How to set up two HA (active / passive mode) firewalls to be managed by panorama

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

How to set up two HA (active / passive mode) firewalls to be managed by panorama

L0 Member

Hi All,


I already have two firewalls to set HA and use Active / Passive mode.
But when I put both devices into the same Device Groups and Templates and push the configuration file to both devices, the HA settings of the second device will be overwritten by the HA settings of the first device.


I saw this "Migrate a Firewall HA Pair to Panorama Management"


It mentioned that it seems to set variables

Please help me.

 

Thank you!

10 REPLIES 10

The setup looks like this:

JoergSchuetter_0-1579711722123.png

 

JoergSchuetter_1-1579711736856.png

JoergSchuetter_2-1579711754169.png

Besides this, there is only a config for the management interface certificate in the node template.

Hi @JoergSchuetter 

Thanks for sharing. In this case I will give it another try.

The question now is why does paloalto write in the adminguide that IP addresses of HA firewalls can only be configured locally ... @kiwi do you may have the answer?

 

Edit: @JoergSchuetter what PAN-OS version do you use? When I configure the HA IPs in panorama template stack, they are not applied to the firewall. All the HA config works, but when I check locally on the firewall the IPs aren't from the template...

@vsys_remo : We are using this template stack since version 8.0 (works well with 8.1 and 9.0).

One initial step is to clean up the local stored config:

delete rulebase

delete zone trust

delete zone untrust

delete network virtual-wire default-vwire

delete network interface

delete network tunnel

delete network ike

delete network virtual-router default

delete deviceconfig system update-schedule

delete deviceconfig high-availability

delete deviceconfig system timezone

@JoergSchuetter 

Did exactly that (besides the HA config I have nothing locally), but there is no value for HA IP address locally on the firewall ...

@vsys_remo 

What do you mean with "no  value for HA IP address locally"?

It will not be listed on the CLI using "show ..."

Does it show up in the GUI of the firewall?

 

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!