add vsys license from HA pair managed by Panorama. Any step? Reboot required ?

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

add vsys license from HA pair managed by Panorama. Any step? Reboot required ?

L2 Linker

I have a HA pair firewall without vsys license.

Now, i would like to add the vsys license in this HA pair in production environment,

Do the traffic affected ?

how is HA status ?

if so, how to minimize the impact for adding the vsys license ?

 

from some document, the device will be in suspended status. 

some people said that the device have to reboot for enabling the vsys license.

 

Please HELP !

1 REPLY 1

Community Team Member

Hi @Martin_Chung ,

 

Which firewall platform are you using, and how many VSYS do you plan on creating?

 

Adding/retrieving the VSYS license itself should not normally impact traffic. The part that needs to be planned carefully is enabling Multi-Vsys on the HA pair.

 

To minimize impact, I would recommend performing this during a maintenance window and doing the following:

 

  1. Confirm both HA peers are healthy and synchronized.
  2. Export config/device state backups.
  3. Retrieve/install the VSYS license on both firewalls.
  4. Temporarily disable HA config sync. This helps prevent partial or mismatched configuration sync while each peer is being updated individually.
  5. Enable Multi Virtual System Capability on one peer, then the other.
  6. If a peer enters suspended state, make it functional again after both peers match.
  7. Re-enable HA config sync.
  8. Verify HA status, config sync, sessions/traffic, and commit status.

A reboot is not always the main concern here. The bigger concern is the temporary HA mismatch while Multi-VSYS is enabled on one peer and not yet enabled on the other. If the GUI/CLI prompts for a reboot on your specific platform/PAN-OS version, follow that prompt and perform it during the maintenance window.

 

Also, if the firewalls are Panorama-managed, review the Panorama/device group/template configuration after enabling Multi-VSYS. Once Multi-VSYS is enabled, some configuration may need to be assigned or organized by VSYS, so it is best to validate the Panorama push behavior before making additional VSYS changes.




LIVEcommunity team member
Stay Secure,
Jay
Don't forget to Like items if a post is helpful to you!

Please help out other users and “Accept as Solution” if a post helps solve your problem !

Read more about how and why to accept solutions.
  • 121 Views
  • 1 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!