<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Pannorama and HA Cluster in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/pannorama-and-ha-cluster/m-p/4547#M3352</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;What about if i have HA Cluster and i do service route for the Panorama through the untrust interface?&lt;/P&gt;&lt;P&gt;Panorama will see both of the device with the same IP right? so how will the configuration be pushed to both of the devices?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 30 Oct 2013 12:12:21 GMT</pubDate>
    <dc:creator>minow</dc:creator>
    <dc:date>2013-10-30T12:12:21Z</dc:date>
    <item>
      <title>Pannorama and HA Cluster</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pannorama-and-ha-cluster/m-p/4545#M3350</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hey&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i would like to know how the commit process works when i push commit on pannoaram to HA device group.&lt;/P&gt;&lt;P&gt;1) does Panorama send the configuration to both of the device and then commit it?&lt;/P&gt;&lt;P&gt;2) does Panorama send it only to one device and it commits it to the other device?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i have a situation of a PA HA cluster, and only one device was inserted to the Panorama and the result was that both of the device were synced but the policy was actually exists on one of the devices and on the other device there was no policy. from this i assume that panorama probably insert the serial number of the "to be deployed" PA device when it sends the policy to the device,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i would like see the white papers of this process &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thank you&lt;/P&gt;&lt;P&gt;dor&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 29 Oct 2013 13:15:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pannorama-and-ha-cluster/m-p/4545#M3350</guid>
      <dc:creator>minow</dc:creator>
      <dc:date>2013-10-29T13:15:10Z</dc:date>
    </item>
    <item>
      <title>Re: Pannorama and HA Cluster</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pannorama-and-ha-cluster/m-p/4546#M3351</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You would have to add both the serial numbers of the HA member device in order to push the config to them from the Panorama. If you send the configuration from the Panorama to only one device , the Panorama pushed&amp;nbsp; config does not sync up between two HA pairs. You can add the two devices in one device group and pushed the configuration to them.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 29 Oct 2013 13:38:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pannorama-and-ha-cluster/m-p/4546#M3351</guid>
      <dc:creator>shasnain</dc:creator>
      <dc:date>2013-10-29T13:38:06Z</dc:date>
    </item>
    <item>
      <title>Re: Pannorama and HA Cluster</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pannorama-and-ha-cluster/m-p/4547#M3352</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;What about if i have HA Cluster and i do service route for the Panorama through the untrust interface?&lt;/P&gt;&lt;P&gt;Panorama will see both of the device with the same IP right? so how will the configuration be pushed to both of the devices?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 30 Oct 2013 12:12:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pannorama-and-ha-cluster/m-p/4547#M3352</guid>
      <dc:creator>minow</dc:creator>
      <dc:date>2013-10-30T12:12:21Z</dc:date>
    </item>
    <item>
      <title>Re: Pannorama and HA Cluster</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pannorama-and-ha-cluster/m-p/4548#M3353</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If you use untrust interface of the device as service route, the configuration will be pushed only to active device (assuming policies are configured correctly) because only 1 ip is active at a time for active/passive, even though you have same ip on both device.&amp;nbsp; Suggested configuration would be to use management interface itself. Since management ip address are unique for both device, you will not have any issues and will prevent extra bandwidth consumption on untrust interface. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 01 Nov 2013 14:14:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pannorama-and-ha-cluster/m-p/4548#M3353</guid>
      <dc:creator>ssharma</dc:creator>
      <dc:date>2013-11-01T14:14:32Z</dc:date>
    </item>
    <item>
      <title>Re: Pannorama and HA Cluster</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pannorama-and-ha-cluster/m-p/4549#M3354</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;it depands.... because panorama will also manage PA device through VPN&amp;nbsp; S2S and that will make my the connection between the panorama and the device rely on the VPN conneciton, so i cannot really move all the functionality from the device to the panorama&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i would like to see that ability that Panorama will push the configuration to the active one and then the policy will be synced to the other one... &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;this is already done when i change for example the Interface of one PA device and push commit, the changed will also be done on the other device because most of the configuration are global to the HA Cluster, then the configuration can be done on a shared template for both of the device and specific configuration will be done on the device. (in all cases i am talking on active passive cluster)&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 03 Nov 2013 08:22:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pannorama-and-ha-cluster/m-p/4549#M3354</guid>
      <dc:creator>minow</dc:creator>
      <dc:date>2013-11-03T08:22:23Z</dc:date>
    </item>
    <item>
      <title>Re: Pannorama and HA Cluster</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pannorama-and-ha-cluster/m-p/4550#M3355</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Panorama pushed config does not sync over from the Active PA to the Passive PA. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 04 Nov 2013 15:01:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pannorama-and-ha-cluster/m-p/4550#M3355</guid>
      <dc:creator>shasnain</dc:creator>
      <dc:date>2013-11-04T15:01:53Z</dc:date>
    </item>
  </channel>
</rss>

