<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Panorama HA sync between on-prem and cloud VM Series in Panorama Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/panorama-discussions/panorama-ha-sync-between-on-prem-and-cloud-vm-series/m-p/1220026#M2779</link>
    <description>&lt;P&gt;Hello,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you deploy &lt;STRONG&gt;Panorama VM with 1 active instance on-premises and 1 passive instance in the cloud&lt;/STRONG&gt;, you might encounter issues with HA Sync when enforcing the permitted IP address restriction on the Panorama management interface.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Panorama Management IP address&lt;/P&gt;
&lt;P&gt;pan-on-prem - 10.10.10.10&lt;/P&gt;
&lt;P&gt;pan-on-cloud - 20.20.20.10&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Let's assume that for High availability setting, we use the Management interface IP address to communicate between Active and Passive Panorama instances.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;HA sync between the active and passive Panorama will not function as expected after applying the permitted IP address restriction in the Management Interface Settings under Panorama --&amp;gt; Setup --&amp;gt; Interfaces --&amp;gt; Management, even if the management IP address of both Panorama is included in the permit list on both Panorama instances.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;set deviceconfig system permitted-ip 10.10.10.10/32 description&amp;nbsp;&amp;nbsp;pan-on-prem&lt;/P&gt;
&lt;P&gt;set deviceconfig system permitted-ip 20.20.20.10/32 description&amp;nbsp;&amp;nbsp;pan-on-cloud&lt;/P&gt;
&lt;P&gt;set deviceconfig system permitted-ip &amp;lt;rest-of-the-ips&amp;gt;&amp;nbsp;description&amp;nbsp; all-other-ips&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Issue: &lt;STRONG&gt;HA sync failure&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Symptoms:&lt;/P&gt;
&lt;P&gt;On &lt;STRONG&gt;Active&lt;/STRONG&gt; Panorama&lt;/P&gt;
&lt;P&gt;Running config: &lt;STRONG&gt;Not Synchronized&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;App version : unknown&lt;/P&gt;
&lt;P&gt;Antivirus version: unknown&lt;/P&gt;
&lt;P&gt;Plugin vm_series: unknown&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;On &lt;STRONG&gt;Passive&lt;/STRONG&gt; Panorama&lt;/P&gt;
&lt;P&gt;Running config: Not Synchronized&lt;/P&gt;
&lt;P&gt;App version : Mismatch&lt;/P&gt;
&lt;P&gt;Antivirus version: Mismatch&lt;/P&gt;
&lt;P&gt;Plugin vm_series: Mismatch&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Solution: &lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Modify the Panorama management interface MTU size from &lt;STRONG&gt;1500&lt;/STRONG&gt; to &lt;STRONG&gt;1380&lt;/STRONG&gt; on both the Panorama virtual appliances.&lt;/LI&gt;
&lt;LI&gt;Commit the changes on both the Panorama virtual appliances.&lt;/LI&gt;
&lt;LI&gt;HA Sync will be working as expected.&lt;/LI&gt;
&lt;/UL&gt;</description>
    <pubDate>Wed, 12 Feb 2025 00:01:05 GMT</pubDate>
    <dc:creator>bpride</dc:creator>
    <dc:date>2025-02-12T00:01:05Z</dc:date>
    <item>
      <title>Panorama HA sync between on-prem and cloud VM Series</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/panorama-ha-sync-between-on-prem-and-cloud-vm-series/m-p/1220026#M2779</link>
      <description>&lt;P&gt;Hello,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you deploy &lt;STRONG&gt;Panorama VM with 1 active instance on-premises and 1 passive instance in the cloud&lt;/STRONG&gt;, you might encounter issues with HA Sync when enforcing the permitted IP address restriction on the Panorama management interface.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Panorama Management IP address&lt;/P&gt;
&lt;P&gt;pan-on-prem - 10.10.10.10&lt;/P&gt;
&lt;P&gt;pan-on-cloud - 20.20.20.10&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Let's assume that for High availability setting, we use the Management interface IP address to communicate between Active and Passive Panorama instances.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;HA sync between the active and passive Panorama will not function as expected after applying the permitted IP address restriction in the Management Interface Settings under Panorama --&amp;gt; Setup --&amp;gt; Interfaces --&amp;gt; Management, even if the management IP address of both Panorama is included in the permit list on both Panorama instances.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;set deviceconfig system permitted-ip 10.10.10.10/32 description&amp;nbsp;&amp;nbsp;pan-on-prem&lt;/P&gt;
&lt;P&gt;set deviceconfig system permitted-ip 20.20.20.10/32 description&amp;nbsp;&amp;nbsp;pan-on-cloud&lt;/P&gt;
&lt;P&gt;set deviceconfig system permitted-ip &amp;lt;rest-of-the-ips&amp;gt;&amp;nbsp;description&amp;nbsp; all-other-ips&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Issue: &lt;STRONG&gt;HA sync failure&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Symptoms:&lt;/P&gt;
&lt;P&gt;On &lt;STRONG&gt;Active&lt;/STRONG&gt; Panorama&lt;/P&gt;
&lt;P&gt;Running config: &lt;STRONG&gt;Not Synchronized&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;App version : unknown&lt;/P&gt;
&lt;P&gt;Antivirus version: unknown&lt;/P&gt;
&lt;P&gt;Plugin vm_series: unknown&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;On &lt;STRONG&gt;Passive&lt;/STRONG&gt; Panorama&lt;/P&gt;
&lt;P&gt;Running config: Not Synchronized&lt;/P&gt;
&lt;P&gt;App version : Mismatch&lt;/P&gt;
&lt;P&gt;Antivirus version: Mismatch&lt;/P&gt;
&lt;P&gt;Plugin vm_series: Mismatch&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Solution: &lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Modify the Panorama management interface MTU size from &lt;STRONG&gt;1500&lt;/STRONG&gt; to &lt;STRONG&gt;1380&lt;/STRONG&gt; on both the Panorama virtual appliances.&lt;/LI&gt;
&lt;LI&gt;Commit the changes on both the Panorama virtual appliances.&lt;/LI&gt;
&lt;LI&gt;HA Sync will be working as expected.&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Wed, 12 Feb 2025 00:01:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/panorama-ha-sync-between-on-prem-and-cloud-vm-series/m-p/1220026#M2779</guid>
      <dc:creator>bpride</dc:creator>
      <dc:date>2025-02-12T00:01:05Z</dc:date>
    </item>
  </channel>
</rss>

