Enhanced Security Measures in Place:   To ensure a safer experience, we’ve implemented additional, temporary security measures for all users.

Removing peer from HA cluster

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

Removing peer from HA cluster

L0 Member

I have a pair of PA-3020s running 7.1.x in HA configuration. I need to remove the passive switch from the rack to be used in another location. What is the best way to disable the HA and delete the config from the active switch without risk of service interruption. Thanks in advance.

4 REPLIES 4

L6 Presenter

@Joel_Abney wrote:

I have a pair of PA-3020s running 7.1.x in HA configuration. I need to remove the passive switch from the rack to be used in another location. What is the best way to disable the HA and delete the config from the active switch without risk of service interruption. Thanks in advance.


You have A/P and want to move the P firewall to another physical location?

Brandon,

 

Correct. We are re-purposing the device so need to remove HA config from from both FWs but also break the HA connection without creating an outage.

I would go to your passive device and "suspend" it

 

HA.PNG

 

 

This tells your passive device to be non-functional.  

 

I would then disable the physical ports.  Then I would physically remove them.  (HA included).  Then go into your primary device and disable HA services.

 

With the previously passive device on a bench / lab connect the FW to you a computer and remove the HA and make any necessary config changes to the passive device.

 

*I'm not a Palo employee, I'd validate any procedures if you're planing work / projects on these procedures.*

@Joel_Abney,

What @Brandon_Wertz is proposing should work perfectly fine. The only thing that might take into account is that the MAC will likely revert to the original interface MAC address if using L3 interfaces. The device would send out multiple gratuitous ARPs just like it does the first time though, so the MAC/IP listing should be updated fairly quickly. 

 

  • 3147 Views
  • 4 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!