<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PA200 disaster recovery option...? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/pa200-disaster-recovery-option/m-p/71288#M40748</link>
    <description>&lt;P&gt;Thank you, both.. &amp;nbsp;I'll probably go with the cold-spare until I can figure out the sub-interface config. &amp;nbsp;These PA's are pretty neat! &amp;nbsp;Always learning... &amp;nbsp;&lt;span class="lia-unicode-emoji" title=":grinning_face_with_smiling_eyes:"&gt;😄&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 20 Jan 2016 20:08:10 GMT</pubDate>
    <dc:creator>thatguy</dc:creator>
    <dc:date>2016-01-20T20:08:10Z</dc:date>
    <item>
      <title>PA200 disaster recovery option...?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa200-disaster-recovery-option/m-p/71279#M40741</link>
      <description>&lt;P&gt;Hi all --&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I curently have one PA200 with all four eth ports taken (internal/trust network,&amp;nbsp;internet/untrust,&amp;nbsp;dmz,&amp;nbsp;voip vlan), as well as the mgmt port connected to the internal&amp;nbsp;network. &amp;nbsp;I'm looking to get a disaster recovery plan in place, but, as far as I understand (from about here to here |--| ), I would need one of the eth interfaces to connect to a second PA200 to utilize HA-Lite. &amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Since I can't spare a port, would another option be to: &amp;nbsp;get a second PA200, import the current running config on the production PA, then just put the spare PA in the closet; &amp;nbsp;then if the production PA ever dies, just replace it with the spare PA and *poof* no one sees a difference?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is that a sound plan? &amp;nbsp;I would think another benefit to this would be in case of a fire, etc, the spare PA could be stored in our other building.. but that could just be me trying to convince meself... &amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thoughts?&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;
&lt;P&gt;-- michael~&lt;/P&gt;</description>
      <pubDate>Wed, 20 Jan 2016 18:23:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa200-disaster-recovery-option/m-p/71279#M40741</guid>
      <dc:creator>thatguy</dc:creator>
      <dc:date>2016-01-20T18:23:04Z</dc:date>
    </item>
    <item>
      <title>Re: PA200 disaster recovery option...?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa200-disaster-recovery-option/m-p/71281#M40742</link>
      <description>&lt;P&gt;Do you have a requriement for physical port separation? &amp;nbsp;Can you collapse ports into sub-interfaces, or would that voilate some local policy/requirement you might have?&lt;/P&gt;</description>
      <pubDate>Wed, 20 Jan 2016 18:29:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa200-disaster-recovery-option/m-p/71281#M40742</guid>
      <dc:creator>Brandon_Wertz</dc:creator>
      <dc:date>2016-01-20T18:29:01Z</dc:date>
    </item>
    <item>
      <title>Re: PA200 disaster recovery option...?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa200-disaster-recovery-option/m-p/71282#M40743</link>
      <description>&lt;P&gt;You can bundle the interface if you can. Check the following document:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.paloaltonetworks.com/documentation/61/pan-os/newfeaturesguide/networking-features/lacp.html" target="_blank"&gt;https://www.paloaltonetworks.com/documentation/61/pan-os/newfeaturesguide/networking-features/lacp.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.paloaltonetworks.com/documentation/61/pan-os/pan-os/networking/lacp-settings.html" target="_blank"&gt;https://www.paloaltonetworks.com/documentation/61/pan-os/pan-os/networking/lacp-settings.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;To export and import the configuration refer to the following document:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Management-Articles/CLI-Commands-to-Export-Import-Configuration-and-Log-Files/ta-p/52661" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Management-Articles/CLI-Commands-to-Export-Import-Configuration-and-Log-Files/ta-p/52661&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope this helps!&lt;/P&gt;</description>
      <pubDate>Wed, 20 Jan 2016 18:42:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa200-disaster-recovery-option/m-p/71282#M40743</guid>
      <dc:creator>pankaku</dc:creator>
      <dc:date>2016-01-20T18:42:35Z</dc:date>
    </item>
    <item>
      <title>Re: PA200 disaster recovery option...?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa200-disaster-recovery-option/m-p/71283#M40744</link>
      <description>&lt;P&gt;check following for HA configuration:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Configuration-Articles/How-to-Configure-High-Availability-on-PAN-OS/ta-p/54086" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Configuration-Articles/How-to-Configure-High-Availability-on-PAN-OS/ta-p/54086&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Learning-Articles/What-is-HA-Lite-on-Palo-Alto-Networks-PA-200-and-VM-Series/ta-p/62553" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Learning-Articles/What-is-HA-Lite-on-Palo-Alto-Networks-PA-200-and-VM-Series/ta-p/62553&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 20 Jan 2016 18:44:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa200-disaster-recovery-option/m-p/71283#M40744</guid>
      <dc:creator>pankaku</dc:creator>
      <dc:date>2016-01-20T18:44:39Z</dc:date>
    </item>
    <item>
      <title>Re: PA200 disaster recovery option...?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa200-disaster-recovery-option/m-p/71284#M40745</link>
      <description>&lt;P&gt;I haven't palyed with subinterfaces before... &amp;nbsp;after a brief read, I'm guessing I could combine the trust (192.168.1.0/24) and the voip vlan (192.168.100.0/24) into the eth0 port, as long as the cxn from the switch is config'd as a trunk? &amp;nbsp;which would even save an additional switch port, yeah?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Sidenote: in case the boss &lt;EM&gt;does&lt;/EM&gt;&amp;nbsp;want the spare stored in another building, would the swap-out idea work as well? &amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Wed, 20 Jan 2016 18:47:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa200-disaster-recovery-option/m-p/71284#M40745</guid>
      <dc:creator>thatguy</dc:creator>
      <dc:date>2016-01-20T18:47:41Z</dc:date>
    </item>
    <item>
      <title>Re: PA200 disaster recovery option...?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa200-disaster-recovery-option/m-p/71285#M40746</link>
      <description>&lt;P&gt;I'm not certain of the phsyical limitation (if any) on the PA-200 with sub-interface limits, but technically you could collapse all interfaces into one interface with 4 sub-interfaces with that one interface on the network "trunked" with each VLAN allowed and use VLAN tagging in the PA-200 to separate out your traffic with each subinterface in it's own Zone as necessary.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The cold spare would work, but you'll have to deal with moving licenses (if using any). &amp;nbsp;You also run the risk of config deviation if you just image that box from a given point in time.&lt;/P&gt;</description>
      <pubDate>Wed, 20 Jan 2016 18:55:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa200-disaster-recovery-option/m-p/71285#M40746</guid>
      <dc:creator>Brandon_Wertz</dc:creator>
      <dc:date>2016-01-20T18:55:19Z</dc:date>
    </item>
    <item>
      <title>Re: PA200 disaster recovery option...?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa200-disaster-recovery-option/m-p/71286#M40747</link>
      <description>&lt;P&gt;Yes you will get extra port both idea will work. Make sure in second plan you should do cabling properly.&lt;/P&gt;</description>
      <pubDate>Wed, 20 Jan 2016 19:01:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa200-disaster-recovery-option/m-p/71286#M40747</guid>
      <dc:creator>pankaku</dc:creator>
      <dc:date>2016-01-20T19:01:42Z</dc:date>
    </item>
    <item>
      <title>Re: PA200 disaster recovery option...?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa200-disaster-recovery-option/m-p/71288#M40748</link>
      <description>&lt;P&gt;Thank you, both.. &amp;nbsp;I'll probably go with the cold-spare until I can figure out the sub-interface config. &amp;nbsp;These PA's are pretty neat! &amp;nbsp;Always learning... &amp;nbsp;&lt;span class="lia-unicode-emoji" title=":grinning_face_with_smiling_eyes:"&gt;😄&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 20 Jan 2016 20:08:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa200-disaster-recovery-option/m-p/71288#M40748</guid>
      <dc:creator>thatguy</dc:creator>
      <dc:date>2016-01-20T20:08:10Z</dc:date>
    </item>
  </channel>
</rss>

