Adding a firewall back into a AP cluster that has outdated network and device settings

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.
Palo Alto Networks Approved
Palo Alto Networks Approved
Community Expert Verified
Community Expert Verified

Adding a firewall back into a AP cluster that has outdated network and device settings

L0 Member

Hi All,

 

I'm curious if anyone can provide an article or just some basic steps of adding a firewall back into a AP cluster that has "outdated" network and device settings.

 

Firewall-02 was moved to a new location and has a new IP scheme for the network and device settings.

Firewall-01 will be physically moved and needs to rejoin the cluster, but it does have outdated IP settings.

 

I'm assuming the first step is to power up 01 without any copper/fiber connected and console into 01 and update the device management IP first.

1 accepted solution

Accepted Solutions

Cyber Elite
Cyber Elite

Step 1 - Take config backup from both firewalls (Device > Setup > Operations).

Step 2 - Make sure that "Device Priority" of Firewall-02 is lower than Firewall-01 to make sure Firewall-02 stays active firewall.

Step 3 - Cabling (at minimum HA1 cable).

Step 4 - Click "Sync to peer" in Firewall-02 (Dashboard > High Availability widget).

 

If you click "Sync to peer" on Firewall-01 you will push old nic scheme from Firewall-01 to Firewall-02 and your network will go down!

 

In addition mgmt IP change as you pointed out.

Enterprise Architect, Security @ Cloud Carib Ltd
Palo Alto Networks certified from 2011

View solution in original post

3 REPLIES 3

Cyber Elite
Cyber Elite

Step 1 - Take config backup from both firewalls (Device > Setup > Operations).

Step 2 - Make sure that "Device Priority" of Firewall-02 is lower than Firewall-01 to make sure Firewall-02 stays active firewall.

Step 3 - Cabling (at minimum HA1 cable).

Step 4 - Click "Sync to peer" in Firewall-02 (Dashboard > High Availability widget).

 

If you click "Sync to peer" on Firewall-01 you will push old nic scheme from Firewall-01 to Firewall-02 and your network will go down!

 

In addition mgmt IP change as you pointed out.

Enterprise Architect, Security @ Cloud Carib Ltd
Palo Alto Networks certified from 2011

Thanks for this!

Thanks for the solution 🙂

Thanks for the reply. Please mark it as a solution. By the way, does anyone over here is looking for an online casino Canadian dollar, if yes, then you can visit https://casinosanalyzer.ca/online-casinos/canadian-dollar-cad here to find those sites where you can find online real money games. I am also using that website link to find real money gaming sites.
  • 1 accepted solution
  • 5631 Views
  • 3 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!