<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Migrating from sub-interface to L3 interface in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/migrating-from-sub-interface-to-l3-interface/m-p/213849#M62173</link>
    <description>&lt;P&gt;Thanks a lot for the inputs. Their requirement is that they don't want any interuption during this migration because they have a monitoring system on this sub-interface, and any traffic interruption will create a noise/alarm.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I agree with &lt;A href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/83021" target="_blank"&gt;@JoeAndreini&lt;/A&gt;, this migration should be simple. I&amp;nbsp;will try to push with this method with them on a maintenance window.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Again, thanks a lot for the input.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 10 May 2018 00:34:06 GMT</pubDate>
    <dc:creator>filterfilter</dc:creator>
    <dc:date>2018-05-10T00:34:06Z</dc:date>
    <item>
      <title>Migrating from sub-interface to L3 interface</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/migrating-from-sub-interface-to-l3-interface/m-p/213502#M62104</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have pair of PA in HA mode, we are going to move one of the sub-interface to a L3 interface. is it possible to do this without any downtime? I am considering below steps&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;take out sub-interface from monitored interface (to prevent failover)&lt;/LI&gt;&lt;LI&gt;configured L3 interface on standby firewall (is this possible to have a different config between active/passive firewall?)&lt;/LI&gt;&lt;LI&gt;failover to standby firewall (not sure if session table will be sync correctly since now it is configured on an l3 interface instead on sub-interface)&lt;/LI&gt;&lt;LI&gt;sync configuration from now active firewall ( previously standby) to passive firewall.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;any suggestion or thoughts?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Tue, 08 May 2018 04:10:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/migrating-from-sub-interface-to-l3-interface/m-p/213502#M62104</guid>
      <dc:creator>filterfilter</dc:creator>
      <dc:date>2018-05-08T04:10:30Z</dc:date>
    </item>
    <item>
      <title>Re: Migrating from sub-interface to L3 interface</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/migrating-from-sub-interface-to-l3-interface/m-p/213610#M62123</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I would say do this in a maintenance window where you can have down time and this could cause issues especially if something is missed in the config. I would not recomnmend having a different config for active/passive units.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Just my thoughts.&lt;/P&gt;</description>
      <pubDate>Tue, 08 May 2018 17:19:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/migrating-from-sub-interface-to-l3-interface/m-p/213610#M62123</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2018-05-08T17:19:15Z</dc:date>
    </item>
    <item>
      <title>Re: Migrating from sub-interface to L3 interface</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/migrating-from-sub-interface-to-l3-interface/m-p/213629#M62128</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/89136"&gt;@filterfilter&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;You could do it the way you describe perfectly fine baring that you toggle a few settings on the firewalls to temporarily break configuration sync. Although as&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/27580"&gt;@OtakarKlier&lt;/a&gt;&amp;nbsp;has already mentioned there are certain risks that go along with this that really&amp;nbsp;best to being done in a maintenance window. You aren't going to know for 100% if you have the configuration done properly until you actually failover traffic, and if it's not dialed in properly you could cause a momentary outage as you move things back to the other HA member.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 08 May 2018 19:38:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/migrating-from-sub-interface-to-l3-interface/m-p/213629#M62128</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2018-05-08T19:38:20Z</dc:date>
    </item>
    <item>
      <title>Re: Migrating from sub-interface to L3 interface</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/migrating-from-sub-interface-to-l3-interface/m-p/213725#M62142</link>
      <description>&lt;P&gt;I think you are making this harder than it needs to be...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I would do the following:&lt;/P&gt;&lt;P&gt;1) configure the new ports on the switch in your VLAN and wire it to the new ports on the firewalls&lt;/P&gt;&lt;P&gt;2) just before your maintenance window, configure the new firewall ports and remove the subinterfaces&lt;/P&gt;&lt;P&gt;3) when the maintenance window begins, apply this candidate configuration&lt;/P&gt;&lt;P&gt;4) once you verify everything is functioning, remove the VLAN from the trunk ports on the switch&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 09 May 2018 11:15:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/migrating-from-sub-interface-to-l3-interface/m-p/213725#M62142</guid>
      <dc:creator>JoeAndreini</dc:creator>
      <dc:date>2018-05-09T11:15:02Z</dc:date>
    </item>
    <item>
      <title>Re: Migrating from sub-interface to L3 interface</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/migrating-from-sub-interface-to-l3-interface/m-p/213752#M62152</link>
      <description>&lt;P&gt;I like the way you are approaching this option, but I would change the methodology slightly:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1) configure the new ports on the switch in your VLAN and wire it to the new ports on the firewalls (with the switchports SHUT)&lt;/P&gt;&lt;P&gt;2) setup the new FW ports as just standard members of the VLAN (untagged or access-port depending on your terminology) and push policy&lt;/P&gt;&lt;P&gt;3) when the maintenance window begins,&amp;nbsp;SHUT the VLAN Trunk Interface on the switch,&amp;nbsp; NO SHUT the standard access ports&lt;/P&gt;&lt;P&gt;4) once you verify everything is functioning, remove the VLAN from the trunk ports on the switch&lt;/P&gt;&lt;P&gt;5) &lt;SPAN&gt;once you verify everything is functioning,&amp;nbsp;&lt;/SPAN&gt;remove the VLAN tagging from the FW ports and push policy&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The roll back is a quick - SHUT of the new ports and NO SHUT of the old ports.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Very similar process to Joe, but slightly different focus.&lt;/P&gt;</description>
      <pubDate>Wed, 09 May 2018 15:13:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/migrating-from-sub-interface-to-l3-interface/m-p/213752#M62152</guid>
      <dc:creator>davanderson</dc:creator>
      <dc:date>2018-05-09T15:13:29Z</dc:date>
    </item>
    <item>
      <title>Re: Migrating from sub-interface to L3 interface</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/migrating-from-sub-interface-to-l3-interface/m-p/213757#M62154</link>
      <description>&lt;P&gt;OP specified they were moving to an L3 interface - not sure you can have two interfaces with same IP even if one is "down."&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;That aside, I feel this is a "tomatoe-tomahto" sort of difference, and agree that either solution is possible and easier than breaking HA and bringing firewalls off/on-line.&lt;/P&gt;</description>
      <pubDate>Wed, 09 May 2018 15:51:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/migrating-from-sub-interface-to-l3-interface/m-p/213757#M62154</guid>
      <dc:creator>JoeAndreini</dc:creator>
      <dc:date>2018-05-09T15:51:28Z</dc:date>
    </item>
    <item>
      <title>Re: Migrating from sub-interface to L3 interface</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/migrating-from-sub-interface-to-l3-interface/m-p/213784#M62161</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/83021"&gt;@JoeAndreini&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;I think you are making this harder than it needs to be...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I would do the following:&lt;/P&gt;&lt;P&gt;1) configure the new ports on the switch in your VLAN and wire it to the new ports on the firewalls&lt;/P&gt;&lt;P&gt;2) just before your maintenance window, configure the new firewall ports and remove the subinterfaces&lt;/P&gt;&lt;P&gt;3) when the maintenance window begins, apply this candidate configuration&lt;/P&gt;&lt;P&gt;4) once you verify everything is functioning, remove the VLAN from the trunk ports on the switch&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;I would also use exactly these steps for this migration. Specially because I can confirm that was working perfectly fine when I did the opposite (migrate from L3 interfaces to subinterfaces).&amp;nbsp;&lt;/P&gt;&lt;P&gt;PaloAlto Firewalls are Zone based firewalls, so the session sync will work during this migration. This is because o&lt;SPAN&gt;n a Palo Alto Networks firewall, a session is defined by two uni-directional flows each uniquely identified by a 6-tuple key: source-address, destination-address, source-port, destination-port, protocol, and security-zone. --&amp;gt; nothing about source-interfaces &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 09 May 2018 18:44:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/migrating-from-sub-interface-to-l3-interface/m-p/213784#M62161</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2018-05-09T18:44:15Z</dc:date>
    </item>
    <item>
      <title>Re: Migrating from sub-interface to L3 interface</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/migrating-from-sub-interface-to-l3-interface/m-p/213849#M62173</link>
      <description>&lt;P&gt;Thanks a lot for the inputs. Their requirement is that they don't want any interuption during this migration because they have a monitoring system on this sub-interface, and any traffic interruption will create a noise/alarm.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I agree with &lt;A href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/83021" target="_blank"&gt;@JoeAndreini&lt;/A&gt;, this migration should be simple. I&amp;nbsp;will try to push with this method with them on a maintenance window.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Again, thanks a lot for the input.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 10 May 2018 00:34:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/migrating-from-sub-interface-to-l3-interface/m-p/213849#M62173</guid>
      <dc:creator>filterfilter</dc:creator>
      <dc:date>2018-05-10T00:34:06Z</dc:date>
    </item>
  </channel>
</rss>

