<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Panorama in HA in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/panorama-in-ha/m-p/27453#M20013</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;found--&amp;gt;&lt;/P&gt;&lt;P&gt;(admin guide) &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;SPAN style="font-size: 24pt; font-family: TwCenMT-Bold; "&gt;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P align="left"&gt;Configuring HA&lt;/P&gt;&lt;SPAN style="font-size: 10pt; font-family: Wingdings3; "&gt;&lt;P align="left"&gt;&lt;/P&gt;&lt;P align="left"&gt;&lt;STRONG&gt;&lt;EM&gt;&lt;SPAN style="font-size: 10pt; font-family: Times New Roman; "&gt;Panorama &amp;gt; High Availability&lt;/SPAN&gt;&lt;STRONG&gt;&lt;EM&gt;&lt;EM&gt;&lt;SPAN style="font-size: 10pt; font-family: Times New Roman; "&gt;&lt;/SPAN&gt;&lt;/EM&gt;&lt;/EM&gt;&lt;/STRONG&gt;&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P align="left"&gt;To support HA for Panorama, you can configure two Panorama devices to provide synchronized&lt;/P&gt;&lt;P align="left"&gt;connections to the managed firewalls. One Panorama device is designated as active and the other as&lt;/P&gt;&lt;P align="left"&gt;passive. If the active Panorama device becomes unavailable, the passive server takes over temporarily.&lt;/P&gt;&lt;P align="left"&gt;If preemption is enabled and the active device becomes available again, the passive device relinquishes&lt;/P&gt;&lt;P align="left"&gt;control and returns to the passive state.&lt;/P&gt;&lt;P align="left"&gt;HA for Panorama also involves the assignment of a primary device and secondary device for logging&lt;/P&gt;&lt;P align="left"&gt;purposes.&lt;/P&gt;&lt;P align="left"&gt;You can configure Panorama to use the same log external storage facility for the primary and secondary&lt;/P&gt;&lt;P align="left"&gt;devices (Network File System or NFS option) or configure logging internally. If the NFS option is&lt;/P&gt;&lt;P align="left"&gt;enabled, then during normal operations only the primary device receives the logs that are sent from the&lt;/P&gt;&lt;P align="left"&gt;managed firewalls. If local logging is enabled, then by default logs are sent to the primary and&lt;/P&gt;&lt;P align="left"&gt;secondary devices.&lt;/P&gt;&lt;P align="left"&gt;Configure the followings settings to enable HA on Panorama.&lt;/P&gt;&lt;/SPAN&gt;&lt;STRONG&gt;&lt;EM style=": ; font-size: 10pt; font-family: Times New Roman; "&gt;&lt;P align="left"&gt;Note:&lt;/P&gt;&lt;/EM&gt;&lt;EM&gt;&lt;SPAN style="font-size: 10pt; font-family: Times New Roman; "&gt;&lt;P align="left"&gt;&lt;/P&gt;&lt;P align="left"&gt;not backward compatible with Release 3.1 or earlier.&lt;/P&gt;&lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt; font-family: Times New Roman; "&gt;HA is supported only for managed devices running Release 4.0 or later. It is&lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN style="font-size: 10pt; font-family: Times New Roman; "&gt;&lt;P align="left"&gt;Note:&lt;/P&gt;&lt;P align="left"&gt;functionality.&lt;/P&gt;&lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt; font-family: Times New Roman; "&gt;HA requires two Panorama licenses and unique serial numbers for&lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN style="font-size: 12pt; font-family: TwCenMT-Bold; "&gt;&lt;P align="left"&gt;Table 130. Panorama HA Settings&lt;/P&gt;&lt;P align="left"&gt;Field Description&lt;/P&gt;&lt;P align="left"&gt;Setup&lt;/P&gt;&lt;/SPAN&gt;&lt;SPAN style="font-size: 8pt; font-family: Times New Roman; "&gt;&lt;P align="left"&gt;Enable HA Select the check box to enable HA.&lt;/P&gt;&lt;P align="left"&gt;Peer HA IP Address Enter the IP address of the HA1 interface that is specified in the Control Link section&lt;/P&gt;&lt;P align="left"&gt;of the other firewall.&lt;/P&gt;&lt;P align="left"&gt;Enable Encryption Select the check box to enable encryption for the synchronization link between the&lt;/P&gt;&lt;P align="left"&gt;active and passive Panorama devices.&lt;/P&gt;&lt;/SPAN&gt;&lt;STRONG&gt;&lt;EM style=": ; font-size: 8pt; font-family: Times New Roman; "&gt;&lt;P align="left"&gt;Note:&lt;/P&gt;&lt;/EM&gt;&lt;EM&gt;&lt;SPAN style="font-size: 8pt; font-family: Times New Roman; "&gt;&lt;P align="left"&gt;&lt;/P&gt;&lt;P align="left"&gt;49160 when encryption is not enabled.&lt;/P&gt;&lt;/SPAN&gt;&lt;SPAN style="font-size: 8pt; font-family: Times New Roman; "&gt;HA connectivity uses TCP port 28 with encryption enabled and 28769 and&lt;/SPAN&gt;&lt;SPAN style="font-size: 8pt; font-family: Times New Roman; "&gt;&lt;P align="left"&gt;Monitor Hold Time&lt;/P&gt;&lt;P align="left"&gt;(ms)&lt;/P&gt;&lt;P align="left"&gt;Enter the length of time (ms) that the system will wait before acting on the control&lt;/P&gt;&lt;P&gt;link failure (1000-60000 ms, default 3000 ms).&lt;/P&gt;&lt;/SPAN&gt;&lt;/EM&gt;&lt;/STRONG&gt;&lt;/STRONG&gt;&lt;/STRONG&gt;&lt;/EM&gt;&lt;/STRONG&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 15 Feb 2012 07:45:46 GMT</pubDate>
    <dc:creator>angel.camacho</dc:creator>
    <dc:date>2012-02-15T07:45:46Z</dc:date>
    <item>
      <title>Panorama in HA</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/panorama-in-ha/m-p/27452#M20012</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi there!&lt;/P&gt;&lt;P&gt;I would like to know if someone is using the Management Panorama in HA (Primary and Secondary). I was looking for information about, but i could not find anything.&lt;/P&gt;&lt;P&gt;Thanks in advance!&lt;/P&gt;&lt;P&gt;Angel. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 15 Feb 2012 07:34:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/panorama-in-ha/m-p/27452#M20012</guid>
      <dc:creator>angel.camacho</dc:creator>
      <dc:date>2012-02-15T07:34:19Z</dc:date>
    </item>
    <item>
      <title>Re: Panorama in HA</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/panorama-in-ha/m-p/27453#M20013</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;found--&amp;gt;&lt;/P&gt;&lt;P&gt;(admin guide) &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;SPAN style="font-size: 24pt; font-family: TwCenMT-Bold; "&gt;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P align="left"&gt;Configuring HA&lt;/P&gt;&lt;SPAN style="font-size: 10pt; font-family: Wingdings3; "&gt;&lt;P align="left"&gt;&lt;/P&gt;&lt;P align="left"&gt;&lt;STRONG&gt;&lt;EM&gt;&lt;SPAN style="font-size: 10pt; font-family: Times New Roman; "&gt;Panorama &amp;gt; High Availability&lt;/SPAN&gt;&lt;STRONG&gt;&lt;EM&gt;&lt;EM&gt;&lt;SPAN style="font-size: 10pt; font-family: Times New Roman; "&gt;&lt;/SPAN&gt;&lt;/EM&gt;&lt;/EM&gt;&lt;/STRONG&gt;&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P align="left"&gt;To support HA for Panorama, you can configure two Panorama devices to provide synchronized&lt;/P&gt;&lt;P align="left"&gt;connections to the managed firewalls. One Panorama device is designated as active and the other as&lt;/P&gt;&lt;P align="left"&gt;passive. If the active Panorama device becomes unavailable, the passive server takes over temporarily.&lt;/P&gt;&lt;P align="left"&gt;If preemption is enabled and the active device becomes available again, the passive device relinquishes&lt;/P&gt;&lt;P align="left"&gt;control and returns to the passive state.&lt;/P&gt;&lt;P align="left"&gt;HA for Panorama also involves the assignment of a primary device and secondary device for logging&lt;/P&gt;&lt;P align="left"&gt;purposes.&lt;/P&gt;&lt;P align="left"&gt;You can configure Panorama to use the same log external storage facility for the primary and secondary&lt;/P&gt;&lt;P align="left"&gt;devices (Network File System or NFS option) or configure logging internally. If the NFS option is&lt;/P&gt;&lt;P align="left"&gt;enabled, then during normal operations only the primary device receives the logs that are sent from the&lt;/P&gt;&lt;P align="left"&gt;managed firewalls. If local logging is enabled, then by default logs are sent to the primary and&lt;/P&gt;&lt;P align="left"&gt;secondary devices.&lt;/P&gt;&lt;P align="left"&gt;Configure the followings settings to enable HA on Panorama.&lt;/P&gt;&lt;/SPAN&gt;&lt;STRONG&gt;&lt;EM style=": ; font-size: 10pt; font-family: Times New Roman; "&gt;&lt;P align="left"&gt;Note:&lt;/P&gt;&lt;/EM&gt;&lt;EM&gt;&lt;SPAN style="font-size: 10pt; font-family: Times New Roman; "&gt;&lt;P align="left"&gt;&lt;/P&gt;&lt;P align="left"&gt;not backward compatible with Release 3.1 or earlier.&lt;/P&gt;&lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt; font-family: Times New Roman; "&gt;HA is supported only for managed devices running Release 4.0 or later. It is&lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN style="font-size: 10pt; font-family: Times New Roman; "&gt;&lt;P align="left"&gt;Note:&lt;/P&gt;&lt;P align="left"&gt;functionality.&lt;/P&gt;&lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt; font-family: Times New Roman; "&gt;HA requires two Panorama licenses and unique serial numbers for&lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN style="font-size: 12pt; font-family: TwCenMT-Bold; "&gt;&lt;P align="left"&gt;Table 130. Panorama HA Settings&lt;/P&gt;&lt;P align="left"&gt;Field Description&lt;/P&gt;&lt;P align="left"&gt;Setup&lt;/P&gt;&lt;/SPAN&gt;&lt;SPAN style="font-size: 8pt; font-family: Times New Roman; "&gt;&lt;P align="left"&gt;Enable HA Select the check box to enable HA.&lt;/P&gt;&lt;P align="left"&gt;Peer HA IP Address Enter the IP address of the HA1 interface that is specified in the Control Link section&lt;/P&gt;&lt;P align="left"&gt;of the other firewall.&lt;/P&gt;&lt;P align="left"&gt;Enable Encryption Select the check box to enable encryption for the synchronization link between the&lt;/P&gt;&lt;P align="left"&gt;active and passive Panorama devices.&lt;/P&gt;&lt;/SPAN&gt;&lt;STRONG&gt;&lt;EM style=": ; font-size: 8pt; font-family: Times New Roman; "&gt;&lt;P align="left"&gt;Note:&lt;/P&gt;&lt;/EM&gt;&lt;EM&gt;&lt;SPAN style="font-size: 8pt; font-family: Times New Roman; "&gt;&lt;P align="left"&gt;&lt;/P&gt;&lt;P align="left"&gt;49160 when encryption is not enabled.&lt;/P&gt;&lt;/SPAN&gt;&lt;SPAN style="font-size: 8pt; font-family: Times New Roman; "&gt;HA connectivity uses TCP port 28 with encryption enabled and 28769 and&lt;/SPAN&gt;&lt;SPAN style="font-size: 8pt; font-family: Times New Roman; "&gt;&lt;P align="left"&gt;Monitor Hold Time&lt;/P&gt;&lt;P align="left"&gt;(ms)&lt;/P&gt;&lt;P align="left"&gt;Enter the length of time (ms) that the system will wait before acting on the control&lt;/P&gt;&lt;P&gt;link failure (1000-60000 ms, default 3000 ms).&lt;/P&gt;&lt;/SPAN&gt;&lt;/EM&gt;&lt;/STRONG&gt;&lt;/STRONG&gt;&lt;/STRONG&gt;&lt;/EM&gt;&lt;/STRONG&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 15 Feb 2012 07:45:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/panorama-in-ha/m-p/27453#M20013</guid>
      <dc:creator>angel.camacho</dc:creator>
      <dc:date>2012-02-15T07:45:46Z</dc:date>
    </item>
  </channel>
</rss>

