IP for Cluster HA Active Pasive

cancel
Showing results for 
Search instead for 
Did you mean: 

IP for Cluster HA Active Pasive

L2 Linker

Hello,

We have a 3200 series HA cluster active/passive version 9.1.10.

The requirement is to access through a single ip always to the active node.

That is, I have an IP for the active node and another for the passive node but I want to configure a single IP to access the active node either one or the other.

Can anyone help me to configure it? How do I have to do it?

2 REPLIES 2

L4 Transporter

Thank you @Alpalo for posting question.

 

To my knowledge this is not possible. Management interface is configured individually on each firewall and is not part of HA. Here is the list of items that are not HA synchronized, management interface is on the top of the list: https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/high-availability/reference-ha-synchroniza...

 

I know that some Firewalls for example Cisco ASA has management interface to be part of HA, then when there is a failover the management interface is also changed, however PA does not have this implementation. Can I ask for the reason why this is required?

 

Thank you & Regards

Pavel

Pavel Kucera

L3 Networker

@Alpalo I presume you are referring to the firewall's managed IP address. If this is the case, the management IP need to be unique on each node. 

You have two possible solutions for you task: 

1. Enable firewall management on one of the data interfaces, e.g. ethernet 1/1. You can achieve this by applying interface management profile to it and enable ssh and https. It may also need security policies configuration . This will ensure management connections only to the active HA member. 

2. The other more complex option will be to use some 3rd party load balancer appliance, which can detect the primary member through API calls and sent management traffic to it. 

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!