<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: HA Active/Passive Management Design in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/ha-active-passive-management-design/m-p/15483#M11355</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes there is a dedicated mgt port on each PAN firewall and you can assign a LAN's IP address to the mgt port.&amp;nbsp; Each firewall should be given a different IP address for its mgt port.&amp;nbsp; Thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 04 May 2012 15:17:52 GMT</pubDate>
    <dc:creator>rmonvon</dc:creator>
    <dc:date>2012-05-04T15:17:52Z</dc:date>
    <item>
      <title>HA Active/Passive Management Design</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ha-active-passive-management-design/m-p/15479#M11351</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P class="MsoNormal"&gt;I am testing out and setting up two PA-2020 in a HA Active/Passive setup for eventual use in our production network.&lt;SPAN style="mso-spacerun:yes"&gt;&amp;nbsp; &lt;/SPAN&gt;I am testing this outside of our current network infrastructure to ensure I understand the complete setup processes. I had a couple design questions regarding this setup.&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;As of now I have two zones, WAN and LAN enabled on both firewalls. I’ve enabled two ports for HA on both firewalls and have connected them with crossover cables. Both WAN cables are running into a switch, and both LAN cables are running into another switch.&lt;SPAN style="mso-spacerun:yes"&gt;&amp;nbsp; &lt;/SPAN&gt;I’ve been able to get HA working, but had a question about how to manage both PAN FWs separately, since the interfaces on one is inactive in the passive state.&lt;SPAN style="mso-spacerun:yes"&gt;&amp;nbsp; &lt;/SPAN&gt;Currently both management ports are set to the default IP and subnet, but I was wondering if I can assign the management port in the same subnet as the LAN network to manage the firewalls independently. In order to suspend firewalls for PAN OS upgrades can I manage both firewalls at the same time in this manner?&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;I’m a little bit new to firewalls, and even newer to PANs and wanted to make sure I understood the setup behind this.&lt;SPAN style="mso-spacerun:yes"&gt;&amp;nbsp; &lt;/SPAN&gt;Thanks for all your help. &lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;Any other thoughts or tips would be awesome, too!&amp;nbsp; Thanks!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 03 May 2012 21:40:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ha-active-passive-management-design/m-p/15479#M11351</guid>
      <dc:creator>cmateam</dc:creator>
      <dc:date>2012-05-03T21:40:34Z</dc:date>
    </item>
    <item>
      <title>Re: HA Active/Passive Management Design</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ha-active-passive-management-design/m-p/15480#M11352</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="font-family: arial, helvetica, sans-serif;"&gt;The interfaces on the passive device will be inactive. You can manage both the active and the passive box through the management ports which remain active irrespective of the HA state. You will still have access to both the boxes during upgrade if you use management ports.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: arial, helvetica, sans-serif;"&gt;There is a specific procedure to be followed during upgrade to ensure minimal downtime. These document walks you through the process:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: arial, helvetica, sans-serif;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;A __default_attr="4043" __jive_macro_name="document" class="jive_macro jive_macro_document" href="https://live.paloaltonetworks.com/"&gt;&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The procedure is the same irrespective of the PANOS to which you want to upgrade from/to.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: arial, helvetica, sans-serif;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 04 May 2012 00:11:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ha-active-passive-management-design/m-p/15480#M11352</guid>
      <dc:creator>zarina</dc:creator>
      <dc:date>2012-05-04T00:11:46Z</dc:date>
    </item>
    <item>
      <title>Re: HA Active/Passive Management Design</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ha-active-passive-management-design/m-p/15481#M11353</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Also, if you're deploying the PAN firewalls in L3 mode, the passive LAN &amp;amp; WAN interfaces can be set to auto and these interfaces on the passive PAN can be in an up state. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 04 May 2012 04:33:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ha-active-passive-management-design/m-p/15481#M11353</guid>
      <dc:creator>rmonvon</dc:creator>
      <dc:date>2012-05-04T04:33:40Z</dc:date>
    </item>
    <item>
      <title>Re: HA Active/Passive Management Design</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ha-active-passive-management-design/m-p/15482#M11354</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Per my original question, can the management ports be subnetted to my LAN zone with an IP address that I can access from the LAN zone - instead of having to walk into my Data Center with two laptops to manage the firewalls.&amp;nbsp; This will also be particularly important as I will need to manage two additional firewalls at a second location via a IPSec tunnel.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 04 May 2012 14:13:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ha-active-passive-management-design/m-p/15482#M11354</guid>
      <dc:creator>cmateam</dc:creator>
      <dc:date>2012-05-04T14:13:01Z</dc:date>
    </item>
    <item>
      <title>Re: HA Active/Passive Management Design</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ha-active-passive-management-design/m-p/15483#M11355</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes there is a dedicated mgt port on each PAN firewall and you can assign a LAN's IP address to the mgt port.&amp;nbsp; Each firewall should be given a different IP address for its mgt port.&amp;nbsp; Thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 04 May 2012 15:17:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ha-active-passive-management-design/m-p/15483#M11355</guid>
      <dc:creator>rmonvon</dc:creator>
      <dc:date>2012-05-04T15:17:52Z</dc:date>
    </item>
    <item>
      <title>Re: HA Active/Passive Management Design</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ha-active-passive-management-design/m-p/15484#M11356</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Anyway I could get access to these docs?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 04 Jan 2013 09:11:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ha-active-passive-management-design/m-p/15484#M11356</guid>
      <dc:creator>Ante</dc:creator>
      <dc:date>2013-01-04T09:11:50Z</dc:date>
    </item>
    <item>
      <title>Re: HA Active/Passive Management Design</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ha-active-passive-management-design/m-p/15485#M11357</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You mean &lt;A __default_attr="4043" __jive_macro_name="document" class="jive_macro jive_macro_document" href="https://live.paloaltonetworks.com/"&gt;&lt;/A&gt; ? It works for me so I guess it should work for you aswell to access that url?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 06 Jan 2013 21:41:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ha-active-passive-management-design/m-p/15485#M11357</guid>
      <dc:creator>mikand</dc:creator>
      <dc:date>2013-01-06T21:41:02Z</dc:date>
    </item>
  </channel>
</rss>

