- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
05-04-2023 02:07 PM
Hi,
I have 2 palo alto firewalls configured as active and passive. I want to know how I should configure the Interface IP address (for inside and Dmz) on the passive firewall? Do they have different IP address configured from the active firewall (similar to how we do it on Cisco ASA) ?
Thanks
05-05-2023 09:15 AM
Hi BPry,
Thank you for your reply. When I tried to remove the IP address from the passive firewall using Panorama config deploy , panorama config deploy errored out. Therefore I put the same IP address that I have on the active Palo Alto onto the passive palo alto. Once I deployed the configuration (with both firewalls having the same inside IP) , I did a failover test and it was successful.
05-08-2023 07:59 AM
Active/Passive firewalls should be inside same template in Panorama.
05-04-2023 02:12 PM
You don't configure interface addresses on the passive firewall when you have an Active/Passive pair. The configured interface address(es) will only ever be active on the Active firewall. You'd access the Passive firewall by its MGMT port and it's configured IP address.
05-05-2023 09:15 AM
Hi BPry,
Thank you for your reply. When I tried to remove the IP address from the passive firewall using Panorama config deploy , panorama config deploy errored out. Therefore I put the same IP address that I have on the active Palo Alto onto the passive palo alto. Once I deployed the configuration (with both firewalls having the same inside IP) , I did a failover test and it was successful.
05-08-2023 07:59 AM
Active/Passive firewalls should be inside same template in Panorama.
05-08-2023 11:41 AM
Hi @ismailsh ,
Fun fact for Panorama managing HA firewalls - Panorama always push the configuration separately to both members when they are in active/passive mode.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!