<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Add to Panorama a new firewall to form an HA with a current standalone already managed by Panorama in Panorama Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/panorama-discussions/add-to-panorama-a-new-firewall-to-form-an-ha-with-a-current/m-p/581339#M2237</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/192693"&gt;@PavelK&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Sorry for the late response.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you so much for your reply, it was really useful and can be accepted as a solution.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;With the help of your instructions, we were able to integrate the device into the HA and panorama.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Kind Regards,&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Jorge Lopez&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 22 Mar 2024 12:34:35 GMT</pubDate>
    <dc:creator>Jorge_Lopez</dc:creator>
    <dc:date>2024-03-22T12:34:35Z</dc:date>
    <item>
      <title>Add to Panorama a new firewall to form an HA with a current standalone already managed by Panorama</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/add-to-panorama-a-new-firewall-to-form-an-ha-with-a-current/m-p/579476#M2209</link>
      <description>&lt;P&gt;One of our customers has a standalone&amp;nbsp;PA-820 that is currently managed by Panorama.&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;They now want to add another PA-820 and form an HA Active/Passive peer with the one mentioned above.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Checking PA documentation, I can only see references about how to integrate both HA peers or a standalone firewall&amp;nbsp;but do not mention anything specific about how to add an HA peer to Panorama when the other peer is already managed by Panorama as a standalone.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In particular, I have been checking the documents below:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Add a Firewall as a Managed Device --&amp;gt; &lt;A href="https://docs.paloaltonetworks.com/panorama/10-1/panorama-admin/manage-firewalls/add-a-firewall-as-a-managed-device" target="_blank"&gt;https://docs.paloaltonetworks.com/panorama/10-1/panorama-admin/manage-firewalls/add-a-firewall-as-a-managed-device&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;How to add a locally managed firewall to panorama management --&amp;gt; &lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000CloRCAS" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000CloRCAS&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;Migrate a Firewall to Panorama Management and Reuse Existing Configuration --&amp;gt; &lt;A href="https://docs.paloaltonetworks.com/panorama/10-1/panorama-admin/manage-firewalls/transition-a-firewall-to-panorama-management/migrate-a-firewall-to-panorama-management" target="_blank"&gt;https://docs.paloaltonetworks.com/panorama/10-1/panorama-admin/manage-firewalls/transition-a-firewall-to-panorama-management/migrate-a-firewall-to-panorama-management&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;But no one of these documents mentions anything about what the customer wants.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;The existing firewall should keep its configuration in panorama, just adding the HA functionality and becoming the primary node in the cluster. The new firewall should just be added to the existing firewall as a secondary node in the cluster.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Thanks in advance to the community.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 06 Mar 2024 15:11:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/add-to-panorama-a-new-firewall-to-form-an-ha-with-a-current/m-p/579476#M2209</guid>
      <dc:creator>Jorge_Lopez</dc:creator>
      <dc:date>2024-03-06T15:11:43Z</dc:date>
    </item>
    <item>
      <title>Re: Add to Panorama a new firewall to form an HA with a current standalone already managed by Panorama</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/add-to-panorama-a-new-firewall-to-form-an-ha-with-a-current/m-p/579574#M2210</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/265212"&gt;@Jorge_Lopez&lt;/a&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;thanks for posting.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have not done this exact scenario before. All HA Firewalls I managed were right from the initial setup managed by Panorama. If I were about to do the same what your customer is planning to do, I would follow below steps.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;1.)&lt;/P&gt;
&lt;P&gt;Install additional PA-820 and perform initial configuration (management interface) and download/install the same PAN-OS + Application/Threat version what other PA-820 is using.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;2.)&lt;/P&gt;
&lt;P&gt;In Panorama, register&amp;nbsp;additional PA-820 in the same Device Group / Template Stack as existing Firewall,&amp;nbsp;then push the configuration to new PA-820. If there is no issue, then I would proceed with HA configuration.&amp;nbsp;If HA function is going to be managed through Panorama, then follow this KB:&amp;nbsp;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000PNG0CAO" target="_self"&gt;How to use one Template stack for a high availability Firewall Pair on Panorama&lt;/A&gt;&amp;nbsp;to set up Template for HA feature. Make sure that device priority is set correctly to make existing Firewall is primary active:&amp;nbsp;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClWPCA0" target="_self"&gt;Understanding Preemption with the Configured Device Priority in HA Active/Passive Mode&lt;/A&gt;. If there is no error with pushing HA related configuration, then I would proceed with next step.&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;3.)&lt;/P&gt;
&lt;P&gt;I would connect HA ports, then make sure that both Firewalls assume respective active role for existing Firewall and passive for new Firewall. If there is no issue with HA synchronization / incompatibility, then I would connect all data plane cables to new Firewall, then perform a failover to make sure there is no issue with traffic flow and interfaces, then fail back.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;To avoid risk, I would perform steps No. 2 and 3 during the same maintenance window and tested it with failover before closing maintenance window.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Kind Regards&lt;/P&gt;
&lt;P&gt;Pavel&lt;/P&gt;</description>
      <pubDate>Thu, 07 Mar 2024 07:34:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/add-to-panorama-a-new-firewall-to-form-an-ha-with-a-current/m-p/579574#M2210</guid>
      <dc:creator>PavelK</dc:creator>
      <dc:date>2024-03-07T07:34:06Z</dc:date>
    </item>
    <item>
      <title>Re: Add to Panorama a new firewall to form an HA with a current standalone already managed by Panorama</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/add-to-panorama-a-new-firewall-to-form-an-ha-with-a-current/m-p/581339#M2237</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/192693"&gt;@PavelK&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Sorry for the late response.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you so much for your reply, it was really useful and can be accepted as a solution.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;With the help of your instructions, we were able to integrate the device into the HA and panorama.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Kind Regards,&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Jorge Lopez&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 22 Mar 2024 12:34:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/add-to-panorama-a-new-firewall-to-form-an-ha-with-a-current/m-p/581339#M2237</guid>
      <dc:creator>Jorge_Lopez</dc:creator>
      <dc:date>2024-03-22T12:34:35Z</dc:date>
    </item>
    <item>
      <title>Re: Add to Panorama a new firewall to form an HA with a current standalone already managed by Panorama</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/add-to-panorama-a-new-firewall-to-form-an-ha-with-a-current/m-p/588376#M2360</link>
      <description>&lt;P&gt;For the new firewall how would you configure the public IP?&lt;/P&gt;</description>
      <pubDate>Thu, 30 May 2024 09:51:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/add-to-panorama-a-new-firewall-to-form-an-ha-with-a-current/m-p/588376#M2360</guid>
      <dc:creator>David_Tolo</dc:creator>
      <dc:date>2024-05-30T09:51:28Z</dc:date>
    </item>
    <item>
      <title>Re: Add to Panorama a new firewall to form an HA with a current standalone already managed by Panorama</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/add-to-panorama-a-new-firewall-to-form-an-ha-with-a-current/m-p/588380#M2362</link>
      <description>&lt;P&gt;The challenge I am running into is the current firewall is in production and I am remote.&amp;nbsp; Everything is cabled up but the new firewall is unconfigured.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The current firewalls configure from Panorama.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I want to keep HA local instead of panorama manged.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;My thought is to configure HA local, commit it to the firewalls and then add the new firewall to the device group and template stack.&amp;nbsp; The issue I am running into as soon as I commit the config on the active firewall it becomes passive and the network goes down.&amp;nbsp; Fortunately I have the panorama setting comitt recovery enabled so it comes back up uncommited.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I cant figure out how to prevent it from failing over.&lt;/P&gt;</description>
      <pubDate>Thu, 30 May 2024 10:01:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/add-to-panorama-a-new-firewall-to-form-an-ha-with-a-current/m-p/588380#M2362</guid>
      <dc:creator>David_Tolo</dc:creator>
      <dc:date>2024-05-30T10:01:30Z</dc:date>
    </item>
  </channel>
</rss>

