<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: active/passive HA setup with existing production firewall in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/active-passive-ha-setup-with-existing-production-firewall/m-p/125565#M46438</link>
    <description>&lt;P&gt;Thanks for the Info. This helped.&lt;/P&gt;</description>
    <pubDate>Thu, 10 Nov 2016 13:12:41 GMT</pubDate>
    <dc:creator>Bvance</dc:creator>
    <dc:date>2016-11-10T13:12:41Z</dc:date>
    <item>
      <title>active/passive HA setup with existing production firewall</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/active-passive-ha-setup-with-existing-production-firewall/m-p/123351#M46220</link>
      <description>&lt;P&gt;I have a second PA-500 I need to add to an existing production PA-500 for active/passive HA. I have read the admin guide for HA setup, but it appears to be for two pre-production&amp;nbsp;firewalls. Are there any special precautions I need to take into account so that the post production firewall syncs it's config to the new firewall? The admin guide dosen't seem to say.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;</description>
      <pubDate>Wed, 02 Nov 2016 18:33:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/active-passive-ha-setup-with-existing-production-firewall/m-p/123351#M46220</guid>
      <dc:creator>Bvance</dc:creator>
      <dc:date>2016-11-02T18:33:55Z</dc:date>
    </item>
    <item>
      <title>Re: active/passive HA setup with existing production firewall</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/active-passive-ha-setup-with-existing-production-firewall/m-p/123381#M46222</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;l haven't&amp;nbsp;done much of HA set-ups but make sure you do have a local backup copy of your configuration (somewhere&amp;nbsp;on your MGMT station).&lt;/P&gt;&lt;P&gt;Then just follow the&amp;nbsp;guide, make a priority to be higher (lower number)&amp;nbsp;on the current running box with preemption&amp;nbsp;is enabled. Can also disable config sync while doing configuration, after all tested enable it back.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;Myky&lt;/P&gt;</description>
      <pubDate>Wed, 02 Nov 2016 19:02:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/active-passive-ha-setup-with-existing-production-firewall/m-p/123381#M46222</guid>
      <dc:creator>TranceforLife</dc:creator>
      <dc:date>2016-11-02T19:02:16Z</dc:date>
    </item>
    <item>
      <title>Re: active/passive HA setup with existing production firewall</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/active-passive-ha-setup-with-existing-production-firewall/m-p/124589#M46332</link>
      <description>&lt;P&gt;i'd first enable HA on the production firewall without connecting the new one just yet&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;once the config is committed it will show as an active member and the cluster is broken (because the secondary member is 'down')&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;next, configure the second member's basics: HA config, management config (leave everything else default) and make sure it's device priority in HA is &lt;STRONG&gt;higher&lt;/STRONG&gt; than the active member (higher number = lower priority) and cluster ID is identical&lt;/P&gt;
&lt;P&gt;once that configuration is committed, suspend the secondary's HA functionality&lt;/P&gt;
&lt;PRE&gt;&amp;gt; request high-availability state suspend &lt;/PRE&gt;
&lt;P&gt;next, hook up the HA cables and wait until member 1 reports the cluster is connected&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;once HA is up (there will be error messages as the config is out of sync) perform a sync-to-peer on the primary unit:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;PRE&gt; &amp;gt; request high-availability sync-to-remote running-config&lt;/PRE&gt;
&lt;P&gt;this will send the active configuration to the new device and commit it&lt;/P&gt;</description>
      <pubDate>Mon, 07 Nov 2016 11:09:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/active-passive-ha-setup-with-existing-production-firewall/m-p/124589#M46332</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2016-11-07T11:09:47Z</dc:date>
    </item>
    <item>
      <title>Re: active/passive HA setup with existing production firewall</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/active-passive-ha-setup-with-existing-production-firewall/m-p/125565#M46438</link>
      <description>&lt;P&gt;Thanks for the Info. This helped.&lt;/P&gt;</description>
      <pubDate>Thu, 10 Nov 2016 13:12:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/active-passive-ha-setup-with-existing-production-firewall/m-p/125565#M46438</guid>
      <dc:creator>Bvance</dc:creator>
      <dc:date>2016-11-10T13:12:41Z</dc:date>
    </item>
  </channel>
</rss>

