PA Cluster and Panorama Template

L4 Transporter

PA Cluster and Panorama Template


i am trying to understand how to use Pannorama with PA cluster

my view of panorama is: if you have pannorama you should never have to login to the PA itself for configuration.

right now i have one PA cluster and one pannorama server (the PA have a customer configuration on it)

i started playing and testing for what i will do so my steps where until now:

  1. Upgrade all the device software to the relevant software version
  2. Verify the cluster is working and synced
  3. Backup the two PA device
  4. Add the PA serial number to the Panorama
  5. Configure the PA device with the Panorama IP and commit configuration
  6. Verify the PA had connected to the panorama server
  7. Create a new template and add the two devices
    • Check the Group HA Peers
  8. taking the users configur from the cluster and placing it inside the template throught the cli:
    • set mgt-config users
  9. i played arround and verified that the templates are synced between the two PA and the pannorama
  10. changing stuf commiting and checking and everything is fine EXCEPT:
  11. i tried to change the password of one user and commit it only on one of the PA and what i have seen that the PA itself does not synchronizing the configuration to its peer, and that one is marked as synchronized and the other as out of sync

what i am having hard to understand is:

  1. why on the template area at PA i cannot see the two PA device as one device (for example group HA Peers)?
  2. why the configuration is really sent only to one device and does not synced to the other device?
  3. after i overrite the configuration on the PA device with the template configuration i cannot see this configuration on the PA device previously where under: set mgt-config users
L4 Transporter

also i have seen that when i commit the template only on one device the the other peer turns into not functional but the runnig config is still shown as synchronized, and also when i do commit the template on both of the device the state of the non-functional device must be manually chaged throught the CLI

and also when i commit the template on both of the device at once after the commit on both of them is finished on is becoming non-functional

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!