<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: move subinterfaces to new aggreagate group in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/move-subinterfaces-to-new-aggreagate-group/m-p/239139#M68496</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;The good news is the security policies rely on zones so as long as the interfaces are in the same zones, you should be OK. I would then test, off hours, by removing one subinterface and then creating it on the new AE. You will also have to update your VirtualRouter with the routes on the subinterfaces. So take it slow and do one at a time off hours and you should be OK.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;</description>
    <pubDate>Thu, 08 Nov 2018 19:37:34 GMT</pubDate>
    <dc:creator>OtakarKlier</dc:creator>
    <dc:date>2018-11-08T19:37:34Z</dc:date>
    <item>
      <title>move subinterfaces to new aggreagate group</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/move-subinterfaces-to-new-aggreagate-group/m-p/239071#M68474</link>
      <description>&lt;P&gt;Hey guys,&lt;/P&gt;&lt;P&gt;I got a pair of PA-3020s (8.0.7) and 2 ae's with a lof of subinterfaces. Each subinterface does have a gateway, security zone and vlan tag.&lt;/P&gt;&lt;P&gt;Out of permonance issues, I want to create a third ae with two new physical interfaces.&lt;/P&gt;&lt;P&gt;Then, I want to move some subinterfaces to that new ae.&lt;/P&gt;&lt;P&gt;What would be the smartest way to do that? (Without loosing any security rules etc.)&lt;/P&gt;&lt;P&gt;Thank you.&lt;/P&gt;</description>
      <pubDate>Thu, 08 Nov 2018 14:51:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/move-subinterfaces-to-new-aggreagate-group/m-p/239071#M68474</guid>
      <dc:creator>MPI-AE</dc:creator>
      <dc:date>2018-11-08T14:51:51Z</dc:date>
    </item>
    <item>
      <title>Re: move subinterfaces to new aggreagate group</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/move-subinterfaces-to-new-aggreagate-group/m-p/239139#M68496</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;The good news is the security policies rely on zones so as long as the interfaces are in the same zones, you should be OK. I would then test, off hours, by removing one subinterface and then creating it on the new AE. You will also have to update your VirtualRouter with the routes on the subinterfaces. So take it slow and do one at a time off hours and you should be OK.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Thu, 08 Nov 2018 19:37:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/move-subinterfaces-to-new-aggreagate-group/m-p/239139#M68496</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2018-11-08T19:37:34Z</dc:date>
    </item>
    <item>
      <title>Re: move subinterfaces to new aggreagate group</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/move-subinterfaces-to-new-aggreagate-group/m-p/239283#M68517</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;does the HA pair inherit that configuration change?&lt;/P&gt;</description>
      <pubDate>Fri, 09 Nov 2018 12:24:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/move-subinterfaces-to-new-aggreagate-group/m-p/239283#M68517</guid>
      <dc:creator>MPI-AE</dc:creator>
      <dc:date>2018-11-09T12:24:00Z</dc:date>
    </item>
    <item>
      <title>Re: move subinterfaces to new aggreagate group</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/move-subinterfaces-to-new-aggreagate-group/m-p/239349#M68540</link>
      <description>&lt;P&gt;If you have enabled config sync in the HA configuration then it will automatically be applied to the second firewall.&lt;/P&gt;</description>
      <pubDate>Sat, 10 Nov 2018 00:42:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/move-subinterfaces-to-new-aggreagate-group/m-p/239349#M68540</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2018-11-10T00:42:53Z</dc:date>
    </item>
  </channel>
</rss>

