<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PA 2020 Active/Passive HA in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/pa-2020-active-passive-ha/m-p/8822#M6464</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Since both the peers are showing as Active-Active. It means that they haven't communicated to each other still. This seems like a configuration problem. Please make sure the following things are correct 1) both the Pan devices are running same software version&lt;/P&gt;&lt;P&gt;2) the HA group id is same for both the pan devices 3) use a crossover cable for ha2 ports 4) peer ids are matching across both the ends of pan devices. If the HA realationship forms correctly one device will be in active state and the other will be in the passive state. The command "show high availability all" will give all the info about the HA state on the device and also about peer state.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;you need not have both the devices in the default config. As long as you configure ha parameters correctly on both the devices and they are in ha relationship, config syncshould work. One more thing,&amp;nbsp; you can sync the config from both the acitve side ----&amp;gt; passive side and also the other way. so please be care ful which side your are doing it from, in case if you sync config from the default config side (passive side ) to the other side, it will wipe out all the config on the other side.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Tx,&lt;/P&gt;&lt;P&gt;Sandeep T&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 09 Feb 2012 16:20:01 GMT</pubDate>
    <dc:creator>sdurga</dc:creator>
    <dc:date>2012-02-09T16:20:01Z</dc:date>
    <item>
      <title>PA 2020 Active/Passive HA</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-2020-active-passive-ha/m-p/8820#M6462</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;I am configuring Active/Passive PA 2020 &lt;/EM&gt;&lt;EM&gt;firewall&lt;/EM&gt;&lt;/STRONG&gt; &lt;EM&gt;&lt;STRONG&gt;for clustering . I have configured all the parameters for HA including the links(HA1 and HA2). Also the firewall are connected and both the HA interfaces are showing up. I am making One PA Firewall as Active by lowering its device Priority (100)and other as standby (priority 150).&amp;nbsp; I am seeing ,that both the PA firewall are showing as active and when I click on "Sync the config" , I am getting the error shown in the attached file.&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt; &lt;EM&gt;&lt;STRONG&gt;Please advice me where am I making mistake. Also my Active firewall has some configuration done on it and my other firewall is on default configuration. Should I bring both the firewall on default config and then configure the HA ? Please advice.&lt;BR /&gt;&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&lt;STRONG&gt;&lt;BR /&gt;&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 09 Feb 2012 15:40:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-2020-active-passive-ha/m-p/8820#M6462</guid>
      <dc:creator>itsecll</dc:creator>
      <dc:date>2012-02-09T15:40:40Z</dc:date>
    </item>
    <item>
      <title>Re: PA 2020 Active/Passive HA</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-2020-active-passive-ha/m-p/8821#M6463</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi...I notice the PA2020 is running version 4.1.0.&amp;nbsp; I recommend that you upgrade both PA2020s to version 4.1.2.&amp;nbsp; You reported that both units are running in Active HA mode, that may mean the units are not seeing each other. We should see 1 unit to be Active and the other should be Passive.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can verify via CLI if they have an HA peer:&lt;/P&gt;&lt;P&gt;&amp;gt; show high-availability state&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If there is no peer, I recommend that you doublecheck your HA config and the HA cabling.&amp;nbsp; Thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 09 Feb 2012 16:18:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-2020-active-passive-ha/m-p/8821#M6463</guid>
      <dc:creator>rmonvon</dc:creator>
      <dc:date>2012-02-09T16:18:30Z</dc:date>
    </item>
    <item>
      <title>Re: PA 2020 Active/Passive HA</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-2020-active-passive-ha/m-p/8822#M6464</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Since both the peers are showing as Active-Active. It means that they haven't communicated to each other still. This seems like a configuration problem. Please make sure the following things are correct 1) both the Pan devices are running same software version&lt;/P&gt;&lt;P&gt;2) the HA group id is same for both the pan devices 3) use a crossover cable for ha2 ports 4) peer ids are matching across both the ends of pan devices. If the HA realationship forms correctly one device will be in active state and the other will be in the passive state. The command "show high availability all" will give all the info about the HA state on the device and also about peer state.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;you need not have both the devices in the default config. As long as you configure ha parameters correctly on both the devices and they are in ha relationship, config syncshould work. One more thing,&amp;nbsp; you can sync the config from both the acitve side ----&amp;gt; passive side and also the other way. so please be care ful which side your are doing it from, in case if you sync config from the default config side (passive side ) to the other side, it will wipe out all the config on the other side.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Tx,&lt;/P&gt;&lt;P&gt;Sandeep T&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 09 Feb 2012 16:20:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-2020-active-passive-ha/m-p/8822#M6464</guid>
      <dc:creator>sdurga</dc:creator>
      <dc:date>2012-02-09T16:20:01Z</dc:date>
    </item>
    <item>
      <title>Re: PA 2020 Active/Passive HA</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-2020-active-passive-ha/m-p/8823#M6465</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="color: #0000ff;"&gt;&lt;EM&gt;Thanks for the reply. I cannot use a cross cable becoz I am running HA1 and HA2 on fiber (SFP) ports. Actually , as per design the two PA firewalls are intwo different buildings, so due to distance constrain , I have to use the Fiber bots for HA. &lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #0000ff;"&gt;&lt;EM&gt; I have one doubt , please clear and I am sure that I am making mistake in that, when I edited the HA parameters , I used HA peer IP as 1.1.1.2 and when I configured&amp;nbsp; Control Link HA1 IP address , I used a different subnet (10.1.0.0/24) , do I have to configure them with the same subnet.? I think yes? Plea&lt;/EM&gt;&lt;/SPAN&gt;&lt;SPAN style="color: #0000ff;"&gt;&lt;EM&gt;se advice&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 09 Feb 2012 16:34:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-2020-active-passive-ha/m-p/8823#M6465</guid>
      <dc:creator>itsecll</dc:creator>
      <dc:date>2012-02-09T16:34:12Z</dc:date>
    </item>
    <item>
      <title>Re: PA 2020 Active/Passive HA</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-2020-active-passive-ha/m-p/8824#M6466</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;yes, the IP address for HA1 should correspond to the IP address for the peer.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 09 Feb 2012 16:38:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-2020-active-passive-ha/m-p/8824#M6466</guid>
      <dc:creator>rmonvon</dc:creator>
      <dc:date>2012-02-09T16:38:29Z</dc:date>
    </item>
    <item>
      <title>Re: PA 2020 Active/Passive HA</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-2020-active-passive-ha/m-p/8825#M6467</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You have the option of running the firewalls' HA1 ports in the same subnet or different subnets.&amp;nbsp; If they're in the same subnet, leave the Gateway in the Control Link section of the config blank.&amp;nbsp; If they're in different subnets, you'll want to specify the correct Gateway address in order to achieve layer 3 connectivity.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Nick Campagna&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 10 Feb 2012 18:42:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-2020-active-passive-ha/m-p/8825#M6467</guid>
      <dc:creator>ncampagna</dc:creator>
      <dc:date>2012-02-10T18:42:21Z</dc:date>
    </item>
    <item>
      <title>Re: PA 2020 Active/Passive HA</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-2020-active-passive-ha/m-p/8826#M6468</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks&amp;nbsp; to all for the reply and support . Really appreciated&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 14 Feb 2012 17:41:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-2020-active-passive-ha/m-p/8826#M6468</guid>
      <dc:creator>itsecll</dc:creator>
      <dc:date>2012-02-14T17:41:06Z</dc:date>
    </item>
  </channel>
</rss>

