- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
08-23-2024 07:36 AM
I’m attempting to configure active/passive HA on a PA-450 using Strata Cloud Manager as per this guide: https://docs.paloaltonetworks.com/ngfw/administration/high-availability/set-up-activepassive-ha/conf...
I’m aware a PA-450 doesn’t have dedicated HA ports, however when using Panorama I can set Eth1/7 & Eth1/8 to HA mode as shown in the image below and it works fine:
When using Strata Cloud Manager, HA mode is not an option on interface configuration.
Using the Strata HA workflow, I’m able to set HA-1 to use the management interface, but then unable to list data interfaces as candidate for HA-2,
I’ve ensured that data interfaces are configured and set to L3 mode on each firewall in the pair.
Does anyone have any experience with this please?
08-23-2024 09:13 AM
The 'Interface Type' needs to be Default to be used for HA configuration in SCM. This needs to be configured in SCM at the Configuration Scope of each HA firewall.
That is what worked for me.
08-23-2024 09:13 AM
The 'Interface Type' needs to be Default to be used for HA configuration in SCM. This needs to be configured in SCM at the Configuration Scope of each HA firewall.
That is what worked for me.
08-23-2024 10:22 AM
Thanks Mike, I'll try that next week.
Just to confirm is the Interface type 'default' only for the interfaces intended for HA-1 & HA-2, or ALL other data interfaces as well?
08-23-2024 10:46 AM
Just the interfaces you want to use for HA.
08-27-2024 07:58 AM - edited 08-27-2024 08:00 AM
Hi @MikeFreyman-WWT
Thanks for the help, I finally got this working today after a bit of a journey!
(I'm attempting to use folders/snippets and variables from Day1)
Journey:
11-07-2024 05:14 AM
I am writing a reply to this, because I REALLY tried to follow along with the steps, but could not understand.
I needed to open a TAC case to get this simple configuration done. (Argh, if only tech documentation could be written much clearer. :P)
So, in basic terms, create your folder structure as you would for NGFW FWs.
For me, I ignore putting anything in the highest (parent) folder of All Firewalls.
I created a folder (LIB Firewalls) in SCM, and put 2 FWs in that folder (FW-A and FW-B)
I created my variable and interfaces in the parent LIB Firewalls folder. (not shown here)
But real clarification is to go to the actual FW-DEVICE (FW-A and FW-B).
This is my "before" picture (I want to have eth1/3 and eth1/4 used for HA)
Notice that eth 3 and eth 4 show as Not Configured.
I clicked on ethernet1/3
When you add your interfaces (which will be only for HA in my example ), you are presented with the ADD Ethernet window,
(Viola!) this is where you see the mysterious Interface Type with a radio button of Default.
You do not need to do anything anything, just hit OK, and the interface is now created (in the device folder itself).
Do this for your 2nd interface...and......
(This is my "after". Notice that now eth 3 and eth 4 currently show Auto (for Link Status)
Now you can come back to Configuration Scope for the parent folder (LIB Firewalls) and finish your configuration for HA with variables or IPs or whatever you need.
Thanks to Rae A (at TAC), who was wonderful and helped me in about 3 minutes. 😛
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!