04-04-2023 02:12 AM
Hello, I need to change 2 palo alto from active/active to active/passive. Is there any guide or something that I can follow or understand what's need to be change.
I already have changed but lost connection on my globalprotect, I can connect but looks like I don't have any connection internaly.
04-04-2023 05:09 AM
Hi @hpitta ,
Did you configure the active/active HA or did someone else? You need to remove any A/A use case configuration (floating IP addresses, ARP load sharing, etc.). https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/high-availability/set-up-activeactive-ha/d...
The cool thing about A/P HA is that the configuration is the same as a single NGFW. All that is needed is a single IP address per interface.
When you make a change of this scope, you need to be ready to clear the ARP tables of your connected L3 devices just like you were replacing a firewall. If your IP addresses have changed, you need to change your routing configuration on connected devices.
04-04-2023 06:20 AM
(network -> tunnel -> global-protect-gateway -> GP_GW-N -> local-address -> floating-ip -> ipv4 '' is not a valid reference"
04-04-2023 06:54 AM
Hi @hpitta ,
Thanks for the info. Notice the "floating-ip" in the error message. I mentioned floating IP addresses in my 1st post. Open the gateway configuration and change the selection to the IP address on the interface. That will fix the error above. You probably will get many more errors.
This is a complicated process, and I cannot walk you through every change. Please open a TAC case if you need more in-depth help. If you want to do it on your own, you will need to familiarize yourself with the (1) use case configurations, (2) routing changes, and (3) ARP behavior, and be ready to make changes on the NGFW and connected network devices.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!