<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Panorama templates for an Active/Passive setup? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/panorama-templates-for-an-active-passive-setup/m-p/245388#M69936</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/45395"&gt;@dstjames&lt;/a&gt;thanks for the reply.&amp;nbsp; That is actually what I ended up trying and it seems to work.&amp;nbsp; Panorama actually has no config information for those fields and they're just defined locally on the firewalls.&amp;nbsp; Since they won't sync even after config sync is re-enabled, they should remain unique on each.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm really curious why the instructions are worded like that... it doesn't make it clear if they're talking about management IP/hostname config in the Panorama templtate or the settings on the local configs on the firewalls.&lt;/P&gt;</description>
    <pubDate>Wed, 09 Jan 2019 20:07:01 GMT</pubDate>
    <dc:creator>jsalmans</dc:creator>
    <dc:date>2019-01-09T20:07:01Z</dc:date>
    <item>
      <title>Panorama templates for an Active/Passive setup?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/panorama-templates-for-an-active-passive-setup/m-p/245353#M69933</link>
      <description>&lt;P&gt;I'm in the process of setting up our new firewalls.&amp;nbsp; I went ahead and set up management on each of them, got them updated, got them paired up into Active/Passive, and am now following the Palo Alto 8.1 guide to migrate an HA config over to Panorama.&amp;nbsp; I'm almost to the end but I have a question concerning the templates.&amp;nbsp; The instructions say to delete the template for the secondary and then add the secondary into the template for the primary, but it also says:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;"Do not combine the HA firewall pair in to a single template if a unique Hostname, management IP address, or HA configuration is configured for each HA peer."&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I find this a little confusing since everything I've read indicates that each unit in the A/P pair still has to have unique management IP, hostname, etc.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The guide I'm following is here:&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/panorama/8-1/panorama-admin/manage-firewalls/transition-a-firewall-to-panorama-management/migrate-a-firewall-ha-pair-to-panorama-management" target="_self"&gt;https://docs.paloaltonetworks.com/panorama/8-1/panorama-admin/manage-firewalls/transition-a-firewall-to-panorama-management/migrate-a-firewall-ha-pair-to-panorama-management&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can anyone clue me in on what best practices is here?&amp;nbsp; My intention was to have a single config with A/P so I don't have to duplicate VPN changes on a second template.&amp;nbsp; The instructions say to turn config sync back on at the end too so it sounds like it is supposed to use a single template but then wouldn't that mean the passive firewall would be unreachable on its management port, even to Panorama?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Wed, 09 Jan 2019 17:06:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/panorama-templates-for-an-active-passive-setup/m-p/245353#M69933</guid>
      <dc:creator>jsalmans</dc:creator>
      <dc:date>2019-01-09T17:06:57Z</dc:date>
    </item>
    <item>
      <title>Re: Panorama templates for an Active/Passive setup?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/panorama-templates-for-an-active-passive-setup/m-p/245387#M69935</link>
      <description>&lt;P&gt;I usually setup the hostname, management IP and HA information locally on each firewall then push everything else out from a single template to both firewalls.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I also have 2 templates that I have setup in a template stack. 1 that has basic configurations that I want all firewalls in the environment to have like NTP servers, logging servers, etc. Then I have a specific template for each HA pair in the template stack and push the template stack out to the firewalls. This way you can make sure that the common settings are applied the exact same to all firewalls in the environment but also maintain individual site settings.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Not sure if this is best practice but its how I configured it.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 09 Jan 2019 19:56:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/panorama-templates-for-an-active-passive-setup/m-p/245387#M69935</guid>
      <dc:creator>dstjames</dc:creator>
      <dc:date>2019-01-09T19:56:54Z</dc:date>
    </item>
    <item>
      <title>Re: Panorama templates for an Active/Passive setup?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/panorama-templates-for-an-active-passive-setup/m-p/245388#M69936</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/45395"&gt;@dstjames&lt;/a&gt;thanks for the reply.&amp;nbsp; That is actually what I ended up trying and it seems to work.&amp;nbsp; Panorama actually has no config information for those fields and they're just defined locally on the firewalls.&amp;nbsp; Since they won't sync even after config sync is re-enabled, they should remain unique on each.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm really curious why the instructions are worded like that... it doesn't make it clear if they're talking about management IP/hostname config in the Panorama templtate or the settings on the local configs on the firewalls.&lt;/P&gt;</description>
      <pubDate>Wed, 09 Jan 2019 20:07:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/panorama-templates-for-an-active-passive-setup/m-p/245388#M69936</guid>
      <dc:creator>jsalmans</dc:creator>
      <dc:date>2019-01-09T20:07:01Z</dc:date>
    </item>
  </channel>
</rss>

