<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Failover Topology in Strata Cloud Manager</title>
    <link>https://live.paloaltonetworks.com/t5/strata-cloud-manager/failover-topology/m-p/1220388#M3</link>
    <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/286529393"&gt;@M.Gill298701&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Yes, the configuration is exactly the same, and in the event of failover the passive then becomes active.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;With active/passive HA, the configuration is exactly the same between both FWs except for a few device configurations listed here.&amp;nbsp; &lt;A href="https://docs.paloaltonetworks.com/pan-os/11-0/pan-os-admin/high-availability/reference-ha-synchronization" target="_blank" rel="noopener"&gt;https://docs.paloaltonetworks.com/pan-os/11-0/pan-os-admin/high-availability/reference-ha-synchronization&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For standalone, you configure one FW and the config is synced.&amp;nbsp; For Panorama, you put the HA pair in the same template (and device group).&amp;nbsp; With SCM, it looks like you put them in the same parent folder and modify that configuration scope.&amp;nbsp; If you configure HA in that scope, you will need to use variables as the HA links must have different IP addresses.&amp;nbsp; &lt;A href="https://live.paloaltonetworks.com/t5/next-generation-firewall/ha-configurations-in-strata-cloud-manager-scm-with-ngfw/td-p/616341" target="_blank"&gt;https://live.paloaltonetworks.com/t5/next-generation-firewall/ha-configurations-in-strata-cloud-manager-scm-with-ngfw/td-p/616341&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;</description>
    <pubDate>Thu, 13 Feb 2025 18:13:58 GMT</pubDate>
    <dc:creator>TomYoung</dc:creator>
    <dc:date>2025-02-13T18:13:58Z</dc:date>
    <item>
      <title>Failover Topology</title>
      <link>https://live.paloaltonetworks.com/t5/strata-cloud-manager/failover-topology/m-p/1220352#M2</link>
      <description>&lt;P&gt;I'm configuring a pair of PA460 for the first time in SCM and a little lost at how I'm meant to do the HA.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I can only do active/passive but my question is more aimed at how I configure the interfaces for the LAN/zones on the two PAs.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Do I configure the interfaces exactly the same on both boxes e.g. IP identical and then the standby just takes over?&lt;BR /&gt;&lt;BR /&gt;Usually firewall vendors will have some sort of FHRP functionality or virtual IP service, but Palo doesn't seem to support either of these hence why I'm a little lost.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Just to clarify: the actual HA config I'm good with, configured a HA1 and HA2 interface and its working as expected. This is purely about the LAN interfaces dealing with traffic&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;LI-PRODUCT title="Strata Cloud Manager" id="Strata_Cloud_Manager"&gt;&lt;/LI-PRODUCT&gt; &lt;LI-PRODUCT title="NGFW" id="NGFW"&gt;&lt;/LI-PRODUCT&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 13 Feb 2025 10:53:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/strata-cloud-manager/failover-topology/m-p/1220352#M2</guid>
      <dc:creator>M.Gill298701</dc:creator>
      <dc:date>2025-02-13T10:53:20Z</dc:date>
    </item>
    <item>
      <title>Re: Failover Topology</title>
      <link>https://live.paloaltonetworks.com/t5/strata-cloud-manager/failover-topology/m-p/1220388#M3</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/286529393"&gt;@M.Gill298701&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Yes, the configuration is exactly the same, and in the event of failover the passive then becomes active.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;With active/passive HA, the configuration is exactly the same between both FWs except for a few device configurations listed here.&amp;nbsp; &lt;A href="https://docs.paloaltonetworks.com/pan-os/11-0/pan-os-admin/high-availability/reference-ha-synchronization" target="_blank" rel="noopener"&gt;https://docs.paloaltonetworks.com/pan-os/11-0/pan-os-admin/high-availability/reference-ha-synchronization&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For standalone, you configure one FW and the config is synced.&amp;nbsp; For Panorama, you put the HA pair in the same template (and device group).&amp;nbsp; With SCM, it looks like you put them in the same parent folder and modify that configuration scope.&amp;nbsp; If you configure HA in that scope, you will need to use variables as the HA links must have different IP addresses.&amp;nbsp; &lt;A href="https://live.paloaltonetworks.com/t5/next-generation-firewall/ha-configurations-in-strata-cloud-manager-scm-with-ngfw/td-p/616341" target="_blank"&gt;https://live.paloaltonetworks.com/t5/next-generation-firewall/ha-configurations-in-strata-cloud-manager-scm-with-ngfw/td-p/616341&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;</description>
      <pubDate>Thu, 13 Feb 2025 18:13:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/strata-cloud-manager/failover-topology/m-p/1220388#M3</guid>
      <dc:creator>TomYoung</dc:creator>
      <dc:date>2025-02-13T18:13:58Z</dc:date>
    </item>
  </channel>
</rss>

