HA1-Backup Failing when setting to Management

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

HA1-Backup Failing when setting to Management

L2 Linker

I have a pair of 1410's configured for HA.  Because the firewalls are not in the same room, I need to use the management interface for the HA1 backup.

When I do the commit in Panorama, it commits without error.  However, when I go to push it out, I get:

 

 

  • Details:
  • . Validation Error:
  • . deviceconfig -> high-availability -> interface -> ha1-backup -> port 'management' is not an allowed keyword
  • . deviceconfig -> high-availability -> interface -> ha1-backup -> port 'management' is not a valid reference
  • . deviceconfig -> high-availability -> interface -> ha1-backup -> port is invalid
  • . Commit failed

 

 

1 accepted solution

Accepted Solutions

Cyber Elite
Cyber Elite

Hello @jwill2

 

I found the answer in data sheet: PA-1400 Series Next-Gen Firewall Hardware Reference:

 

PavelK_0-1756420016852.png

Kind Regards

Pavel

Help the community: Like helpful comments and mark solutions.

View solution in original post

5 REPLIES 5

L2 Linker

So I was looking at the actual firewall context to see if I could set it manually, but only ha1-a and ha1-b are options.  Management is not an option.

Is this something specific to the newer firewalls that have physical ha1-a and ha1-b ports?

Is there a way to utilize management for the ha1-backup?

 

Also, is it me or are Palo error messages unhelpful.

Cyber Elite
Cyber Elite

Hello @jwill2

 

thanks for post!

 

In the official KB and documentation: HA1 interfaces on PA-3400 and PA-5400 series cannot be configured on the management port only PA-3400 and PA-5400 series are mentioned as affected platforms. I do not have PA-1400 Firewall at my disposition to confirm it, however it looks like that PA-1400 has this limitation as well.

 

Kind Regards

Pavel

Help the community: Like helpful comments and mark solutions.

Cyber Elite
Cyber Elite

Hello @jwill2

 

I found the answer in data sheet: PA-1400 Series Next-Gen Firewall Hardware Reference:

 

PavelK_0-1756420016852.png

Kind Regards

Pavel

Help the community: Like helpful comments and mark solutions.

Perfect.  Thank you.  Seems kind of stupid that they would get rid of using management as an option.  There is a use case where the firewalls are physically distant with no direct copper.  As is the case with this deployment.

I've got it working by running HA1a through the internal network but wanted a backup path in case that link/path/switch were to go down.

The port mgmt cannot be configured as HA1 backup in Panorama, only as HA1. That's why the push fails.

  • 1 accepted solution
  • 303 Views
  • 5 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!