- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
02-23-2016 08:48 AM
We currently have a HA pair configured in a data centre and will soon be moving to a new site. For a seemless migration, we were wondering if there are any issues with or considerations we'd need to make if we were to disable HA and remove the HA config, reset and move the passive device to the new site to get it up and running, then move the device from the old DC to the new site and join it as the passive device?
In my head, it seems straight-forward, but want to make sure I havent missed anything.
Thanks in advance.
02-23-2016 12:25 PM
Hi,
you can always do following:
- disable preemtion,
- failover to passive,
- move active to the new site, configure for the new site,
- move passive to the new site, push configuration from active, test, enable preemption if it was used.
Not sure about licensing, honestly 🙂
Best regards,
Luciano
02-23-2016 08:57 AM
Hi,
You want to run the 2 firewalls independently? I'm not sure you are allowed to do that from a licensing point of view. You probably have subscriptions for a HA pair, not 2 independent firewalls. You should check with Palo Alto Networks if you can do that for a short period of time.
Regards,
Benjamin
02-23-2016 08:59 AM
Hi Benjamin,
thanks for your reply. I will check with our support provider to see if there is a way round the license issue.
Ash
02-23-2016 08:59 AM
> Yes, you can suspend the passive device first
> Move that passive device to the other site
> Keep the Preemptive option checked for the primary device
I don't see any issues with this deployment, only one concern when the passive unit is in transit the data center will be left with a stand alone device.
02-23-2016 09:02 AM
> Licenses are rolled out per box only so I am assuming you should already have the licenses on the passive unit
02-23-2016 12:25 PM
Hi,
you can always do following:
- disable preemtion,
- failover to passive,
- move active to the new site, configure for the new site,
- move passive to the new site, push configuration from active, test, enable preemption if it was used.
Not sure about licensing, honestly 🙂
Best regards,
Luciano
02-24-2016 02:09 AM
I'm sure PA will be ok with (short) period of time when devices aren't in cluster. Or just don't tell them 🙂
But yeah, all licenses are on both devices.
02-24-2016 02:24 AM
I have been advised that doing this would not cause any licensing issues. It would only cause a license issue if you moved both appliances to separate locations and then ran them as standalone appliances from there on in.
Thanks to all for your assistance.
06-04-2020 02:35 PM
How did this end up working for you? We're about to do the same thing, so I'm wondering if there were any surprises.
Thanks.
06-13-2020 01:46 AM
This worked out great and was fairly straight-forward.
06-13-2020 09:17 AM
Hi,
Need to confirm you did below things
suspend the passive device
Moved to new DC and power it on and it came back as passive automatically?
Regards
06-17-2020 01:54 AM
Hi,
from what I can remember:
1. Disabled the HA Preemptive Election setting on both devices
2. Suspend HA on Primary firewall to failover to Passive device
3. Move Primary to new site and reconfigure as necessary
4. Move Secondary to new site
5. Sync changes from Primary to Secondary
6. Re-enable the Preemtive option
06-17-2020 08:56 AM
Thanks for replying!
We're still in the planning stages, so it'll be some time before we try.
But reading these responses, as well as talking with support and our local sales engineer I'm pretty confident we'll have few issues.
01-08-2021 03:34 PM
I am trying to do the same thing, darn network team did not advise that the circuits for our SDWAN are independent and thus need firewalls in standalone mode. I disabled the secondary, removed the HA configuration rebooted, and also removed the HA cables that were connected.
Did the same for the other firewall, bu they are still show in a active/passive mode with no HA
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!