<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Upgrading a stand alone PA-Firewall 3020  to a HA-Cluster in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/upgrading-a-stand-alone-pa-firewall-3020-to-a-ha-cluster/m-p/228575#M65696</link>
    <description>&lt;P&gt;Hello everybody,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;is there any article or best practice document which discribes the configuration of a Palo Alto 3020 Firewall HA-Cluster active/passive while there is already a working stand alone PA 3020 Firewall.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is it the same way I configure a HA-Cluster out of the box?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.paloaltonetworks.com/documentation/80/pan-os/pan-os/high-availability/set-up-activepassive-ha/configure-activepassive-ha&amp;nbsp;" target="_blank"&gt;https://www.paloaltonetworks.com/documentation/80/pan-os/pan-os/high-availability/set-up-activepassive-ha/configure-activepassive-ha&amp;nbsp;&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Which parts of the config get synced to the peer and which had to be preconfigured on the secondary node?&lt;/P&gt;&lt;P&gt;Something I should pay attention to?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for your support!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Kind regards&lt;/P&gt;</description>
    <pubDate>Tue, 28 Aug 2018 15:15:51 GMT</pubDate>
    <dc:creator>Mvdohe</dc:creator>
    <dc:date>2018-08-28T15:15:51Z</dc:date>
    <item>
      <title>Upgrading a stand alone PA-Firewall 3020  to a HA-Cluster</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/upgrading-a-stand-alone-pa-firewall-3020-to-a-ha-cluster/m-p/228575#M65696</link>
      <description>&lt;P&gt;Hello everybody,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;is there any article or best practice document which discribes the configuration of a Palo Alto 3020 Firewall HA-Cluster active/passive while there is already a working stand alone PA 3020 Firewall.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is it the same way I configure a HA-Cluster out of the box?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.paloaltonetworks.com/documentation/80/pan-os/pan-os/high-availability/set-up-activepassive-ha/configure-activepassive-ha&amp;nbsp;" target="_blank"&gt;https://www.paloaltonetworks.com/documentation/80/pan-os/pan-os/high-availability/set-up-activepassive-ha/configure-activepassive-ha&amp;nbsp;&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Which parts of the config get synced to the peer and which had to be preconfigured on the secondary node?&lt;/P&gt;&lt;P&gt;Something I should pay attention to?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for your support!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Kind regards&lt;/P&gt;</description>
      <pubDate>Tue, 28 Aug 2018 15:15:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/upgrading-a-stand-alone-pa-firewall-3020-to-a-ha-cluster/m-p/228575#M65696</guid>
      <dc:creator>Mvdohe</dc:creator>
      <dc:date>2018-08-28T15:15:51Z</dc:date>
    </item>
    <item>
      <title>Re: Upgrading a stand alone PA-Firewall 3020  to a HA-Cluster</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/upgrading-a-stand-alone-pa-firewall-3020-to-a-ha-cluster/m-p/228594#M65699</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;The process is the same. The way I have done it in the past was to setup the 'active' one first, in your case it would be the one that is already deployed. I would then also set its 'priority' so something like 10 so it'll negotiate as the 'active'. Then I would setup the 'passive' device per the documentation.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.paloaltonetworks.com/documentation/80/pan-os/pan-os/high-availability/set-up-activepassive-ha/configure-activepassive-ha#id2351b088-8534-472b-9f43-34744c9075ec" target="_blank"&gt;https://www.paloaltonetworks.com/documentation/80/pan-os/pan-os/high-availability/set-up-activepassive-ha/configure-activepassive-ha#id2351b088-8534-472b-9f43-34744c9075ec&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope that helps!&lt;/P&gt;</description>
      <pubDate>Tue, 28 Aug 2018 16:40:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/upgrading-a-stand-alone-pa-firewall-3020-to-a-ha-cluster/m-p/228594#M65699</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2018-08-28T16:40:35Z</dc:date>
    </item>
    <item>
      <title>Re: Upgrading a stand alone PA-Firewall 3020  to a HA-Cluster</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/upgrading-a-stand-alone-pa-firewall-3020-to-a-ha-cluster/m-p/228729#M65752</link>
      <description>&lt;P&gt;even it is very easy to change your deployment from standalone to HA, there is one giant caveat: the firewall's MAC addresses will change into shared MACs, so you will need to flush your arp/mac tables on all connected devices&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;other than that, walk in the park &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 29 Aug 2018 11:44:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/upgrading-a-stand-alone-pa-firewall-3020-to-a-ha-cluster/m-p/228729#M65752</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2018-08-29T11:44:51Z</dc:date>
    </item>
    <item>
      <title>Re: Upgrading a stand alone PA-Firewall 3020  to a HA-Cluster</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/upgrading-a-stand-alone-pa-firewall-3020-to-a-ha-cluster/m-p/228741#M65758</link>
      <description>&lt;P&gt;Thanks for your answer!&lt;/P&gt;&lt;P&gt;At which step do you flush the arp tables? After setup of the HA-Cluster?&lt;/P&gt;&lt;P&gt;What means any connceted device? Any virtual machine e.g?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;And which parameters had to be preconfigured on the secondary firewall (mgmt. ip, dns, ha-config, interfaces, virt. router,...) and which parameters will be synced to the peer by setting up the active/passive HA-Cluster.&lt;/P&gt;&lt;P&gt;Is there any best practice paper or knowledge base article?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for your support!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 29 Aug 2018 13:39:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/upgrading-a-stand-alone-pa-firewall-3020-to-a-ha-cluster/m-p/228741#M65758</guid>
      <dc:creator>Mvdohe</dc:creator>
      <dc:date>2018-08-29T13:39:42Z</dc:date>
    </item>
    <item>
      <title>Re: Upgrading a stand alone PA-Firewall 3020  to a HA-Cluster</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/upgrading-a-stand-alone-pa-firewall-3020-to-a-ha-cluster/m-p/228757#M65760</link>
      <description>&lt;P&gt;when you commit the HA config the MAC addresses will change, your routers and switches will benefit most from clearing the cache/reviewing static entries&lt;/P&gt;
&lt;P&gt;Hosts will typically ask for MAC information and won't be impacted as much&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The secondary firewall needs to be configured with a management interface and matching HA config,&lt;/P&gt;
&lt;P&gt;It will also need to be set to the identical software version and ideally (optional but strongly recommended) same content/threat/AV/URL filtering versions&lt;/P&gt;
&lt;P&gt;After the HA is established, the primary member can copy over mostly all config&amp;nbsp; (sync to peer)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Here you can find what is and isn't synced:&amp;nbsp;&amp;nbsp;&lt;A href="https://www.paloaltonetworks.com/documentation/80/pan-os/pan-os/high-availability/reference-ha-synchronization" target="_blank"&gt;https://www.paloaltonetworks.com/documentation/80/pan-os/pan-os/high-availability/reference-ha-synchronization&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;(so in short, you will still need to configure 'system specific' settings like dns, ntp, licensing, content update schedules, HA parameters)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;There is a best practices space that addresses all sorts of deployments:&amp;nbsp;&lt;A href="https://www.paloaltonetworks.com/documentation/best-practices" target="_blank"&gt;https://www.paloaltonetworks.com/documentation/best-practices&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;And there is a best practice on how to upgrade a firewall/cluster&amp;nbsp;&lt;A href="https://live.paloaltonetworks.com/t5/Featured-Articles/Best-Practices-for-PAN-OS-Upgrade/ta-p/111045" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Featured-Articles/Best-Practices-for-PAN-OS-Upgrade/ta-p/111045&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 29 Aug 2018 14:05:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/upgrading-a-stand-alone-pa-firewall-3020-to-a-ha-cluster/m-p/228757#M65760</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2018-08-29T14:05:28Z</dc:date>
    </item>
    <item>
      <title>Re: Upgrading a stand alone PA-Firewall 3020  to a HA-Cluster</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/upgrading-a-stand-alone-pa-firewall-3020-to-a-ha-cluster/m-p/228758#M65761</link>
      <description>&lt;P&gt;Hi reaper,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thanks for your feedback, that helps me a lot.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Have a nice day!&lt;/P&gt;</description>
      <pubDate>Wed, 29 Aug 2018 14:13:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/upgrading-a-stand-alone-pa-firewall-3020-to-a-ha-cluster/m-p/228758#M65761</guid>
      <dc:creator>Mvdohe</dc:creator>
      <dc:date>2018-08-29T14:13:00Z</dc:date>
    </item>
  </channel>
</rss>

