<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Migrate subinterface config to another interface in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/migrate-subinterface-config-to-another-interface/m-p/20086#M14622</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you !&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So here is what i will have to do:&lt;/P&gt;&lt;P&gt;I connect to the standby device in SSH and deactivate the HA:&lt;/P&gt;&lt;P&gt;request high-availability state suspend&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Then i apply all we saw just before, to replace the number of the interface, and i force the commit&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Then I have to test the new configuration by routing the traffic to the passive unit.&lt;/P&gt;&lt;P&gt;If i understand correctly I&amp;nbsp; have to reactivate the passive unit in the HA cluster,with the command:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;request high-availability state functionnal&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Then i connect to the active unit and use the commande :&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;request high-availability state suspend&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I check that everything is fine, and if so, i use the same commands on the new passive unit to modify the interface number.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Then i can reactivate the HA.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;During the test, if i see any problem, to rollback, i will just have to reactivate HA, then go on the one with the good configuration, apply a commit, is that correct ?&lt;/P&gt;&lt;P&gt;Is there a command to make the passive unit become the active ? (if the HA is correctly configured).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 01 Jul 2013 14:59:13 GMT</pubDate>
    <dc:creator>CRF</dc:creator>
    <dc:date>2013-07-01T14:59:13Z</dc:date>
    <item>
      <title>Migrate subinterface config to another interface</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/migrate-subinterface-config-to-another-interface/m-p/20082#M14618</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;here is a sample of my configuration.&lt;/P&gt;&lt;P&gt;I have trunk link (from a cisco device) to the 1/6 interface, where i configured several subinterfaces.&lt;/P&gt;&lt;P&gt;You can see that we have the 1/6.3 in the Virtual Router vr-recette in the Virtual System Recette.&lt;/P&gt;&lt;P&gt;And after that I have 1/6.206, 1/6.207,1/6.208 in the Virtual Router vr-sante in the Virtual System Sante.&lt;/P&gt;&lt;P&gt;This is a partial extract, i have in fact 11 subinterfaces in the 1/6physical interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="example1.JPG" class="jive-image-thumbnail jive-image" height="110" src="https://live.paloaltonetworks.com/legacyfs/online/7153_example1.JPG" width="896" /&gt;&lt;/P&gt;&lt;P&gt;Due to a modification in our Cisco Switches stack, the vlans which referred to 1/6.3 and 1/6.208 subinterfaces (respectively vlans 3 and 208 on the stack) will no longer be on the same stack than the others subinterfaces.&lt;/P&gt;&lt;P&gt;How can we modify the interface number of each lines that reffered to the 1/6.3 and 1/6.208 subinterfaces, for example for 1/8 physical interface (1/7 is already in use) ?&lt;/P&gt;&lt;P&gt;We have, as you imagine, a lot of rules on each Security Zones (DMZ_Recette and DMZ_Sante).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I didn't find yet any way to do it yet.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 28 Jun 2013 09:51:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/migrate-subinterface-config-to-another-interface/m-p/20082#M14618</guid>
      <dc:creator>CRF</dc:creator>
      <dc:date>2013-06-28T09:51:01Z</dc:date>
    </item>
    <item>
      <title>Re: Migrate subinterface config to another interface</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/migrate-subinterface-config-to-another-interface/m-p/20083#M14619</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You can log into the cli, and log the cli session:&lt;/P&gt;&lt;P&gt;admin&amp;gt; confiugre&lt;/P&gt;&lt;P&gt;admin# run set cli config-output-format set&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can then filter the configuration of the interface 1/6 using the "show" command, and then pressing the / button, and typing "ethernet1/6",as below. It brings the configuration of eth1/6 and its subinterfaces. I am just showing for the sub interface eth1/6.3&lt;/P&gt;&lt;P&gt;admin#show&lt;/P&gt;&lt;P&gt;/ethernet1/6&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;set network interface ethernet ethernet1/6 layer3 units ethernet1/6.3 ipv6 neighbor-discovery router-advertisement enable no&lt;/P&gt;&lt;P&gt;set network interface ethernet ethernet1/6 layer3 units ethernet1/6.3 ipv6 neighbor-discovery router-advertisement min-interval 200&lt;/P&gt;&lt;P&gt;set network interface ethernet ethernet1/6 layer3 units ethernet1/6.3 ipv6 neighbor-discovery router-advertisement max-interval 600&lt;/P&gt;&lt;P&gt;set network interface ethernet ethernet1/6 layer3 units ethernet1/6.3 ipv6 neighbor-discovery router-advertisement hop-limit 64&lt;/P&gt;&lt;P&gt;set network interface ethernet ethernet1/6 layer3 units ethernet1/6.3 ipv6 neighbor-discovery router-advertisement reachable-time unspecified&lt;/P&gt;&lt;P&gt;set network interface ethernet ethernet1/6 layer3 units ethernet1/6.3 ipv6 neighbor-discovery router-advertisement retransmission-timer unspecified&lt;/P&gt;&lt;P&gt;set network interface ethernet ethernet1/6 layer3 units ethernet1/6.3 ipv6 neighbor-discovery router-advertisement lifetime 1800&lt;/P&gt;&lt;P&gt;set network interface ethernet ethernet1/6 layer3 units ethernet1/6.3 ipv6 neighbor-discovery router-advertisement managed-flag no&lt;/P&gt;&lt;P&gt;set network interface ethernet ethernet1/6 layer3 units ethernet1/6.3 ipv6 neighbor-discovery router-advertisement other-flag no&lt;/P&gt;&lt;P&gt;set network interface ethernet ethernet1/6 layer3 units ethernet1/6.3 ipv6 neighbor-discovery router-advertisement enable-consistency-check no&lt;/P&gt;&lt;P&gt;set network interface ethernet ethernet1/6 layer3 units ethernet1/6.3 ipv6 neighbor-discovery router-advertisement link-mtu unspecified&lt;/P&gt;&lt;P&gt;set network interface ethernet ethernet1/6 layer3 units ethernet1/6.3 ipv6 neighbor-discovery enable-dad no&lt;/P&gt;&lt;P&gt;set network interface ethernet ethernet1/6 layer3 units ethernet1/6.3 ipv6 neighbor-discovery reachable-time 30&lt;/P&gt;&lt;P&gt;set network interface ethernet ethernet1/6 layer3 units ethernet1/6.3 ipv6 neighbor-discovery ns-interval 1&lt;/P&gt;&lt;P&gt;set network interface ethernet ethernet1/6 layer3 units ethernet1/6.3 ipv6 neighbor-discovery dad-attempts 1&lt;/P&gt;&lt;P&gt;set network interface ethernet ethernet1/6 layer3 units ethernet1/6.3 ipv6 enabled no&lt;/P&gt;&lt;P&gt;set network interface ethernet ethernet1/6 layer3 units ethernet1/6.3 ipv6 interface-id EUI-64&lt;/P&gt;&lt;P&gt;set network interface ethernet ethernet1/6 layer3 units ethernet1/6.3 ip 192.168.102.21/24&lt;/P&gt;&lt;P&gt;set network interface ethernet ethernet1/6 layer3 units ethernet1/6.3 adjust-tcp-mss no&lt;/P&gt;&lt;P&gt;set network interface ethernet ethernet1/6 layer3 units ethernet1/6.3 tag 3&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Open the notepad on which the logs are being written to. replace the word "set" with "delete", so that we are gonna delete the eth1/6 references. Copy paste all these output again, and replace eth1/6 with eth1/8, so that you should have the output of the format &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;set config devices localhost.localdomain network interface ethernet ethernet1/8 layer3 units ethernet1/8.3 ipv6 enabled no&lt;/P&gt;&lt;P&gt;set config devices localhost.localdomain network interface ethernet ethernet1/8 layer3 units ethernet1/8.3 ipv6 interface-id EUI-64&lt;/P&gt;&lt;P&gt;set config devices localhost.localdomain network interface ethernet ethernet1/8 layer3 units ethernet1/8.3 ip 192.168.102.21/24&lt;/P&gt;&lt;P&gt;set config devices localhost.localdomain network interface ethernet ethernet1/8 layer3 units ethernet1/8.3 adjust-tcp-mss no&lt;/P&gt;&lt;P&gt;set config devices localhost.localdomain network interface ethernet ethernet1/8 layer3 units ethernet1/8.3 tag 3&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Go back to the cli&lt;/P&gt;&lt;P&gt;and then paste all the "delete" and the "set" commands for the eth1/6 and eth1/8 respectively&lt;/P&gt;&lt;P&gt;once pasted, commit the configuration&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;admin#&lt;/P&gt;&lt;P&gt;delete config devices localhost.localdomain network interface ethernet ethernet1/6 layer3 units ethernet1/6.3 ipv6 enabled no&lt;/P&gt;&lt;P&gt;delete config devices localhost.localdomain network interface ethernet ethernet1/6 layer3 units ethernet1/6.3 ipv6 interface-id EUI-64&lt;/P&gt;&lt;P&gt;delete config devices localhost.localdomain network interface ethernet ethernet1/6 layer3 units ethernet1/6.3 ip 192.168.102.21/24&lt;/P&gt;&lt;P&gt;delete config devices localhost.localdomain network interface ethernet ethernet1/6 layer3 units ethernet1/6.3 adjust-tcp-mss no&lt;/P&gt;&lt;P&gt;delete config devices localhost.localdomain network interface ethernet ethernet1/6 layer3 units ethernet1/6.3 tag 3&lt;/P&gt;&lt;P&gt;set config devices localhost.localdomain network interface ethernet ethernet1/8 layer3 units ethernet1/8.3 ipv6 enabled no&lt;/P&gt;&lt;P&gt;set config devices localhost.localdomain network interface ethernet ethernet1/8 layer3 units ethernet1/8.3 ipv6 interface-id EUI-64&lt;/P&gt;&lt;P&gt;set config devices localhost.localdomain network interface ethernet ethernet1/8 layer3 units ethernet1/8.3 ip 192.168.102.21/24&lt;/P&gt;&lt;P&gt;set config devices localhost.localdomain network interface ethernet ethernet1/8 layer3 units ethernet1/8.3 adjust-tcp-mss no&lt;/P&gt;&lt;P&gt;set config devices localhost.localdomain network interface ethernet ethernet1/8 layer3 units ethernet1/8.3 tag 3&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;admin# commit force&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 28 Jun 2013 14:00:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/migrate-subinterface-config-to-another-interface/m-p/20083#M14619</guid>
      <dc:creator>kprakash</dc:creator>
      <dc:date>2013-06-28T14:00:54Z</dc:date>
    </item>
    <item>
      <title>Re: Migrate subinterface config to another interface</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/migrate-subinterface-config-to-another-interface/m-p/20084#M14620</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you for answering&lt;/P&gt;&lt;P&gt;So this is how i will proceed:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'Tahoma','sans-serif'; font-size: 10pt;"&gt;delete network interface ethernet ethernet1/6 layer3 units ethernet1/6.3 mtu 1500&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'Tahoma','sans-serif'; font-size: 10pt;"&gt;delete network interface ethernet ethernet1/6 layer3 units ethernet1/6.3 interface-management-profile Ping&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'Tahoma','sans-serif'; font-size: 10pt;"&gt;delete network interface ethernet ethernet1/6 layer3 units ethernet1/6.3 tag 3&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'Tahoma','sans-serif'; font-size: 10pt;"&gt;delete network interface ethernet ethernet1/6 layer3 units ethernet1/6.3 ip 192.168.102.21/24&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'Tahoma','sans-serif'; font-size: 10pt;"&gt;delete network interface ethernet ethernet1/6 layer3 units ethernet1/6.3 ipv6 enabled no&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'Tahoma','sans-serif'; font-size: 10pt;"&gt;delete network interface ethernet ethernet1/6 layer3 units ethernet1/6.3 ipv6 neighbor-discovery enable-dad no&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'Tahoma','sans-serif'; font-size: 10pt;"&gt;delete network virtual-router vr-recette interface ethernet1/6.3&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'Tahoma','sans-serif'; font-size: 10pt;"&gt;delete vsys vsys2 import network interface ethernet1/6.3&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'Tahoma','sans-serif'; font-size: 10pt;"&gt;delete vsys vsys2 zone DMZ_Recette network layer3 ethernet1/6.3&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'Tahoma','sans-serif'; font-size: 10pt;"&gt;set network interface ethernet ethernet1/8 layer3 units ethernet1/8.3 mtu 1500&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'Tahoma','sans-serif'; font-size: 10pt;"&gt;set network interface ethernet ethernet1/8 layer3 units ethernet1/8.3 interface-management-profile Ping&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'Tahoma','sans-serif'; font-size: 10pt;"&gt;set network interface ethernet ethernet1/8 layer3 units ethernet1/8.3 tag 3&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'Tahoma','sans-serif'; font-size: 10pt;"&gt;set network interface ethernet ethernet1/8 layer3 units ethernet1/8.3 ip 192.168.102.21/24&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'Tahoma','sans-serif'; font-size: 10pt;"&gt;set network interface ethernet ethernet1/8 layer3 units ethernet1/8.3 ipv6 enabled no&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'Tahoma','sans-serif'; font-size: 10pt;"&gt;set network interface ethernet ethernet1/8 layer3 units ethernet1/8.3 ipv6 neighbor-discovery enable-dad no&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'Tahoma','sans-serif'; font-size: 10pt;"&gt;set network virtual-router vr-recette interface ethernet1/8.3&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'Tahoma','sans-serif'; font-size: 10pt;"&gt;set vsys vsys2 import network interface ethernet1/8.3&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'Tahoma','sans-serif'; font-size: 10pt;"&gt;set vsys vsys2 zone DMZ_Recette network layer3 ethernet1/8.3&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'Tahoma','sans-serif'; font-size: 10pt;"&gt;For your example you did't talk about this configuration:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'Tahoma','sans-serif'; font-size: 10pt;"&gt;set network virtual-router vr-recette interface ethernet1/8.3&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'Tahoma','sans-serif'; font-size: 10pt;"&gt;set vsys vsys2 import network interface ethernet1/8.3&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'Tahoma','sans-serif'; font-size: 10pt;"&gt;set vsys vsys2 zone DMZ_Recette network layer3 ethernet1/8.3&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is it correct ? Was-it a forgetting ?&lt;/P&gt;&lt;P&gt;If this is correct, when i will put these commands, il will be on a anctive/standby architecture.&lt;/P&gt;&lt;P&gt;How can i desactive the failover in order to be sure that everything went ok. Then i will reactivate the failover to propagate the rules to the other unit.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 01 Jul 2013 08:36:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/migrate-subinterface-config-to-another-interface/m-p/20084#M14620</guid>
      <dc:creator>CRF</dc:creator>
      <dc:date>2013-07-01T08:36:04Z</dc:date>
    </item>
    <item>
      <title>Re: Migrate subinterface config to another interface</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/migrate-subinterface-config-to-another-interface/m-p/20085#M14621</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi CRF,&lt;/P&gt;&lt;P&gt;I did not paste the configuration of the lines, my bad, but you are correct. You need these lines as well:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="font-size: 12px; font-family: Arial, Helvetica, sans-serif; color: #000000; background-color: #ffffff;"&gt;&lt;SPAN style="font-style: inherit; font-size: 10pt; font-family: Tahoma, sans-serif;"&gt;delete network virtual-router vr-recette interface ethernet1/6.3&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-size: 12px; font-family: Arial, Helvetica, sans-serif; color: #000000; background-color: #ffffff;"&gt;&lt;SPAN style="font-style: inherit; font-size: 10pt; font-family: Tahoma, sans-serif;"&gt;delete vsys vsys2 import network interface ethernet1/6.3&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-size: 12px; font-family: Arial, Helvetica, sans-serif; color: #000000; background-color: #ffffff;"&gt;&lt;SPAN style="font-style: inherit; font-size: 10pt; font-family: Tahoma, sans-serif;"&gt;delete vsys vsys2 zone DMZ_Recette network layer3 ethernet1/6.3&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-size: 12px; font-family: Arial, Helvetica, sans-serif; color: #000000; background-color: #ffffff;"&gt;&lt;SPAN style="font-style: inherit; font-size: 10pt; font-family: Tahoma, sans-serif;"&gt;set network virtual-router vr-recette interface ethernet1/8.3&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-size: 12px; font-family: Arial, Helvetica, sans-serif; color: #000000; background-color: #ffffff;"&gt;&lt;SPAN style="font-style: inherit; font-size: 10pt; font-family: Tahoma, sans-serif;"&gt;set vsys vsys2 import network interface ethernet1/8.3&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-size: 12px; font-family: Arial, Helvetica, sans-serif; color: #000000; background-color: #ffffff;"&gt;&lt;SPAN style="font-style: inherit; font-size: 10pt; font-family: Tahoma, sans-serif;"&gt;set vsys vsys2 zone DMZ_Recette network layer3 ethernet1/8.3&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-size: 12px; font-family: Arial, Helvetica, sans-serif; color: #000000; background-color: #ffffff;"&gt;&lt;SPAN style="font-style: inherit; font-size: 10pt; font-family: Tahoma, sans-serif;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-size: 12px; font-family: Arial, Helvetica, sans-serif; color: #000000; background-color: #ffffff;"&gt;&lt;SPAN style="font-style: inherit; font-size: 10pt; font-family: Tahoma, sans-serif;"&gt;When you commit the PANFW, with all these changes, the configuration will be automatically pushed to both the devices in the cluster. But if you want to test this out on one box first, you can remove the passive box from the cluster, by disabling the HA, under the HA settings (Also be careful that you do not run into a split brain scenario). You can then apply these changes on this box and commit them, and test the traffic. If they work as expected, you can then apply these changes on the active box too, and bring back the other box into the HA cluster.&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 01 Jul 2013 12:48:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/migrate-subinterface-config-to-another-interface/m-p/20085#M14621</guid>
      <dc:creator>kprakash</dc:creator>
      <dc:date>2013-07-01T12:48:42Z</dc:date>
    </item>
    <item>
      <title>Re: Migrate subinterface config to another interface</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/migrate-subinterface-config-to-another-interface/m-p/20086#M14622</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you !&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So here is what i will have to do:&lt;/P&gt;&lt;P&gt;I connect to the standby device in SSH and deactivate the HA:&lt;/P&gt;&lt;P&gt;request high-availability state suspend&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Then i apply all we saw just before, to replace the number of the interface, and i force the commit&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Then I have to test the new configuration by routing the traffic to the passive unit.&lt;/P&gt;&lt;P&gt;If i understand correctly I&amp;nbsp; have to reactivate the passive unit in the HA cluster,with the command:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;request high-availability state functionnal&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Then i connect to the active unit and use the commande :&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;request high-availability state suspend&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I check that everything is fine, and if so, i use the same commands on the new passive unit to modify the interface number.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Then i can reactivate the HA.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;During the test, if i see any problem, to rollback, i will just have to reactivate HA, then go on the one with the good configuration, apply a commit, is that correct ?&lt;/P&gt;&lt;P&gt;Is there a command to make the passive unit become the active ? (if the HA is correctly configured).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 01 Jul 2013 14:59:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/migrate-subinterface-config-to-another-interface/m-p/20086#M14622</guid>
      <dc:creator>CRF</dc:creator>
      <dc:date>2013-07-01T14:59:13Z</dc:date>
    </item>
    <item>
      <title>Re: Migrate subinterface config to another interface</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/migrate-subinterface-config-to-another-interface/m-p/20087#M14623</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi CRF,&lt;/P&gt;&lt;P&gt;Yes, you are right again. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1) You will suspend the current passive box: request high-availability state suspend&lt;/P&gt;&lt;P&gt;2) Apply the changes and force the commit&lt;/P&gt;&lt;P&gt;3) Make the current box functional. The box will still remain passive, and there will be a mismatch in the running configuration on both the active and the passive devices&lt;/P&gt;&lt;P&gt;4) Now test the traffic by suspending the current active box, and make it functional and&amp;nbsp; passive:&lt;/P&gt;&lt;P&gt; &amp;gt;request high-availability state suspend&lt;/P&gt;&lt;P&gt;&amp;gt;request high-availability state functional ( on the suspended box)&lt;/P&gt;&lt;P&gt;5) If everything is fine, you can synchronize the running configuration, from the new active box&lt;/P&gt;&lt;P&gt;&amp;gt; request high-availability sync-to-remote running-config ( on the current active box)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If at all you encounter any issues, suspend the current active box ( with the new interface config. Bring back this box to passive ), and then synchronize the running configuration from the active box.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;BR,&lt;/P&gt;&lt;P&gt;Karthik &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 02 Jul 2013 19:51:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/migrate-subinterface-config-to-another-interface/m-p/20087#M14623</guid>
      <dc:creator>kprakash</dc:creator>
      <dc:date>2013-07-02T19:51:03Z</dc:date>
    </item>
  </channel>
</rss>

