HA and all. We did it this way:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Followed KB article:&amp;nbsp;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g0000008UIPCA2" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g0000008UIPCA2&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;Performed the steps for both firewalls in tandem, added them to new device group and template, forced template values for the last step, committed/pushed, and ended up with two identical firewalls. We updated HA settings to get them back online and synced.&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;What would be the recommended approach so we don't end up with the same issue? I'm thinking the following:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Turn off HA sync on both firewalls before going through the article steps.&lt;/LI&gt;
&lt;LI&gt;Per article, add both devices to Panorama device group and template but bypass steps 8 and 9 for the passive firewall.&lt;/LI&gt;
&lt;LI&gt;Finish steps 8 and 9 for the active firewall, export config bundle, then commit/push config to only the active firewall.&lt;/LI&gt;
&lt;LI&gt;Log into both firewalls, make sure MGMT and HA settings are different, re-enable sync and allow active to sync or force sync.&lt;/LI&gt;
&lt;/UL&gt;</description>
    <pubDate>Mon, 28 Aug 2023 16:36:36 GMT</pubDate>
    <dc:creator>shawnmuas</dc:creator>
    <dc:date>2023-08-28T16:36:36Z</dc:date>
    <item>
      <title>Panorama-Local Config Merge in HA</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/panorama-local-config-merge-in-ha/m-p/555540#M1788</link>
      <description>&lt;P&gt;We have a project to clean up the Panorama environment in order to manage changes from Panorama as much as possible. We have a pair of 3020 in A/P HA, already synced to Panorama with some local overrides. I performed the exact steps recommended by Palo on another HA set and it failed initially but was eventually fixed once we figured that "force template values" and sending to both firewalls will make them exactly the same as each other, HA and all. We did it this way:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Followed KB article:&amp;nbsp;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g0000008UIPCA2" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g0000008UIPCA2&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;Performed the steps for both firewalls in tandem, added them to new device group and template, forced template values for the last step, committed/pushed, and ended up with two identical firewalls. We updated HA settings to get them back online and synced.&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;What would be the recommended approach so we don't end up with the same issue? I'm thinking the following:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Turn off HA sync on both firewalls before going through the article steps.&lt;/LI&gt;
&lt;LI&gt;Per article, add both devices to Panorama device group and template but bypass steps 8 and 9 for the passive firewall.&lt;/LI&gt;
&lt;LI&gt;Finish steps 8 and 9 for the active firewall, export config bundle, then commit/push config to only the active firewall.&lt;/LI&gt;
&lt;LI&gt;Log into both firewalls, make sure MGMT and HA settings are different, re-enable sync and allow active to sync or force sync.&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Mon, 28 Aug 2023 16:36:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/panorama-local-config-merge-in-ha/m-p/555540#M1788</guid>
      <dc:creator>shawnmuas</dc:creator>
      <dc:date>2023-08-28T16:36:36Z</dc:date>
    </item>
    <item>
      <title>Re: Panorama-Local Config Merge in HA</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/panorama-local-config-merge-in-ha/m-p/555559#M1789</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/225917"&gt;@shawnmuas&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hear is an article on how to migrate an HA pair to Panorama.&amp;nbsp; &lt;A href="https://docs.paloaltonetworks.com/panorama/9-1/panorama-admin/manage-firewalls/transition-a-firewall-to-panorama-management/migrate-a-firewall-ha-pair-to-panorama-management" target="_blank"&gt;https://docs.paloaltonetworks.com/panorama/9-1/panorama-admin/manage-firewalls/transition-a-firewall-to-panorama-management/migrate-a-firewall-ha-pair-to-panorama-management&lt;/A&gt;&amp;nbsp; I have used it many times.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It is similar to your process, but a little different.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Panorama will not overwrite the Mgmt interface settings, even if you check Force Template Values.&lt;/LI&gt;
&lt;LI&gt;I am pretty sure a local sync config will NOT sync the Panorama pushed settings, only the local configuration.&amp;nbsp; So, you will need to do steps 8 and 9 for each NGFW as mentioned in this document.&lt;/LI&gt;
&lt;LI&gt;With regard to the HA settings, you could (1) click the Remove All button under the template and manage it locally, (2) use template variables, or (3) override locally.&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;</description>
      <pubDate>Mon, 28 Aug 2023 18:26:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/panorama-local-config-merge-in-ha/m-p/555559#M1789</guid>
      <dc:creator>TomYoung</dc:creator>
      <dc:date>2023-08-28T18:26:40Z</dc:date>
    </item>
  </channel>
</rss>

