<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to onboard passive PA440 firewall to Panorama using dataplane interface in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-onboard-passive-pa440-firewall-to-panorama-using/m-p/1227146#M124075</link>
    <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/653493405"&gt;@Ramesh&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;
&lt;P&gt;I need assistance integrating Palo Alto firewalls in an Active/Passive HA setup with Panorama. Below is an overview of the setup:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;At customer sites, we have Palo Alto firewalls configured in Active/Passive HA mode, and they are currently managed locally. We are now planning to integrate them with Panorama, which is hosted in the AWS cloud. An IPSec tunnel has been established between AWS and the customer sites for this purpose.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Since the management subnet at the sites does not have a route to reach Panorama in AWS, I have configured a dedicated dataplane interface solely for Panorama communication. I have also modified the service route to use this dataplane interface instead of the default management interface.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;However, because this dataplane interface is not active on the passive firewall, the passive firewall is unable to communicate with Panorama and appears as “disconnected” in Panorama.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;To onboard the firewalls into Panorama, we need to import the existing firewall configuration into Panorama and then push the configuration back to the devices. Since the passive firewall is in a disconnected state, we are unable to perform this operation.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is there a recommended workaround to address this situation?&lt;/P&gt;
&lt;P&gt;Firewall model: PA 440&lt;/P&gt;
&lt;P&gt;Software version: 11.1.4&lt;/P&gt;
&lt;P&gt;&lt;LI-WRAPPER&gt;&lt;/LI-WRAPPER&gt;&lt;/P&gt;
&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;
&lt;P&gt;In the HA setup, there's an option that allows the interfaces to be in an "UP" / online state.&amp;nbsp; I'm not sure but that might be enough to bring the dataplane port up for the service route to work.&lt;/P&gt;</description>
    <pubDate>Tue, 22 Apr 2025 18:02:14 GMT</pubDate>
    <dc:creator>Brandon_Wertz</dc:creator>
    <dc:date>2025-04-22T18:02:14Z</dc:date>
    <item>
      <title>How to onboard passive PA440 firewall to Panorama using dataplane interface</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-onboard-passive-pa440-firewall-to-panorama-using/m-p/1226925#M124050</link>
      <description>&lt;P&gt;I need assistance integrating Palo Alto firewalls in an Active/Passive HA setup with Panorama. Below is an overview of the setup:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;At customer sites, we have Palo Alto firewalls configured in Active/Passive HA mode, and they are currently managed locally. We are now planning to integrate them with Panorama, which is hosted in the AWS cloud. An IPSec tunnel has been established between AWS and the customer sites for this purpose.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Since the management subnet at the sites does not have a route to reach Panorama in AWS, I have configured a dedicated dataplane interface solely for Panorama communication. I have also modified the service route to use this dataplane interface instead of the default management interface.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;However, because this dataplane interface is not active on the passive firewall, the passive firewall is unable to communicate with Panorama and appears as “disconnected” in Panorama.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;To onboard the firewalls into Panorama, we need to import the existing firewall configuration into Panorama and then push the configuration back to the devices. Since the passive firewall is in a disconnected state, we are unable to perform this operation.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is there a recommended workaround to address this situation?&lt;/P&gt;
&lt;P&gt;Firewall model: PA 440&lt;/P&gt;
&lt;P&gt;Software version: 11.1.4&lt;/P&gt;
&lt;P&gt;&lt;LI-WRAPPER&gt;&lt;/LI-WRAPPER&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 21 Apr 2025 03:58:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-onboard-passive-pa440-firewall-to-panorama-using/m-p/1226925#M124050</guid>
      <dc:creator>Ramesh</dc:creator>
      <dc:date>2025-04-21T03:58:14Z</dc:date>
    </item>
    <item>
      <title>Re: How to onboard passive PA440 firewall to Panorama using dataplane interface</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-onboard-passive-pa440-firewall-to-panorama-using/m-p/1227137#M124071</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;Did you also change the 'service route' to the new interface?&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="OtakarKlier_0-1745338898641.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/67226i384D7B0FF1567CF2/image-size/medium?v=v2&amp;amp;px=400" role="button" title="OtakarKlier_0-1745338898641.png" alt="OtakarKlier_0-1745338898641.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Also is the interface setup to be a Management interface?&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="OtakarKlier_1-1745339025108.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/67227iCD77B22448115D0D/image-size/medium?v=v2&amp;amp;px=400" role="button" title="OtakarKlier_1-1745339025108.png" alt="OtakarKlier_1-1745339025108.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you did and its still not working ,I suggest utilizing the management interface and adding the route to the VPN.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Tue, 22 Apr 2025 16:24:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-onboard-passive-pa440-firewall-to-panorama-using/m-p/1227137#M124071</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2025-04-22T16:24:01Z</dc:date>
    </item>
    <item>
      <title>Re: How to onboard passive PA440 firewall to Panorama using dataplane interface</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-onboard-passive-pa440-firewall-to-panorama-using/m-p/1227146#M124075</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/653493405"&gt;@Ramesh&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;
&lt;P&gt;I need assistance integrating Palo Alto firewalls in an Active/Passive HA setup with Panorama. Below is an overview of the setup:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;At customer sites, we have Palo Alto firewalls configured in Active/Passive HA mode, and they are currently managed locally. We are now planning to integrate them with Panorama, which is hosted in the AWS cloud. An IPSec tunnel has been established between AWS and the customer sites for this purpose.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Since the management subnet at the sites does not have a route to reach Panorama in AWS, I have configured a dedicated dataplane interface solely for Panorama communication. I have also modified the service route to use this dataplane interface instead of the default management interface.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;However, because this dataplane interface is not active on the passive firewall, the passive firewall is unable to communicate with Panorama and appears as “disconnected” in Panorama.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;To onboard the firewalls into Panorama, we need to import the existing firewall configuration into Panorama and then push the configuration back to the devices. Since the passive firewall is in a disconnected state, we are unable to perform this operation.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is there a recommended workaround to address this situation?&lt;/P&gt;
&lt;P&gt;Firewall model: PA 440&lt;/P&gt;
&lt;P&gt;Software version: 11.1.4&lt;/P&gt;
&lt;P&gt;&lt;LI-WRAPPER&gt;&lt;/LI-WRAPPER&gt;&lt;/P&gt;
&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;
&lt;P&gt;In the HA setup, there's an option that allows the interfaces to be in an "UP" / online state.&amp;nbsp; I'm not sure but that might be enough to bring the dataplane port up for the service route to work.&lt;/P&gt;</description>
      <pubDate>Tue, 22 Apr 2025 18:02:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-onboard-passive-pa440-firewall-to-panorama-using/m-p/1227146#M124075</guid>
      <dc:creator>Brandon_Wertz</dc:creator>
      <dc:date>2025-04-22T18:02:14Z</dc:date>
    </item>
    <item>
      <title>Re: How to onboard passive PA440 firewall to Panorama using dataplane interface</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-onboard-passive-pa440-firewall-to-panorama-using/m-p/1227147#M124076</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/27580"&gt;@OtakarKlier&lt;/a&gt;&amp;nbsp;-- OPs issue is the secondary/passive FW isn't being seen by PAN in AWS.&amp;nbsp; The passive firewall using a service route on the DP.&amp;nbsp; The issue is since he's using an inline data port and the DP is down in a passive state the service route won't work.&amp;nbsp; (I think this is his issue)&lt;/P&gt;</description>
      <pubDate>Tue, 22 Apr 2025 18:05:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-onboard-passive-pa440-firewall-to-panorama-using/m-p/1227147#M124076</guid>
      <dc:creator>Brandon_Wertz</dc:creator>
      <dc:date>2025-04-22T18:05:08Z</dc:date>
    </item>
  </channel>
</rss>

