Enhanced Security Measures in Place:   To ensure a safer experience, we’ve implemented additional, temporary security measures for all users.

Migration of HA Pair to Panorama!

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

Migration of HA Pair to Panorama!

L2 Linker

Hello Folks,

 

I'm planning to Migration of HA Pair (active-passive) to Panorama, can someone help to understand whether ther will be a service interruption during this phase?

 

HA Pair -> 8.1

Panorama -> 8.1

 

Best Regards,

Pradeepkumar 

1 accepted solution

Accepted Solutions

L2 Linker

There should not be any service interruption on migration of an existing HA pair into Panorama Management.

Here is the link to the steps to complete the setup: 

https://docs.paloaltonetworks.com/panorama/8-1/panorama-admin/manage-firewalls/transition-a-firewall...

Refer to : Migrate a Firewall HA Pair to Panorama Management

Thanks

View solution in original post

6 REPLIES 6

L2 Linker

There should not be any service interruption on migration of an existing HA pair into Panorama Management.

Here is the link to the steps to complete the setup: 

https://docs.paloaltonetworks.com/panorama/8-1/panorama-admin/manage-firewalls/transition-a-firewall...

Refer to : Migrate a Firewall HA Pair to Panorama Management

Thanks

@bseal 

 

Thanks for your quick turn-up!

 

I was going through the link you provided, even though it didn't say explicitly that the migration is non-disruptive, but it does mentioned If we have a pair of firewalls in an HA configuration that you want to manage using Panorama, you have the option to import the configuration local to your firewall HA pair to Panorama without needing to recreate any configurations or policies, is my assumption are correct?

 

Thanks in advance.

The steps mentioned in the article provides step by step process, where an existing HA-pair configuration ( config-local to the firewall) is migrated to the Panorama Management. 

Steps are to be executed for each firewall in HA unit, so at any point of time there is always a firewall available to take care of the traffic flow.

Make sure to clear Enable Sync between the units till migration is complete.


Thanks

@bseal 

 

it makes sense, thanks for your time and effort!

Hi Pradeep can I ask what your final template stack / template setup was post-onboarding?  When I do this I am left with a spare template from the second firewall in the HA pair being imported and Im wondering if I can just delete this.

Did you finish up with 1 template containing 1 template and both firewalls i the pair assigned to the 1 stack?

 

Many thanks

L2 Linker

@CyberEng I have migrated over a dozen HA pairs, we always delete the orphan template, both devices in the HA pair remain under the template created by the first peer.

Roderick De La Rosa, PCNSA
Information Security Analyst
  • 1 accepted solution
  • 6141 Views
  • 6 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!