<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Moving from a single PA500 to HA pair of PA820 in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/moving-from-a-single-pa500-to-ha-pair-of-pa820/m-p/158839#M52008</link>
    <description>&lt;P&gt;For IP addresses configured on interfaces, you shouldn't need to clear arp due to the firewall performaing gratuitous arp after an HA event.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Gratuitous arp is not done for NAT addresses so you might need to clear on external routers if you are doing NAT.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 01 Jun 2017 05:01:52 GMT</pubDate>
    <dc:creator>rmfalconer</dc:creator>
    <dc:date>2017-06-01T05:01:52Z</dc:date>
    <item>
      <title>Moving from a single PA500 to HA pair of PA820</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/moving-from-a-single-pa500-to-ha-pair-of-pa820/m-p/158808#M52001</link>
      <description>&lt;P&gt;As the subject states we are single PA500 shop now moving to Dual PA820 in HA.&lt;/P&gt;&lt;P&gt;What can I expect when moving to this type of setup coming from a single FW setup.&lt;/P&gt;&lt;P&gt;Is there anything I need to look out for any "Gotchas"? So far I know I am using 5 copper ports on the PA500 and the PA820 only has 4 so I know I will need a module. &amp;nbsp;Can anyone think of anything else I may encounter, anything related to Policies, Objects, VPN config anything that you guys can think of.&lt;/P&gt;</description>
      <pubDate>Wed, 31 May 2017 20:30:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/moving-from-a-single-pa500-to-ha-pair-of-pa820/m-p/158808#M52001</guid>
      <dc:creator>CTaveras</dc:creator>
      <dc:date>2017-05-31T20:30:40Z</dc:date>
    </item>
    <item>
      <title>Re: Moving from a single PA500 to HA pair of PA820</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/moving-from-a-single-pa500-to-ha-pair-of-pa820/m-p/158812#M52004</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/64809"&gt;@CTaveras&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;I assume that you are going to run in an Active/Passive setup. Not much really changes and there are not really any additional steps that you have to do to keep things working correctly. As far as VPN goes GP clients usually transfer over during a failover even fine, where IPSec site-to-site tunnels that I have generally need a few minutes to re-key with the other unit to start passing traffic again.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 31 May 2017 20:49:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/moving-from-a-single-pa500-to-ha-pair-of-pa820/m-p/158812#M52004</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2017-05-31T20:49:40Z</dc:date>
    </item>
    <item>
      <title>Re: Moving from a single PA500 to HA pair of PA820</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/moving-from-a-single-pa500-to-ha-pair-of-pa820/m-p/158814#M52005</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;Thank you very much for the response, how does HA handle user traffic passing out if one of the firewalls dies,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;Do I need to flush arp anywhere or do they keep session tables to some degree?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 31 May 2017 21:14:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/moving-from-a-single-pa500-to-ha-pair-of-pa820/m-p/158814#M52005</guid>
      <dc:creator>CTaveras</dc:creator>
      <dc:date>2017-05-31T21:14:39Z</dc:date>
    </item>
    <item>
      <title>Re: Moving from a single PA500 to HA pair of PA820</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/moving-from-a-single-pa500-to-ha-pair-of-pa820/m-p/158839#M52008</link>
      <description>&lt;P&gt;For IP addresses configured on interfaces, you shouldn't need to clear arp due to the firewall performaing gratuitous arp after an HA event.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Gratuitous arp is not done for NAT addresses so you might need to clear on external routers if you are doing NAT.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 01 Jun 2017 05:01:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/moving-from-a-single-pa500-to-ha-pair-of-pa820/m-p/158839#M52008</guid>
      <dc:creator>rmfalconer</dc:creator>
      <dc:date>2017-06-01T05:01:52Z</dc:date>
    </item>
    <item>
      <title>Re: Moving from a single PA500 to HA pair of PA820</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/moving-from-a-single-pa500-to-ha-pair-of-pa820/m-p/158853#M52013</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/55733"&gt;@rmfalconer&lt;/a&gt;&amp;nbsp;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If the Palo has DNAT configured on the&amp;nbsp;external interface for let's say an external range of IPs, it will not send a GARP after failover?&lt;/P&gt;</description>
      <pubDate>Thu, 01 Jun 2017 06:49:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/moving-from-a-single-pa500-to-ha-pair-of-pa820/m-p/158853#M52013</guid>
      <dc:creator>TranceforLife</dc:creator>
      <dc:date>2017-06-01T06:49:52Z</dc:date>
    </item>
    <item>
      <title>Re: Moving from a single PA500 to HA pair of PA820</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/moving-from-a-single-pa500-to-ha-pair-of-pa820/m-p/158857#M52016</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/55733"&gt;@rmfalconer&lt;/a&gt;: the PA does proxy arp for IP addresses used in NAT policies&lt;/P&gt;
&lt;P&gt;The HA cluster uses a virtual MAC address which is moved over to the active member if there is a failover event, so the GARP will trigger any switches to learn where the MAC is located and any upstream devices will already have a mapping for the NAT addresses to the virtual MAC. if an IP is not known yet, the active member (wether primary or secondary) will simply proxy arp for the IP using the virtual cluster MAC&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/64809"&gt;@CTaveras&lt;/a&gt;: the HA cluster (via the HA2 interface) shares all information regarding active sessions (tcp sequence, NAT, QoS, content scanning status,...) , so if there is a failover event all sessions are immediately 'active' on the secondary firewall and can continue as if nothing happened&lt;/P&gt;</description>
      <pubDate>Thu, 01 Jun 2017 07:28:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/moving-from-a-single-pa500-to-ha-pair-of-pa820/m-p/158857#M52016</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2017-06-01T07:28:41Z</dc:date>
    </item>
    <item>
      <title>Re: Moving from a single PA500 to HA pair of PA820</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/moving-from-a-single-pa500-to-ha-pair-of-pa820/m-p/158858#M52017</link>
      <description>&lt;P&gt;Ok so floating MAC address shared between the&amp;nbsp;HA members. All ARP requests for any DNAT IP address that Palo&amp;nbsp;owns will be replied by an active member with its floating MAC address?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 01 Jun 2017 09:42:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/moving-from-a-single-pa500-to-ha-pair-of-pa820/m-p/158858#M52017</guid>
      <dc:creator>TranceforLife</dc:creator>
      <dc:date>2017-06-01T09:42:09Z</dc:date>
    </item>
    <item>
      <title>Re: Moving from a single PA500 to HA pair of PA820</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/moving-from-a-single-pa500-to-ha-pair-of-pa820/m-p/158861#M52020</link>
      <description>&lt;P&gt;correct&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;- a HA cluster switches to a floating MAC on all interfaces (based on the cluster ID)&lt;/P&gt;
&lt;P&gt;- upon HA failover GARP is sent out for all interfaces&lt;/P&gt;
&lt;P&gt;- PA performs proxy ARP for any IP used in NAT policies (in case of HA, the floating MAC is shared)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;so normally all connected devices will automatically switch everything over to the active HA peer&lt;/P&gt;</description>
      <pubDate>Thu, 01 Jun 2017 08:42:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/moving-from-a-single-pa500-to-ha-pair-of-pa820/m-p/158861#M52020</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2017-06-01T08:42:00Z</dc:date>
    </item>
    <item>
      <title>Re: Moving from a single PA500 to HA pair of PA820</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/moving-from-a-single-pa500-to-ha-pair-of-pa820/m-p/158862#M52021</link>
      <description>&lt;P&gt;Such a clear answer! Thanks as always&lt;/P&gt;</description>
      <pubDate>Thu, 01 Jun 2017 08:46:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/moving-from-a-single-pa500-to-ha-pair-of-pa820/m-p/158862#M52021</guid>
      <dc:creator>TranceforLife</dc:creator>
      <dc:date>2017-06-01T08:46:00Z</dc:date>
    </item>
    <item>
      <title>Re: Moving from a single PA500 to HA pair of PA820</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/moving-from-a-single-pa500-to-ha-pair-of-pa820/m-p/159155#M52066</link>
      <description>&lt;P&gt;First thank you all for the info/Insight great info!!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;A few more quetions&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1. &amp;nbsp;Any benefit going Active/Active over Active Passive, Pros and cons?&lt;/P&gt;&lt;P&gt;2. &amp;nbsp;We have the public and private keys of a trusted Certificate Authority imported into the firewall such that the firewall can issue certificates as that CA. &amp;nbsp;I’m assuming exporting and importing the config won’t also migrate over certificate information such that we would have redo those configurations on the new firewall.&lt;/P&gt;</description>
      <pubDate>Fri, 02 Jun 2017 12:51:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/moving-from-a-single-pa500-to-ha-pair-of-pa820/m-p/159155#M52066</guid>
      <dc:creator>CTaveras</dc:creator>
      <dc:date>2017-06-02T12:51:24Z</dc:date>
    </item>
    <item>
      <title>Re: Moving from a single PA500 to HA pair of PA820</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/moving-from-a-single-pa500-to-ha-pair-of-pa820/m-p/159164#M52067</link>
      <description>&lt;P&gt;1) No benefits, l know it adds only complexity&amp;nbsp;through l never done it before. Only useful&amp;nbsp;as a temp fix while you dealing with the asymmetric routing&amp;nbsp;on the network.&lt;/P&gt;&lt;P&gt;2) Keys and certs will be migrated (keys are encrypted&amp;nbsp;with the master key on palo)&lt;/P&gt;</description>
      <pubDate>Sat, 03 Jun 2017 10:15:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/moving-from-a-single-pa500-to-ha-pair-of-pa820/m-p/159164#M52067</guid>
      <dc:creator>TranceforLife</dc:creator>
      <dc:date>2017-06-03T10:15:43Z</dc:date>
    </item>
    <item>
      <title>Re: Moving from a single PA500 to HA pair of PA820</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/moving-from-a-single-pa500-to-ha-pair-of-pa820/m-p/159223#M52071</link>
      <description>&lt;P&gt;&lt;SPAN class=""&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/64809"&gt;@CTaveras&lt;/a&gt;&amp;nbsp;&lt;/SPAN&gt;Just be aware that PAN-OS 8.0.x is the minimum OS version for the&amp;nbsp;new platforms 220, 800 series and 5200 series.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Other than that, I agree with some of the other comments such as:&lt;/P&gt;&lt;P&gt;1. Be aware of potential proxy arp configuration on upstream routers. it may break the NAT functionality. If you have static or proxy arp on upstream routers make sure to remove it before starting to test especially the NAT rules.&lt;/P&gt;&lt;P&gt;2. Make sure to configure the Active/Passive Settings as Auto instead of Shutdown. The reason for that is because in the shutdown state, upstream and downstream devices connected to the passive device will not see a valid path until the passive firewall becomes active. That may be a little frustrating because the failover may be delayed a few seconds longer, which may be unnaceptable for some businesses.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="Screen Shot 2017-06-02 at 9.17.21 AM.png" style="width: 500px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/9511iF9FB292BBCBB6AB7/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Screen Shot 2017-06-02 at 9.17.21 AM.png" alt="Screen Shot 2017-06-02 at 9.17.21 AM.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;3. Also be aware of the preemption feature. If your firewalls are connected to two different ISPs and both have different bandwidths, typically you want the firewall connected to the higher bandwidth to always be the Active firewall in the HA pair. In this case you may want to enable the preemtion feature and configure a timer on it.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For more advises on HA optimization and configuration please refer to the following document:&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/twzvq79624/attachments/twzvq79624/documentation_tkb/543/2/HA_Failover_Optimization-RevC.pdf" target="_blank"&gt;https://live.paloaltonetworks.com/twzvq79624/attachments/twzvq79624/documentation_tkb/543/2/HA_Failover_Optimization-RevC.pdf&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I hope this helps.&lt;/P&gt;</description>
      <pubDate>Fri, 02 Jun 2017 16:25:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/moving-from-a-single-pa500-to-ha-pair-of-pa820/m-p/159223#M52071</guid>
      <dc:creator>acc6d0b3610eec313831f7900fdbd235</dc:creator>
      <dc:date>2017-06-02T16:25:20Z</dc:date>
    </item>
    <item>
      <title>Re: Moving from a single PA500 to HA pair of PA820</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/moving-from-a-single-pa500-to-ha-pair-of-pa820/m-p/160054#M52204</link>
      <description>&lt;P&gt;We will def have 2 ISP but using both simultaniously.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Some one mentioned something about Virtual MAC when in HA...I assume that was for the External interface?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What about the Trusted port does that also get a Virtual MAC?&lt;/P&gt;</description>
      <pubDate>Wed, 07 Jun 2017 20:04:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/moving-from-a-single-pa500-to-ha-pair-of-pa820/m-p/160054#M52204</guid>
      <dc:creator>CTaveras</dc:creator>
      <dc:date>2017-06-07T20:04:28Z</dc:date>
    </item>
    <item>
      <title>Re: Moving from a single PA500 to HA pair of PA820</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/moving-from-a-single-pa500-to-ha-pair-of-pa820/m-p/160142#M52223</link>
      <description>&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/64809"&gt;@CTaveras&lt;/a&gt; If you want to utilize both links simultaneously one of the options you have available is to enable the ECMP feature. &lt;A href="https://live.paloaltonetworks.com/t5/Configuration-Articles/How-to-Implement-ECMP-Load-Balancing-on-the-Firewall/ta-p/110339" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Configuration-Articles/How-to-Implement-ECMP-Load-Balancing-on-the-Firewall/ta-p/110339&lt;/A&gt; The ECMP allows you to specify up to 4 route paths with the same cost (metric) while applying Load Balance algorithms such as Round Robin for load distribution.</description>
      <pubDate>Thu, 08 Jun 2017 06:07:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/moving-from-a-single-pa500-to-ha-pair-of-pa820/m-p/160142#M52223</guid>
      <dc:creator>acc6d0b3610eec313831f7900fdbd235</dc:creator>
      <dc:date>2017-06-08T06:07:18Z</dc:date>
    </item>
    <item>
      <title>Re: Moving from a single PA500 to HA pair of PA820</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/moving-from-a-single-pa500-to-ha-pair-of-pa820/m-p/160211#M52245</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/36590"&gt;@acc6d0b3610eec313831f7900fdbd235&lt;/a&gt;&amp;nbsp;I notice that although I set the Passive link state on the Active FW to Auto, the Passive has not sync'd this change.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is this expected behavior or does the passive device also need this setting? &amp;nbsp;I read the Doc you linked and it doesnt mention anything about the passive device.&lt;/P&gt;</description>
      <pubDate>Thu, 08 Jun 2017 13:23:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/moving-from-a-single-pa500-to-ha-pair-of-pa820/m-p/160211#M52245</guid>
      <dc:creator>CTaveras</dc:creator>
      <dc:date>2017-06-08T13:23:22Z</dc:date>
    </item>
    <item>
      <title>Re: Moving from a single PA500 to HA pair of PA820</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/moving-from-a-single-pa500-to-ha-pair-of-pa820/m-p/160214#M52247</link>
      <description>&lt;P&gt;Yes expected. These settings are local:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ha.PNG" style="width: 746px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/9595iB7A318FA0AFF8276/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="ha.PNG" alt="ha.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/twzvq79624/attachments/twzvq79624/documentation_tkb/568/1/HA_Synchronization_RevD.pdf" target="_blank"&gt;https://live.paloaltonetworks.com/twzvq79624/attachments/twzvq79624/documentation_tkb/568/1/HA_Synchronization_RevD.pdf&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 08 Jun 2017 13:30:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/moving-from-a-single-pa500-to-ha-pair-of-pa820/m-p/160214#M52247</guid>
      <dc:creator>TranceforLife</dc:creator>
      <dc:date>2017-06-08T13:30:16Z</dc:date>
    </item>
  </channel>
</rss>

