<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Swapping the roles of Firewalls in HA Pair in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/swapping-the-roles-of-firewalls-in-ha-pair/m-p/227421#M65444</link>
    <description>&lt;P&gt;Preemption controls what happens when higher priority device returns from down/non-functional state to functional, nothing else.&lt;/P&gt;&lt;P&gt;If it's on, higher priority device becomes active when it&amp;nbsp;&lt;SPAN&gt;returns from down/non-functional state&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;If it's off,&amp;nbsp;&lt;SPAN&gt;higher priority device becomes&amp;nbsp;passive&amp;nbsp; when it&amp;nbsp;returns from down/non-functional state&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Decide how you want your cluster to behave, then control it with preemption.&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 17 Aug 2018 07:22:01 GMT</pubDate>
    <dc:creator>santonic</dc:creator>
    <dc:date>2018-08-17T07:22:01Z</dc:date>
    <item>
      <title>Swapping the roles of Firewalls in HA Pair</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/swapping-the-roles-of-firewalls-in-ha-pair/m-p/226539#M65214</link>
      <description>&lt;P&gt;Hi Guys&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I want to swap the Active/passive roles of the Firewalls in HA pair and let it run for couple of weeks.&lt;/P&gt;&lt;P&gt;I know that can be done by 'suspending the role' from GUI and from CLI too.&lt;/P&gt;&lt;P&gt;want to be careful about pre-emption and donot want to break the HA pair.&lt;/P&gt;&lt;P&gt;Does suspending teh device on active &amp;nbsp;means forcing the device to be passive plus taking it off from HA pair?&lt;/P&gt;&lt;P&gt;any tips that needs to be taken care of?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Thu, 09 Aug 2018 03:33:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/swapping-the-roles-of-firewalls-in-ha-pair/m-p/226539#M65214</guid>
      <dc:creator>R_Sharma</dc:creator>
      <dc:date>2018-08-09T03:33:21Z</dc:date>
    </item>
    <item>
      <title>Re: Swapping the roles of Firewalls in HA Pair</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/swapping-the-roles-of-firewalls-in-ha-pair/m-p/226587#M65222</link>
      <description>&lt;P&gt;Disable pre-empt on both, suspend the local active, done.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I don't have pre-empt on anymore as I would rather failover and run on the other device until I decide the time is right to switch back.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 09 Aug 2018 08:09:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/swapping-the-roles-of-firewalls-in-ha-pair/m-p/226587#M65222</guid>
      <dc:creator>RobinClayton</dc:creator>
      <dc:date>2018-08-09T08:09:37Z</dc:date>
    </item>
    <item>
      <title>Re: Swapping the roles of Firewalls in HA Pair</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/swapping-the-roles-of-firewalls-in-ha-pair/m-p/226589#M65223</link>
      <description>&lt;P&gt;Suspending device means making it non-functional. So yes in a way it's like taking it out of a cluster as it won't take active role again even if the other shuts down.&lt;/P&gt;&lt;P&gt;So you want to make it functional again asap. Pre-emptive will control how cluster behaves when primary device returns.&lt;/P&gt;</description>
      <pubDate>Thu, 09 Aug 2018 08:57:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/swapping-the-roles-of-firewalls-in-ha-pair/m-p/226589#M65223</guid>
      <dc:creator>santonic</dc:creator>
      <dc:date>2018-08-09T08:57:25Z</dc:date>
    </item>
    <item>
      <title>Re: Swapping the roles of Firewalls in HA Pair</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/swapping-the-roles-of-firewalls-in-ha-pair/m-p/226741#M65280</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/71756"&gt;@RobinClayton&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;Disable pre-empt on both, suspend the local active, done.&amp;nbsp;&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;That breaks the HA config leaving you running on only a single firewall. You forgot the last step, un-suspend the now passive box, in order to re-add it to the HA pair.&amp;nbsp; &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1.&amp;nbsp; Make sure pre-empt is disabled on the active firewall and the passive firewall.&lt;/P&gt;&lt;P&gt;2.&amp;nbsp; Suspend the active firewall, thus forcing a fail-over event, switching the roles of the two firewalls.&lt;/P&gt;&lt;P&gt;3.&amp;nbsp; Re-enable the (now) passive firewall, to re-add it to the HA pair.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 10 Aug 2018 18:08:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/swapping-the-roles-of-firewalls-in-ha-pair/m-p/226741#M65280</guid>
      <dc:creator>fjwcash</dc:creator>
      <dc:date>2018-08-10T18:08:03Z</dc:date>
    </item>
    <item>
      <title>Re: Swapping the roles of Firewalls in HA Pair</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/swapping-the-roles-of-firewalls-in-ha-pair/m-p/226855#M65305</link>
      <description>&lt;P&gt;Yeah, I only ever realy suspend when patching so the suspended unit gets rebooted and becomes active anyway.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Rob&lt;/P&gt;</description>
      <pubDate>Mon, 13 Aug 2018 08:04:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/swapping-the-roles-of-firewalls-in-ha-pair/m-p/226855#M65305</guid>
      <dc:creator>RobinClayton</dc:creator>
      <dc:date>2018-08-13T08:04:16Z</dc:date>
    </item>
    <item>
      <title>Re: Swapping the roles of Firewalls in HA Pair</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/swapping-the-roles-of-firewalls-in-ha-pair/m-p/227396#M65441</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/10238"&gt;@santonic&lt;/a&gt;&lt;/P&gt;&lt;P&gt;Thank you. I am talking in terms of upgrading the firewalls in HA pair. As my passive firewall doesn;t use service enroute interface as management interface, it is unable to download the software.&lt;/P&gt;&lt;P&gt;So I have to&amp;nbsp;dis-able and re-enable pre-emp after or&amp;nbsp;before&amp;nbsp;every reboot?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 17 Aug 2018 00:53:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/swapping-the-roles-of-firewalls-in-ha-pair/m-p/227396#M65441</guid>
      <dc:creator>R_Sharma</dc:creator>
      <dc:date>2018-08-17T00:53:14Z</dc:date>
    </item>
    <item>
      <title>Re: Swapping the roles of Firewalls in HA Pair</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/swapping-the-roles-of-firewalls-in-ha-pair/m-p/227421#M65444</link>
      <description>&lt;P&gt;Preemption controls what happens when higher priority device returns from down/non-functional state to functional, nothing else.&lt;/P&gt;&lt;P&gt;If it's on, higher priority device becomes active when it&amp;nbsp;&lt;SPAN&gt;returns from down/non-functional state&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;If it's off,&amp;nbsp;&lt;SPAN&gt;higher priority device becomes&amp;nbsp;passive&amp;nbsp; when it&amp;nbsp;returns from down/non-functional state&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Decide how you want your cluster to behave, then control it with preemption.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 17 Aug 2018 07:22:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/swapping-the-roles-of-firewalls-in-ha-pair/m-p/227421#M65444</guid>
      <dc:creator>santonic</dc:creator>
      <dc:date>2018-08-17T07:22:01Z</dc:date>
    </item>
  </channel>
</rss>

