<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: forming firewall HA in a panorama managed environment in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/forming-firewall-ha-in-a-panorama-managed-environment/m-p/77960#M42769</link>
    <description>&lt;P&gt;With multi VSYS running, each VSYS is considered to be a firewall by Panorama. &amp;nbsp;For example, we have 5 VSYS'es defined and Panorama will detect 5 firewall instances (10 firewall instances in the case of HA). &amp;nbsp;Typically, we will define 5 device groups, 1 group for each VSYS with a pair of A/P firewalls in each group.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You will need to to commit to the passive to push the objects from Panorama. &amp;nbsp;Panorama commits are not sync to give us the flexibility to commit to 1 PA or to both. &amp;nbsp;Also, there is no VSYS sync but rather the sync is done with HA process.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 11 May 2016 17:04:22 GMT</pubDate>
    <dc:creator>rmonvon</dc:creator>
    <dc:date>2016-05-11T17:04:22Z</dc:date>
    <item>
      <title>forming firewall HA in a panorama managed environment</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/forming-firewall-ha-in-a-panorama-managed-environment/m-p/77885#M42739</link>
      <description>&lt;P&gt;we have a panorama managed firewall and we push objects from panorama to it . we are considering to make a HA firewall setup . as per articles from PaloAlto , Panorama objects are not being synchronized.&lt;BR /&gt;&lt;BR /&gt;Question 1 : Should we add secondary firewall to Panorama prior to forming HA cluster and ensure it's completely synced up ? &lt;BR /&gt;&lt;BR /&gt;Question 2 : Is there any other concerns that we need to be aware for this scenario ( forming firewall HA with a panorama managed device )&lt;/P&gt;</description>
      <pubDate>Wed, 11 May 2016 01:43:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/forming-firewall-ha-in-a-panorama-managed-environment/m-p/77885#M42739</guid>
      <dc:creator>akhalighi</dc:creator>
      <dc:date>2016-05-11T01:43:59Z</dc:date>
    </item>
    <item>
      <title>Re: forming firewall HA in a panorama managed environment</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/forming-firewall-ha-in-a-panorama-managed-environment/m-p/77940#M42756</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/39064"&gt;@akhalighi&lt;/a&gt; wrote:&lt;BR /&gt;
&lt;P&gt;we have a panorama managed firewall and we push objects from panorama to it . we are considering to make a HA firewall setup . as per articles from PaloAlto , Panorama objects are not being synchronized.&lt;BR /&gt;&lt;BR /&gt;Question 1 : Should we add secondary firewall to Panorama prior to forming HA cluster and ensure it's completely synced up ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you plan to configure the HA settings from Panorama &amp;amp; push to the 2nd firewall, then you should add the 2nd PA to Panorama 1st and define a template for the 2nd PA. &amp;nbsp; If you plan to keep the HA setting local to the PA, then you can do it either way.&lt;BR /&gt;&lt;BR /&gt;Question 2 : Is there any other concerns that we need to be aware for this scenario ( forming firewall HA with a panorama managed device )&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You need to put both PAs into the same device group so they can have the same shared policies. &amp;nbsp;You can commit to each PA one at a time or select both when committing from Panorama. &amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If the PAs are in A/P HA and their network settings are the same, you may want to put both in the same template assuming the mgmt &amp;amp; HA settings are set locally at the PA. &amp;nbsp;Or you can put each PA in its own template and assign every settings within the template.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 11 May 2016 14:30:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/forming-firewall-ha-in-a-panorama-managed-environment/m-p/77940#M42756</guid>
      <dc:creator>rmonvon</dc:creator>
      <dc:date>2016-05-11T14:30:29Z</dc:date>
    </item>
    <item>
      <title>Re: forming firewall HA in a panorama managed environment</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/forming-firewall-ha-in-a-panorama-managed-environment/m-p/77946#M42762</link>
      <description>&lt;P&gt;Thanks&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This is going to be an Active-Passivesetup with Active running some VSYSs. &lt;/P&gt;
&lt;P&gt;in our scenario panorama pushes objects to VSYSs on Active firewall . do we still need to add all VSYSs on passive PA to receive objects from Panorama ? Or objects will be replicated as part of VSYS syncronization ?&lt;/P&gt;</description>
      <pubDate>Wed, 11 May 2016 14:56:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/forming-firewall-ha-in-a-panorama-managed-environment/m-p/77946#M42762</guid>
      <dc:creator>akhalighi</dc:creator>
      <dc:date>2016-05-11T14:56:51Z</dc:date>
    </item>
    <item>
      <title>Re: forming firewall HA in a panorama managed environment</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/forming-firewall-ha-in-a-panorama-managed-environment/m-p/77960#M42769</link>
      <description>&lt;P&gt;With multi VSYS running, each VSYS is considered to be a firewall by Panorama. &amp;nbsp;For example, we have 5 VSYS'es defined and Panorama will detect 5 firewall instances (10 firewall instances in the case of HA). &amp;nbsp;Typically, we will define 5 device groups, 1 group for each VSYS with a pair of A/P firewalls in each group.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You will need to to commit to the passive to push the objects from Panorama. &amp;nbsp;Panorama commits are not sync to give us the flexibility to commit to 1 PA or to both. &amp;nbsp;Also, there is no VSYS sync but rather the sync is done with HA process.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 11 May 2016 17:04:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/forming-firewall-ha-in-a-panorama-managed-environment/m-p/77960#M42769</guid>
      <dc:creator>rmonvon</dc:creator>
      <dc:date>2016-05-11T17:04:22Z</dc:date>
    </item>
    <item>
      <title>Re: forming firewall HA in a panorama managed environment</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/forming-firewall-ha-in-a-panorama-managed-environment/m-p/77968#M42770</link>
      <description>&lt;P&gt;Thanks . so to be clear , If I have two VSYSs ( VSYS1 and VSYS2) on Active PA and I form a HA cluster ; these two VSYSs will be craeted on passive node durinf first configuration Sync&amp;nbsp; but I have to add them to Panorama to receive the objects . Is that right ?&lt;/P&gt;</description>
      <pubDate>Wed, 11 May 2016 19:44:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/forming-firewall-ha-in-a-panorama-managed-environment/m-p/77968#M42770</guid>
      <dc:creator>akhalighi</dc:creator>
      <dc:date>2016-05-11T19:44:10Z</dc:date>
    </item>
    <item>
      <title>Re: forming firewall HA in a panorama managed environment</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/forming-firewall-ha-in-a-panorama-managed-environment/m-p/77972#M42772</link>
      <description>&lt;P&gt;1st you will need to manually enable Multi-VSYS on the passive. &amp;nbsp;Then if the VSYS'es are defined locally on active PA, you can perform an HA sync and the configuration of the VSYS will sync to the passive. &amp;nbsp;If you are using template in Panorama to define the VSYS'es, then you need to perform a template commit to push the VSYS config to the passive.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope that helps.&lt;/P&gt;</description>
      <pubDate>Wed, 11 May 2016 22:43:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/forming-firewall-ha-in-a-panorama-managed-environment/m-p/77972#M42772</guid>
      <dc:creator>rmonvon</dc:creator>
      <dc:date>2016-05-11T22:43:43Z</dc:date>
    </item>
    <item>
      <title>Re: forming firewall HA in a panorama managed environment</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/forming-firewall-ha-in-a-panorama-managed-environment/m-p/77987#M42778</link>
      <description>&lt;P&gt;Thanks . VSYSs are defined locally but they receive objects ( address objects and service objects ) from Panorama . so I guess after HA Sync , we need to add VSYSs on Passive PA to Panaroma and push Panorama objects to them ?&lt;/P&gt;</description>
      <pubDate>Thu, 12 May 2016 12:53:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/forming-firewall-ha-in-a-panorama-managed-environment/m-p/77987#M42778</guid>
      <dc:creator>akhalighi</dc:creator>
      <dc:date>2016-05-12T12:53:50Z</dc:date>
    </item>
    <item>
      <title>Re: forming firewall HA in a panorama managed environment</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/forming-firewall-ha-in-a-panorama-managed-environment/m-p/77999#M42785</link>
      <description>&lt;P&gt;The HA sync should add the VSYS'es onto the passive PA, and Panorama will see the new VSYS'es of the passive PA. &amp;nbsp;You then need to add these VSYS'es of the passive to the device group(s) within Panorama. &amp;nbsp;Once the VSYS'es are in device group(s), you can push Panorama objects &amp;amp; policies to the passive.&lt;/P&gt;</description>
      <pubDate>Thu, 12 May 2016 13:57:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/forming-firewall-ha-in-a-panorama-managed-environment/m-p/77999#M42785</guid>
      <dc:creator>rmonvon</dc:creator>
      <dc:date>2016-05-12T13:57:43Z</dc:date>
    </item>
  </channel>
</rss>

