<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic master device in panorama device-group if using dataplane interface in Panorama Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/panorama-discussions/master-device-in-panorama-device-group-if-using-dataplane/m-p/409548#M255</link>
    <description>&lt;P&gt;Due to high cpu utilization in firewall , we want to use dataplane interface of firewall for user-id services.&lt;/P&gt;&lt;P&gt;Currently , when primary firewall failover to secondary we do not require to change master device in panorama device-group.&lt;/P&gt;&lt;P&gt;How panorama collecting user-id info if primary firewall which selected as a master in device-group becomes passive ?&lt;/P&gt;&lt;P&gt;What if Primary firewall goes completely down ?&lt;/P&gt;&lt;P&gt;If we use dataplane interface, do we require to change master device in Panorama device-group if failover happens ?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Deepak_K_0-1622112578545.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/34110i12F0474FCA5E3F39/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Deepak_K_0-1622112578545.png" alt="Deepak_K_0-1622112578545.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 27 May 2021 10:50:14 GMT</pubDate>
    <dc:creator>Deepak_K</dc:creator>
    <dc:date>2021-05-27T10:50:14Z</dc:date>
    <item>
      <title>master device in panorama device-group if using dataplane interface</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/master-device-in-panorama-device-group-if-using-dataplane/m-p/409548#M255</link>
      <description>&lt;P&gt;Due to high cpu utilization in firewall , we want to use dataplane interface of firewall for user-id services.&lt;/P&gt;&lt;P&gt;Currently , when primary firewall failover to secondary we do not require to change master device in panorama device-group.&lt;/P&gt;&lt;P&gt;How panorama collecting user-id info if primary firewall which selected as a master in device-group becomes passive ?&lt;/P&gt;&lt;P&gt;What if Primary firewall goes completely down ?&lt;/P&gt;&lt;P&gt;If we use dataplane interface, do we require to change master device in Panorama device-group if failover happens ?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Deepak_K_0-1622112578545.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/34110i12F0474FCA5E3F39/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Deepak_K_0-1622112578545.png" alt="Deepak_K_0-1622112578545.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 27 May 2021 10:50:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/master-device-in-panorama-device-group-if-using-dataplane/m-p/409548#M255</guid>
      <dc:creator>Deepak_K</dc:creator>
      <dc:date>2021-05-27T10:50:14Z</dc:date>
    </item>
    <item>
      <title>Re: master device in panorama device-group if using dataplane interface</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/master-device-in-panorama-device-group-if-using-dataplane/m-p/409635#M256</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/62177"&gt;@Deepak_K&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Sorry for asking, but how should using dp interface for user-id help with reducing the load on the cpu?&lt;/P&gt;
&lt;P&gt;The master device is defined by firewall serial number, so it does not matter if you use cp or dp interface. The user-id information is collected from this specified master device, so if the master goes down panorama is no longer able to collect these informations.&lt;/P&gt;</description>
      <pubDate>Thu, 27 May 2021 16:33:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/master-device-in-panorama-device-group-if-using-dataplane/m-p/409635#M256</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2021-05-27T16:33:57Z</dc:date>
    </item>
    <item>
      <title>Re: master device in panorama device-group if using dataplane interface</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/master-device-in-panorama-device-group-if-using-dataplane/m-p/409659#M257</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/62177"&gt;@Deepak_K&lt;/a&gt; ,&lt;/P&gt;&lt;P&gt;I am only guessing, but:&lt;/P&gt;&lt;P&gt;- If you use dataplane interface for user-id in active-passive HA both devices will use same ip address so in case of failover the backup should establish connection to the server/user-id agent&lt;/P&gt;&lt;P&gt;- User-ID information is synced between members in active-passive HA.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So in theory in case of failover, secondary device will get user-id info monitored server/user-id agent and sync it to primary member, which Panorama will still use. But this is valid of the primary FW is still alive (listed as passive in the HA cluster) and able to communicate with Panorama.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 27 May 2021 17:00:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/master-device-in-panorama-device-group-if-using-dataplane/m-p/409659#M257</guid>
      <dc:creator>aleksandar.astardzhiev</dc:creator>
      <dc:date>2021-05-27T17:00:51Z</dc:date>
    </item>
    <item>
      <title>Re: master device in panorama device-group if using dataplane interface</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/master-device-in-panorama-device-group-if-using-dataplane/m-p/411084#M258</link>
      <description>&lt;P&gt;Thanks Alexander,&lt;/P&gt;&lt;P&gt;User-id(users/group) info from primary to panorama will sync via which interface mgmt or dataplane?&lt;/P&gt;&lt;P&gt;Condition: service route on HA pair for LDAP and uid service is on dataplane interface. Master device in Panorama device-group is primary firewall and now secondary firewall is active&lt;/P&gt;</description>
      <pubDate>Fri, 04 Jun 2021 05:46:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/master-device-in-panorama-device-group-if-using-dataplane/m-p/411084#M258</guid>
      <dc:creator>Deepak25</dc:creator>
      <dc:date>2021-06-04T05:46:32Z</dc:date>
    </item>
  </channel>
</rss>

