- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
02-25-2026 07:46 AM - edited 02-25-2026 07:47 AM
Just completed the PALO BPA and we have a recommendation for "No backup to the HA1 peer IP address is configured" We've tested failover and it works perfectly but my understanding is that this is incase the primary HA connection went down. I read different opinions that using the management interface IP for this fine? Has anyone done that? And if so my question is if I am on my primary do I set the Backup Peer HA1 IP Address to its management interface or to the the IP of the management interface on the secondary firewall? I couldn't find anything explaining that.
02-25-2026 10:25 AM
Hi @Walt ,
Using the management IP address for the Peer HA1 IP Address or the Backup Peer HA1 IP Address is fine. I have done it many times. It saves you from having to create a dedicated HA interface. You would configure the Backup Peer HA1 IP Address as the management IP address of the other NGFW.
Thanks,
Tom
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!

