<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How do you Commit the configuration of a Panorama to an existing HA Pair of 5060s? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/how-do-you-commit-the-configuration-of-a-panorama-to-an-existing/m-p/26410#M19260</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-family: Times New Roman; font-size: 12pt;"&gt; &lt;/SPAN&gt;&lt;SPAN style="color: #000000; font-size: 12pt; font-family: Calibri;"&gt;I followed the instructions from “Panorama-Device-Migration-Tech_Note-revB.pdf” using the CLI method to capture the configuration of an HA Pair of 5060 running PAN OS 5.0.11 and paste it to the Panorama running PAN OS 6.0. The Migration Checklist states during the cutover process to cutover 1 firewall first. The document states after deleting the Rules, objects etc. on the FW, when committing the configuration to the HA pair, follow the documented HA procedure to minimize network impact. What are they referring to when they say “follow the documented HA procedure? I cannot find anything referencing what they mean. I figure I should leave the passive FW alone and do the Active one first because when doing a commit on the Active FW it usually pushes the configuration to the Passive FW.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-family: Times New Roman; font-size: 12pt;"&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-size: 12pt; font-family: Calibri;"&gt;But, What impact does the Device Group have when you set the FWs up as an HA pair in the Device Group? Also, when deleting the items from the Active FW, should I also delete them from the Passive FW?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-family: Times New Roman; font-size: 12pt;"&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-size: 12pt; font-family: Calibri;"&gt;Another approach that I have read is to rename the objects, policies etc. on the Panorama then commit it to the FWs. What does that do to the existing configuration on the FW? Is there now a duplicate configuration with a different set of names? Or does it overwrite the existing configuration?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-family: Times New Roman; font-size: 12pt;"&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-size: 12pt; font-family: Calibri;"&gt;Lots of questions and scenarios that I cannot find answers to anywhere.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-family: Times New Roman; font-size: 12pt;"&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 05 Mar 2014 16:32:47 GMT</pubDate>
    <dc:creator>Nonno1</dc:creator>
    <dc:date>2014-03-05T16:32:47Z</dc:date>
    <item>
      <title>How do you Commit the configuration of a Panorama to an existing HA Pair of 5060s?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-do-you-commit-the-configuration-of-a-panorama-to-an-existing/m-p/26410#M19260</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-family: Times New Roman; font-size: 12pt;"&gt; &lt;/SPAN&gt;&lt;SPAN style="color: #000000; font-size: 12pt; font-family: Calibri;"&gt;I followed the instructions from “Panorama-Device-Migration-Tech_Note-revB.pdf” using the CLI method to capture the configuration of an HA Pair of 5060 running PAN OS 5.0.11 and paste it to the Panorama running PAN OS 6.0. The Migration Checklist states during the cutover process to cutover 1 firewall first. The document states after deleting the Rules, objects etc. on the FW, when committing the configuration to the HA pair, follow the documented HA procedure to minimize network impact. What are they referring to when they say “follow the documented HA procedure? I cannot find anything referencing what they mean. I figure I should leave the passive FW alone and do the Active one first because when doing a commit on the Active FW it usually pushes the configuration to the Passive FW.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-family: Times New Roman; font-size: 12pt;"&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-size: 12pt; font-family: Calibri;"&gt;But, What impact does the Device Group have when you set the FWs up as an HA pair in the Device Group? Also, when deleting the items from the Active FW, should I also delete them from the Passive FW?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-family: Times New Roman; font-size: 12pt;"&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-size: 12pt; font-family: Calibri;"&gt;Another approach that I have read is to rename the objects, policies etc. on the Panorama then commit it to the FWs. What does that do to the existing configuration on the FW? Is there now a duplicate configuration with a different set of names? Or does it overwrite the existing configuration?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-family: Times New Roman; font-size: 12pt;"&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-size: 12pt; font-family: Calibri;"&gt;Lots of questions and scenarios that I cannot find answers to anywhere.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-family: Times New Roman; font-size: 12pt;"&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 05 Mar 2014 16:32:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-do-you-commit-the-configuration-of-a-panorama-to-an-existing/m-p/26410#M19260</guid>
      <dc:creator>Nonno1</dc:creator>
      <dc:date>2014-03-05T16:32:47Z</dc:date>
    </item>
    <item>
      <title>Re: How do you Commit the configuration of a Panorama to an existing HA Pair of 5060s?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-do-you-commit-the-configuration-of-a-panorama-to-an-existing/m-p/26411#M19261</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Nonno1,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Point-1: We will add devices into Panorama based on their Serial number, and it does not matter from Panorama point of view, whether the devices are standalone or in HA. The panorama will always treat as an individual device. Please follow the mentioned KB article to understand information synchronized in HA pair &lt;A href="https://live.paloaltonetworks.com/docs/DOC-4175"&gt;Information Synchronized in an HA Pair&lt;/A&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="HA-sync-to-peer.JPG.jpg" class="jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/11961_HA-sync-to-peer.JPG.jpg" style="width: 620px; height: 132px;" /&gt;&lt;/P&gt;&lt;P&gt;NOTE: If you use &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;untrust&lt;/SPAN&gt;&lt;/SPAN&gt; interface of the device as service route, the configuration will be pushed only to active device (assuming policies are configured correctly) because only 1 IP is active at a time for active/passive, even though you have the same IP on both devices.&amp;nbsp; Suggested configuration would be to use management interface itself. Since the management IP address is unique for both devices, you will not have any issues and will prevent extra bandwidth consumption on &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;untrust&lt;/SPAN&gt;&lt;/SPAN&gt; interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Point-2: If you want to merge the panorama pushed config with your PAN FW local config, you should use the option "&lt;EM&gt;merge with candidate config&lt;/EM&gt;". But if you want to override your FW config with Panorama pushed config, then you have to check the option "&lt;EM&gt;Force template values"&lt;/EM&gt;.&lt;/P&gt;&lt;P&gt;&lt;IMG __jive_id="11960" alt="Panorama-commit.JPG.jpg" class="jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/11960_Panorama-commit.JPG.jpg" /&gt;&lt;/P&gt;&lt;P&gt;Hope this helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 05 Mar 2014 20:29:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-do-you-commit-the-configuration-of-a-panorama-to-an-existing/m-p/26411#M19261</guid>
      <dc:creator>HULK</dc:creator>
      <dc:date>2014-03-05T20:29:05Z</dc:date>
    </item>
    <item>
      <title>Re: How do you Commit the configuration of a Panorama to an existing HA Pair of 5060s?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-do-you-commit-the-configuration-of-a-panorama-to-an-existing/m-p/26412#M19262</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I will give this a try. &lt;/P&gt;&lt;P&gt;Our SE answered my question this morning also. The only addition he made was to Disable Config Sync in the FWs before pushing configuration from Panorama.&lt;/P&gt;&lt;P&gt;Thank You&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 06 Mar 2014 13:33:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-do-you-commit-the-configuration-of-a-panorama-to-an-existing/m-p/26412#M19262</guid>
      <dc:creator>Nonno1</dc:creator>
      <dc:date>2014-03-06T13:33:36Z</dc:date>
    </item>
  </channel>
</rss>

