<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic One template in Panorama for HA pair of firewalls in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/one-template-in-panorama-for-ha-pair-of-firewalls/m-p/167683#M53530</link>
    <description>&lt;P&gt;&lt;SPAN&gt;Transition/migrate HA pair to firewall&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I followed those instructions &lt;A href="https://www.paloaltonetworks.com/documentation/80/panorama/panorama_adminguide/manage-firewalls/migrate-a-firewall-to-panorama-management#_39720" target="_blank"&gt;https://www.paloaltonetworks.com/documentation/80/panorama/panorama_adminguide/manage-firewalls/migrate-a-firewall-to-panorama-management#_39720&lt;/A&gt;, steps from 1 to 7 and successfully migrated 3 HA pairs to Panorama management.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;After migration I've got in Panorama 3 device groups and 6 device templates. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;In this document &lt;A href="https://live.paloaltonetworks.com/t5/Management-Articles/Any-special-considerations-when-importing-HA-firewall/ta-p/114668" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Management-Articles/Any-special-considerations-when-importing-HA-firewall/ta-p/114668&lt;/A&gt; is written that each firewall has to use its own template (bellow special note). This limitation is annoying and can lead to mistakes. After checking template values I think there is no need for this limitation and I think I could put both firewalls into the same template because relevant values for HA aren't part of the template (e.g. High Availability - General - Preemptive - Device Priority).&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Is this correct, or has anyone experience with such deployment (two firewalls and one template) in the production (&lt;A href="https://live.paloaltonetworks.com/t5/Management-Articles/How-to-add-a-locally-managed-firewall-to-panorama-management/tac-p/165380#M" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Management-Articles/How-to-add-a-locally-managed-firewall-to-panorama-management/tac-p/165380#M&lt;/A&gt;)?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Regards Milan&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 21 Jul 2017 13:24:47 GMT</pubDate>
    <dc:creator>Milan_Lesnik</dc:creator>
    <dc:date>2017-07-21T13:24:47Z</dc:date>
    <item>
      <title>One template in Panorama for HA pair of firewalls</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/one-template-in-panorama-for-ha-pair-of-firewalls/m-p/167683#M53530</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Transition/migrate HA pair to firewall&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I followed those instructions &lt;A href="https://www.paloaltonetworks.com/documentation/80/panorama/panorama_adminguide/manage-firewalls/migrate-a-firewall-to-panorama-management#_39720" target="_blank"&gt;https://www.paloaltonetworks.com/documentation/80/panorama/panorama_adminguide/manage-firewalls/migrate-a-firewall-to-panorama-management#_39720&lt;/A&gt;, steps from 1 to 7 and successfully migrated 3 HA pairs to Panorama management.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;After migration I've got in Panorama 3 device groups and 6 device templates. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;In this document &lt;A href="https://live.paloaltonetworks.com/t5/Management-Articles/Any-special-considerations-when-importing-HA-firewall/ta-p/114668" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Management-Articles/Any-special-considerations-when-importing-HA-firewall/ta-p/114668&lt;/A&gt; is written that each firewall has to use its own template (bellow special note). This limitation is annoying and can lead to mistakes. After checking template values I think there is no need for this limitation and I think I could put both firewalls into the same template because relevant values for HA aren't part of the template (e.g. High Availability - General - Preemptive - Device Priority).&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Is this correct, or has anyone experience with such deployment (two firewalls and one template) in the production (&lt;A href="https://live.paloaltonetworks.com/t5/Management-Articles/How-to-add-a-locally-managed-firewall-to-panorama-management/tac-p/165380#M" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Management-Articles/How-to-add-a-locally-managed-firewall-to-panorama-management/tac-p/165380#M&lt;/A&gt;)?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Regards Milan&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Jul 2017 13:24:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/one-template-in-panorama-for-ha-pair-of-firewalls/m-p/167683#M53530</guid>
      <dc:creator>Milan_Lesnik</dc:creator>
      <dc:date>2017-07-21T13:24:47Z</dc:date>
    </item>
    <item>
      <title>Re: One template in Panorama for HA pair of firewalls</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/one-template-in-panorama-for-ha-pair-of-firewalls/m-p/167707#M53533</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/37841"&gt;@Milan_Lesnik&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We already have a lot of such deployments. The dedicated template is only in the migration. After that you're free to change everything you want. You only need dedicated templates when you use them for settings which aren't the same on both firewalls.&lt;/P&gt;&lt;P&gt;In your case it is no problem to use one template for both clustermembers. In my case we use template stacks which contain multiple templates (global settings template, clustersettings template and devicespecific templates for each firewall with settings like mgmt ip, hostname ...)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Just keep in mind that you need to delete the devicespecific values from the import templates and the you could apply this one template to both firewalls of your HA pair.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope this helps.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Remo&lt;/P&gt;</description>
      <pubDate>Fri, 21 Jul 2017 15:04:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/one-template-in-panorama-for-ha-pair-of-firewalls/m-p/167707#M53533</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2017-07-21T15:04:32Z</dc:date>
    </item>
    <item>
      <title>Re: One template in Panorama for HA pair of firewalls</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/one-template-in-panorama-for-ha-pair-of-firewalls/m-p/167826#M53567</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It helps, thank you for the answer.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;During migration dedicated template, after migration one template for both firewalls.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards Milan&lt;/P&gt;</description>
      <pubDate>Sat, 22 Jul 2017 19:32:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/one-template-in-panorama-for-ha-pair-of-firewalls/m-p/167826#M53567</guid>
      <dc:creator>Milan_Lesnik</dc:creator>
      <dc:date>2017-07-22T19:32:39Z</dc:date>
    </item>
  </channel>
</rss>

