Interface IP address configuration when firewall in HA active passive

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

Interface IP address configuration when firewall in HA active passive

L1 Bithead

Hi,

 

I have 2 palo alto firewalls configured as active and passive.  I want to know how I should configure the Interface IP address (for inside and Dmz) on the passive firewall?  Do they have different IP address configured from the active firewall (similar to how we do it on Cisco ASA) ?

 

Thanks

 

 

2 accepted solutions

Accepted Solutions

Hi BPry,

 

Thank you for your reply.  When I tried to remove the IP address from the passive firewall using Panorama config deploy , panorama config deploy errored out.  Therefore I put the same IP address that I have on the active Palo Alto onto the passive palo alto.  Once I deployed the configuration (with both firewalls having the same inside IP) , I did a failover test and it was successful. 

View solution in original post

Cyber Elite
Cyber Elite

Active/Passive firewalls should be inside same template in Panorama.

Enterprise Architect, Security @ Cloud Carib Ltd
Palo Alto Networks certified from 2011

View solution in original post

4 REPLIES 4

Cyber Elite
Cyber Elite

@ismailsh,

You don't configure interface addresses on the passive firewall when you have an Active/Passive pair. The configured interface address(es) will only ever be active on the Active firewall. You'd access the Passive firewall by its MGMT port and it's configured IP address. 

Hi BPry,

 

Thank you for your reply.  When I tried to remove the IP address from the passive firewall using Panorama config deploy , panorama config deploy errored out.  Therefore I put the same IP address that I have on the active Palo Alto onto the passive palo alto.  Once I deployed the configuration (with both firewalls having the same inside IP) , I did a failover test and it was successful. 

Cyber Elite
Cyber Elite

Active/Passive firewalls should be inside same template in Panorama.

Enterprise Architect, Security @ Cloud Carib Ltd
Palo Alto Networks certified from 2011

Hi @ismailsh ,

Fun fact for Panorama managing HA firewalls - Panorama always push the configuration separately to both members when they are in active/passive mode.

  • 2 accepted solutions
  • 1931 Views
  • 4 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!