<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Panorama High availability in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/panorama-high-availability/m-p/10211#M7498</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Brian/Judy,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It would be best if you work with your systems engineer from PA to discuss your scenario and answer your questions.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 19 Jul 2011 22:22:28 GMT</pubDate>
    <dc:creator>mrajdev</dc:creator>
    <dc:date>2011-07-19T22:22:28Z</dc:date>
    <item>
      <title>Panorama High availability</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/panorama-high-availability/m-p/10208#M7495</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Are there any issues with running 2 Panorama servers in an HA configuration across a WAN?&amp;nbsp; Recommendations for configuring hold timers and various interval settings?&lt;/P&gt;&lt;P&gt;Judy&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 28 Apr 2011 18:37:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/panorama-high-availability/m-p/10208#M7495</guid>
      <dc:creator>ImplementationEngineering</dc:creator>
      <dc:date>2011-04-28T18:37:14Z</dc:date>
    </item>
    <item>
      <title>Re: Panorama High availability</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/panorama-high-availability/m-p/10209#M7496</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;When you say Panorama HA across a WAN, what exactly are yo talking about?&amp;nbsp; Panorama1 and Panorama2 are at opposit ends of a WAN link? Or Pan1 and Pan2 are located at one site and the firewalls are located at a diffeent site?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Logging over the WAN&amp;nbsp; depends entirely on your traffic through the firewall and how much data you log. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Steve Krall&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 06 May 2011 17:04:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/panorama-high-availability/m-p/10209#M7496</guid>
      <dc:creator>skrall</dc:creator>
      <dc:date>2011-05-06T17:04:44Z</dc:date>
    </item>
    <item>
      <title>Re: Panorama High availability</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/panorama-high-availability/m-p/10210#M7497</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We are also concerned about the operation of HA between Panorama servers in multiple locations, as well as logging from PA firewalls across the WAN.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;FYI - our WAN is very fast, high-speed links with not much traffic, i.e. 10Gbps, and the sites are not that far apart (say &amp;lt; 30ms nominal).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We want to know about:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;HA syncing between Panorama 1 and Panorama 2&lt;/LI&gt;&lt;LI&gt;HA failover from Panorama 1 to Panorama 2&lt;/LI&gt;&lt;LI&gt;specific configuration "knobs" that impact false-positive and false-negative regarding HA (HA failovers that are not necessary, or actual failures that do not trigger HA, respectively).&lt;/LI&gt;&lt;LI&gt;rules-of-thumb regarding latency, bandwidth-delay product, how HA is done (TCP/UDP, which ports, what IP options, TCP/UDP options, etc.)&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HA syncing and failover - what is automated, and what needs to be done manually? On Panorama? On PA firewalls in Active/Standby?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What gets synced between Panorama instances? Just configs? How about logs? Is there any way to de-dup logs sent to two Panoramas? Are there any special techniques/commands/tools to support merging/syncing/de-duping logs, e.g. via a third Panorama?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What are the options regarding exporting (e.g. ranges of dates), and clearing (also ranges of dates) logs?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What are the performance/scalability limits on logs? Is there a way to partition the DB for historical views, that avoids some of these issues? What DB is used, is there a published schema for it, are there third party tools available for managing the DB for logs?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Brian Dickson&lt;/P&gt;&lt;P&gt;bdickson at verisign dot com&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 19 Jul 2011 20:35:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/panorama-high-availability/m-p/10210#M7497</guid>
      <dc:creator>brdickson</dc:creator>
      <dc:date>2011-07-19T20:35:08Z</dc:date>
    </item>
    <item>
      <title>Re: Panorama High availability</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/panorama-high-availability/m-p/10211#M7498</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Brian/Judy,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It would be best if you work with your systems engineer from PA to discuss your scenario and answer your questions.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 19 Jul 2011 22:22:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/panorama-high-availability/m-p/10211#M7498</guid>
      <dc:creator>mrajdev</dc:creator>
      <dc:date>2011-07-19T22:22:28Z</dc:date>
    </item>
    <item>
      <title>Re: Panorama High availability</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/panorama-high-availability/m-p/10212#M7499</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Brian,&lt;/P&gt;&lt;P&gt;Since you have a lot of questions I think it would be good to setup a call with me (Panorama PM) and your SE.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I will reach out to you unicast to set this up.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Mike Schuricht&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 22 Jul 2011 15:48:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/panorama-high-availability/m-p/10212#M7499</guid>
      <dc:creator>mschuricht</dc:creator>
      <dc:date>2011-07-22T15:48:34Z</dc:date>
    </item>
    <item>
      <title>Re: Panorama High availability</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/panorama-high-availability/m-p/10213#M7500</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Brian asks some good questions regarding the inner workings of Panorama. Is there any available documentation that covers at least some portion of what he's asking? Or are we supposed to go thru our SE to get any of this detail? &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 10 Aug 2011 20:51:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/panorama-high-availability/m-p/10213#M7500</guid>
      <dc:creator>chrisp</dc:creator>
      <dc:date>2011-08-10T20:51:40Z</dc:date>
    </item>
    <item>
      <title>Re: Panorama High availability</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/panorama-high-availability/m-p/10214#M7501</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;There is some documentation on setup procedures in the admin guide and I would also suggest talking with your SE to get some added details. At that point if there are still open item we can have a conf call if needed.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 10 Aug 2011 23:02:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/panorama-high-availability/m-p/10214#M7501</guid>
      <dc:creator>mschuricht</dc:creator>
      <dc:date>2011-08-10T23:02:29Z</dc:date>
    </item>
    <item>
      <title>Re: Panorama High availability</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/panorama-high-availability/m-p/10215#M7502</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I was wondering on this issue, if Panorama is able to sync databases from two geo-located instances for HA?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If so what documentation is the referenced?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 29 Feb 2012 00:48:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/panorama-high-availability/m-p/10215#M7502</guid>
      <dc:creator>erantanen</dc:creator>
      <dc:date>2012-02-29T00:48:39Z</dc:date>
    </item>
    <item>
      <title>Re: Panorama High availability</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/panorama-high-availability/m-p/10216#M7503</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;There is no sync of the log databases between HA peers. Devices send logs to both Panorama HA instances by default when utilizing VMware virtual disk storage so the sync is not needed. The devices will buffer logs if connectivity is lost, to either Panorama, and then spooled to the disconnected Panorama upon reconnection. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 29 Feb 2012 03:12:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/panorama-high-availability/m-p/10216#M7503</guid>
      <dc:creator>mschuricht</dc:creator>
      <dc:date>2012-02-29T03:12:44Z</dc:date>
    </item>
    <item>
      <title>Re: Panorama High availability</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/panorama-high-availability/m-p/10217#M7504</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I reuse this thread since this is a semi high availability question regarding Panorama.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is it possible to setup Panoroma this way?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1) One Panorama at each site (datacenter).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Well of course this on its own will work but this is just to explain what Im thinking of &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2) Devices at siteX will log to Panorama at siteX.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is also pretty straight through since you setup the ip of the Panorama in each device.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;3) Each Panorama will then send a copy of the logs to a syslogserver (along with adminlogs).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is this possible today? Or must each device send the syslogs to the syslogserver?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;4) Configurations are synched between all Panoramas so it doesnt matter which Panorama the administrator logins to in order to change a security rule or such.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is the main question. The idea is that logs are handled locally at each site (datacenter) where configurations are redundant at all Panoramas. Like a clustering feature of Panaroma. The point here is also to keep the logs locally (no need to synchronise logs between Panoramas/Sites in this case) but as backup the archive feature will be used.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 29 Feb 2012 07:48:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/panorama-high-availability/m-p/10217#M7504</guid>
      <dc:creator>mikand</dc:creator>
      <dc:date>2012-02-29T07:48:23Z</dc:date>
    </item>
    <item>
      <title>Re: Panorama High availability</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/panorama-high-availability/m-p/181301#M56016</link>
      <description>&lt;P&gt;This is reply to a old post, but for the benefit of the community ...&lt;/P&gt;&lt;P&gt;As per admin guide you can ping between both Panorama servers using mgmt IPs (across the wan in this case), and if the response times are sub 500ms then you're good to go!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Ajaz Nawaz&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 11 Oct 2017 13:31:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/panorama-high-availability/m-p/181301#M56016</guid>
      <dc:creator>nawaza</dc:creator>
      <dc:date>2017-10-11T13:31:01Z</dc:date>
    </item>
  </channel>
</rss>

