<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to configure passive HA Panorama ethernet interface in Panorama Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/panorama-discussions/how-to-configure-passive-ha-panorama-ethernet-interface/m-p/505925#M966</link>
    <description>&lt;P&gt;Thank you for answering and sorry for the late response &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/192693"&gt;@PavelK&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have tried the second method on the production Panorama (by applying different IP on secondary Panorama) and it worked successfully, and now I could deploy the firewalls that connects to both active and passive Panorama.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you!&lt;/P&gt;</description>
    <pubDate>Fri, 24 Jun 2022 02:08:50 GMT</pubDate>
    <dc:creator>KNau</dc:creator>
    <dc:date>2022-06-24T02:08:50Z</dc:date>
    <item>
      <title>How to configure passive HA Panorama ethernet interface</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/how-to-configure-passive-ha-panorama-ethernet-interface/m-p/488549#M911</link>
      <description>&lt;P&gt;We are currently deploying two Panorama M-series appliances with active/passive configuration. The expected interface configuration will be like this:&lt;/P&gt;
&lt;P&gt;Active/Primary Panorama:&lt;/P&gt;
&lt;P&gt;Management: 172.20.1.11 (only for Panorama management access)&lt;/P&gt;
&lt;P&gt;ethernet1/1: 10.20.5.100 (for device management, log collection, etc.)&lt;EM&gt; &amp;gt; devices will be connected to this interface&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;Passive/Secondary Panorama:&lt;/P&gt;
&lt;P&gt;Management: 172.20.1.12&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;ethernet1/1: &lt;/EM&gt;10.20.5.100 (if possible to use same IP as primary) OR 10.20.5.101 (if different IP is required)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The issue is the ethernet1/1 options on the passive Panorama are greyed out and we cannot configure anything on it.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;My question is, is it possible to configure ethernet interface on an M-series Panorama in passive HA configuration? If possible, then how is the behavior of the ethernet interface:&lt;/P&gt;
&lt;P&gt;1. The secondary Panorama ethernet1/1 interface will be disabled due to passive mode, and automatically enabled when the appliance becomes active mode (just like HA on firewalls)&lt;/P&gt;
&lt;P&gt;2. The secondary Panorama ethernet1/1 interface is enabled all the time regardless of active/passive mode (in this case we will use different eth1/1 IP on primary and secondary to prevent IP conflict)&lt;/P&gt;
&lt;P&gt;3. Primary and secondary Panorama ethernet interfaces configuration are synced between each other.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Model: Panorama M-600 (x2)&lt;/P&gt;
&lt;P&gt;SW version: 10.1.4-h4&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;LI-PRODUCT title="Panorama" id="Panorama"&gt;&lt;/LI-PRODUCT&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 19 May 2022 11:10:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/how-to-configure-passive-ha-panorama-ethernet-interface/m-p/488549#M911</guid>
      <dc:creator>KNau</dc:creator>
      <dc:date>2022-05-19T11:10:30Z</dc:date>
    </item>
    <item>
      <title>Re: How to configure passive HA Panorama ethernet interface</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/how-to-configure-passive-ha-panorama-ethernet-interface/m-p/491061#M920</link>
      <description>&lt;P&gt;Thank you for the post&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/204369"&gt;@KNau&lt;/a&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I do not have this exact same setup in my environment, however by looking into documentation, you should make these changes from active Panorama. Please refer to this document, &lt;STRONG&gt;STEP 3 &amp;gt;&amp;gt; (HA only) Configure the interfaces on the passive Panorama management server.&lt;/STRONG&gt;:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/panorama/10-1/panorama-admin/set-up-panorama/set-up-the-m-series-appliance/configure-panorama-to-use-multiple-interfaces/configure-panorama-for-network-segmentation" target="_blank"&gt;https://docs.paloaltonetworks.com/panorama/10-1/panorama-admin/set-up-panorama/set-up-the-m-series-appliance/configure-panorama-to-use-multiple-interfaces/configure-panorama-for-network-segmentation&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I think selecting the checkbox:&amp;nbsp;&lt;STRONG&gt;Device Management and Device Log Collection&lt;/STRONG&gt; is what you need to meet your requirement.&lt;/P&gt;
&lt;P&gt;The reason why you can't make this change on Panorama passive node is feature limitation. Only Device Deployment is supported. Options to enable&amp;nbsp;Device Management and Device Log Collection and Collector Group Communication are therefore gray out.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regarding the IP address you configure on interface 1/1, you should use different IP address than what you configured for interface 1/1 on Panorama active node. From 3 options you mentioned,&amp;nbsp; the option 2 is from my point of view correct answer.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;After you make these changes, do not forget to commit it to Panorama and push the changes to log collector group.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Kind Regards&lt;/P&gt;
&lt;P&gt;Pavel&lt;/P&gt;</description>
      <pubDate>Tue, 24 May 2022 21:44:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/how-to-configure-passive-ha-panorama-ethernet-interface/m-p/491061#M920</guid>
      <dc:creator>PavelK</dc:creator>
      <dc:date>2022-05-24T21:44:53Z</dc:date>
    </item>
    <item>
      <title>Re: How to configure passive HA Panorama ethernet interface</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/how-to-configure-passive-ha-panorama-ethernet-interface/m-p/505925#M966</link>
      <description>&lt;P&gt;Thank you for answering and sorry for the late response &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/192693"&gt;@PavelK&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have tried the second method on the production Panorama (by applying different IP on secondary Panorama) and it worked successfully, and now I could deploy the firewalls that connects to both active and passive Panorama.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you!&lt;/P&gt;</description>
      <pubDate>Fri, 24 Jun 2022 02:08:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/how-to-configure-passive-ha-panorama-ethernet-interface/m-p/505925#M966</guid>
      <dc:creator>KNau</dc:creator>
      <dc:date>2022-06-24T02:08:50Z</dc:date>
    </item>
  </channel>
</rss>

