<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Managing HA Settings of firewall locally instead of managing it from Panorama in Panorama Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/panorama-discussions/managing-ha-settings-of-firewall-locally-instead-of-managing-it/m-p/455844#M611</link>
    <description>&lt;P&gt;Hi Folks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We had recently migrated HA firewall to Panorama using the below documentation&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV dir="ltr"&gt;&lt;STRONG dir="ltr"&gt;Migrate a Firewall HA Pair to Panorama Management:&lt;/STRONG&gt;&lt;/DIV&gt;
&lt;DIV dir="ltr"&gt;&lt;STRONG dir="ltr"&gt;​&lt;/STRONG&gt;&lt;/DIV&gt;
&lt;DIV dir="ltr"&gt;&lt;A dir="ltr" href="https://docs.paloaltonetworks.com/panorama/10-0/panorama-admin/manage-firewalls/transition-a-firewall-to-panorama-management/migrate-a-firewall-ha-pair-to-panorama-management.html" target="_blank"&gt;https://docs.paloaltonetworks.com/panorama/10-0/panorama-admin/manage-firewalls/transition-a-firewall-to-panorama-management/migrate-a-firewall-ha-pair-to-panorama-management.html&lt;/A&gt;&lt;/DIV&gt;
&lt;DIV dir="ltr"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV dir="ltr"&gt;As per below documentation once the migration had been completed the HA settings and management IP address of the HA firewall need to be managed locally on the firewall by over-riding the template values.&lt;/DIV&gt;
&lt;DIV dir="ltr"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV dir="ltr"&gt;Also both the HA firewalls are in same template group which indicates that we will not be able to manage the firewall.&lt;/DIV&gt;
&lt;DIV dir="ltr"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV dir="ltr"&gt;But the customer is not OK with it and need to manage HA settings and everything from Panorama itself.&lt;/DIV&gt;
&lt;DIV dir="ltr"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV dir="ltr"&gt;We are thinking about creating an common template containing all the required changes for both the firewalls and create two template stack for each firewall and call the template in those template stacks.&lt;/DIV&gt;
&lt;DIV dir="ltr"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV dir="ltr"&gt;Then create two separate template dedicated for HA Settings, Management IP address configuration and other things which will be different from both the firewalls and map primary firewall HA temp config to Primary firewall stack and do the same for Secondary firewall temp and map it to secondary firewall also.&lt;/DIV&gt;
&lt;DIV dir="ltr"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV dir="ltr"&gt;Please let me know if this approach is correct.&lt;/DIV&gt;
&lt;DIV dir="ltr"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV dir="ltr"&gt;Temp 1 == all common settings, temp 2= Primary HA Settings, Temp 3 = Sec HA Settings\\\ Temp stack 1(Primary FW)== temp1, temp 2. \\\temp stack 2(Secondary FW) =&amp;nbsp;temp1, temp 3&lt;/DIV&gt;
&lt;DIV dir="ltr"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV dir="ltr"&gt;Thanks in advance&lt;/DIV&gt;</description>
    <pubDate>Wed, 29 Dec 2021 14:50:30 GMT</pubDate>
    <dc:creator>tamilvanan</dc:creator>
    <dc:date>2021-12-29T14:50:30Z</dc:date>
    <item>
      <title>Managing HA Settings of firewall locally instead of managing it from Panorama</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/managing-ha-settings-of-firewall-locally-instead-of-managing-it/m-p/455844#M611</link>
      <description>&lt;P&gt;Hi Folks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We had recently migrated HA firewall to Panorama using the below documentation&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV dir="ltr"&gt;&lt;STRONG dir="ltr"&gt;Migrate a Firewall HA Pair to Panorama Management:&lt;/STRONG&gt;&lt;/DIV&gt;
&lt;DIV dir="ltr"&gt;&lt;STRONG dir="ltr"&gt;​&lt;/STRONG&gt;&lt;/DIV&gt;
&lt;DIV dir="ltr"&gt;&lt;A dir="ltr" href="https://docs.paloaltonetworks.com/panorama/10-0/panorama-admin/manage-firewalls/transition-a-firewall-to-panorama-management/migrate-a-firewall-ha-pair-to-panorama-management.html" target="_blank"&gt;https://docs.paloaltonetworks.com/panorama/10-0/panorama-admin/manage-firewalls/transition-a-firewall-to-panorama-management/migrate-a-firewall-ha-pair-to-panorama-management.html&lt;/A&gt;&lt;/DIV&gt;
&lt;DIV dir="ltr"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV dir="ltr"&gt;As per below documentation once the migration had been completed the HA settings and management IP address of the HA firewall need to be managed locally on the firewall by over-riding the template values.&lt;/DIV&gt;
&lt;DIV dir="ltr"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV dir="ltr"&gt;Also both the HA firewalls are in same template group which indicates that we will not be able to manage the firewall.&lt;/DIV&gt;
&lt;DIV dir="ltr"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV dir="ltr"&gt;But the customer is not OK with it and need to manage HA settings and everything from Panorama itself.&lt;/DIV&gt;
&lt;DIV dir="ltr"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV dir="ltr"&gt;We are thinking about creating an common template containing all the required changes for both the firewalls and create two template stack for each firewall and call the template in those template stacks.&lt;/DIV&gt;
&lt;DIV dir="ltr"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV dir="ltr"&gt;Then create two separate template dedicated for HA Settings, Management IP address configuration and other things which will be different from both the firewalls and map primary firewall HA temp config to Primary firewall stack and do the same for Secondary firewall temp and map it to secondary firewall also.&lt;/DIV&gt;
&lt;DIV dir="ltr"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV dir="ltr"&gt;Please let me know if this approach is correct.&lt;/DIV&gt;
&lt;DIV dir="ltr"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV dir="ltr"&gt;Temp 1 == all common settings, temp 2= Primary HA Settings, Temp 3 = Sec HA Settings\\\ Temp stack 1(Primary FW)== temp1, temp 2. \\\temp stack 2(Secondary FW) =&amp;nbsp;temp1, temp 3&lt;/DIV&gt;
&lt;DIV dir="ltr"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV dir="ltr"&gt;Thanks in advance&lt;/DIV&gt;</description>
      <pubDate>Wed, 29 Dec 2021 14:50:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/managing-ha-settings-of-firewall-locally-instead-of-managing-it/m-p/455844#M611</guid>
      <dc:creator>tamilvanan</dc:creator>
      <dc:date>2021-12-29T14:50:30Z</dc:date>
    </item>
    <item>
      <title>Re: Managing HA Settings of firewall locally instead of managing it from Panorama</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/managing-ha-settings-of-firewall-locally-instead-of-managing-it/m-p/455953#M612</link>
      <description>&lt;P&gt;Thank you for the post&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/165087"&gt;@tamilvanan&lt;/a&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;First of all, I agree with you that it is better and safer to managed HA locally instead of using Panorama. Overall, your design of Templates/Template Stack looks good and to me it looks functional. The only thing I am worried about is pushing of setting from Template (HA setting, interfaces,..) will not be applied if Firewall has already existing overlapping configuration. You will have to override it locally to apply Panorama pushed configuration:&amp;nbsp;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u0000008UgMCAU&amp;amp;lang=en_US%E2%80%A9" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u0000008UgMCAU&amp;amp;lang=en_US%E2%80%A9&lt;/A&gt;&amp;nbsp;Alternative approach is to select: "Force Template Values" while pushing configuration, but this involves risk that local config that is not included in Template will be wiped, so I would go with overriding it locally as this is only one time job.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Could you please post back how well this went? I am wondering how smooth it was.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Kind Regards&lt;/P&gt;
&lt;P&gt;Pavel&lt;/P&gt;</description>
      <pubDate>Thu, 30 Dec 2021 02:39:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/managing-ha-settings-of-firewall-locally-instead-of-managing-it/m-p/455953#M612</guid>
      <dc:creator>PavelK</dc:creator>
      <dc:date>2021-12-30T02:39:45Z</dc:date>
    </item>
    <item>
      <title>Re: Managing HA Settings of firewall locally instead of managing it from Panorama</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/managing-ha-settings-of-firewall-locally-instead-of-managing-it/m-p/455979#M614</link>
      <description>&lt;P&gt;Whatever you have mentioned had worked well in my case. I had overridden local settings on firewall first. Just sharing my experience. Thank you&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 30 Dec 2021 07:17:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/managing-ha-settings-of-firewall-locally-instead-of-managing-it/m-p/455979#M614</guid>
      <dc:creator>d.spider</dc:creator>
      <dc:date>2021-12-30T07:17:23Z</dc:date>
    </item>
  </channel>
</rss>

