- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
08-07-2026 10:49 AM
We have a pair of PA440s as our main firewall, with a fairly complex but not totally weird configuration - all physical interfaces in use, some with sub-interfaces, NAT to some inbound servers, VPN, URL filtering, etc etc.
We have a new Internet connection - same provider, but with upgraded service that precluded just turning up the speed. It's a different physical line to different vendor equipment, with a new external IP range.
I'm thinking about how I would test and implement this, and here's what I think:
- disable HA so that both PA440s are now standalone - with the same configuration as each other, right?
- keep A on the old connection, leave all connections the same
- patch B's Internet interface into the new connection, and shutdown everything else except mgmt
- reconfigure B for the new IP range, and a different IP from my main range on the internal trusted interface
So then, I could test by shutting down A and bringing up interfaces on B (and changing internal routing as needed) and at least see that outbound-only traffic was behaving, right?
And then, update public DNS to reflect the changed external range and make sure I didn't typo the NAT policies.
Obviously, this is high-level overview. But - am I insane to think this will work (for instance, will the passive of the HA pair have a usable config on it, or will it revert to something else)?
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!

