Replacing HA Hardware

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

Replacing HA Hardware

L1 Bithead

Hi All,

I need to replace 3220 in HA to 1420 in HA.

- The 3220 running 11.1.3-h3

- I installed 11.1.3-h3 on the new 1420s.

- Installed the same version of the apps and threats.

- exported the running config from the 3220

- imported the config to the 1420 and ran a commit.

 

I read that i cannot run the HA with different platforms. Is there a way to do a 0 downtime or only hard cutover to the new HA?

2 REPLIES 2

Cyber Elite
Cyber Elite

Hello @ademo-user25

 

thanks for posting!

 

To form HA both Firewalls must be the same HW models: Prerequisites for Active/Passive HA.

 

I have done Data Center Firewall migration before with minimal downtime. Could you please refer to this thread: PALO ALTO 5020 migrate to 5220 from Panorama?

You can skip points No.1 and 2. Also, if you can include more details about your environment it would make it easier and more accurate to answer you. 

 

Kind Regards

Pavel  

Help the community: Like helpful comments and mark solutions.

Hi @PavelK ,

Thanks for the reply.

We have very simple configuration of 2 firewalls in HA. We want to keep the same configuration, IP etc. just with the new hardware.

No Panorama.

We mounted the new firewalls next to the old firewalls.

I've done it on other firewalls but this is the first time i replace palo alto hardware so i am not sure what behavior to expect.

my plan is:

1. disable preemptive

2. move cables from old firewall2 to new firewall2: i am expecting the firewall to be able to see each other but not be a working HA

3. allow new firewall2 to download and activate license from license center.

3. make new firewall2 active. i am expecting to be able to just click for a failover but will disconnect old firewall1 if not.

4. after sanity tests, move cables from old firewall1 to new firewall1.

5. allow new firewall1 to download and activate license from license center.

6. at this point im expecting to see a healthy ha pair.

7. failover to new firewall1

8. run sanity tests

9. reactivate preemptive.

 

This way i am hoping to have no downtime during the replacement.

  • 97 Views
  • 2 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!