palo alto shifting

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

palo alto shifting

L0 Member

i have 2 firewall  i want to shift to other location please advise me how  

3 REPLIES 3

Cyber Elite

@M.Mohamed143196,

I'm not positive of what you're asking. What do you mean by 'shift' to another location? You'd have to provide a bit more information on what you're actually trying to accomplish here for anyone to be able to offer assistance. 

L0 Member

ok, please note we are going to change our data center location so i have 2 firewalls in HA Mode what is best plan to move hardware with minimum downtime  move passive break ha and then move old active and join HA

 

Cyber Elite

@M.Mohamed143196,

I imagine here that you're not going to do a clean cutover and that equipment is going to be active in both locations? Otherwise you could simply shut down both units and move them with the rest of the equipment.

 

Assuming that this isn't a clean cutover and that you'll have equipment active at both locations, this is a bit more of a complex question that I would generally recommend you have an actual conversation with someone who can actually review your network and configuration. That might mean a local consultant that you trust, it could be professional services, but if you're asking this level of question it's likely worth spending a little bit of money for someone to fully review your plans with all of the relevant background knowledge.

As is, the answer to how you would move everything is highly dependent on the following:

  • Do you advertise your own prefix?
  • If not, is you're ISP going to have service active at both locations concurrently? Is there a need to change your public addressing for any potential external services that you have?
  • Do you have external services that will be running across both locations until everything is moved over?
  • Do you have VPN connections configured to any other entities or sites running on the equipment that you will be moving?

Ultimately the general idea is going to be the same. You can offline your passive device and then break HA on both devices. You'll then treat them completely as standalone devices and make all of the necessary configuration changes on each device to support both environments for as long as the 'old' location stays active. Once you're ready to bring things back together, I would completely reset the 'old' location firewall and rejoin it to the firewall in your 'new' location and treat it more like you're adding HA for the first time to an existing location. 

Keep in mind that there's likely a whole lot of configuration updates you're going to need to make to support both locations being online at the same time and they aren't generally minor updates. Depending on your answers to the question above, it can change the entire process of the migration of services while you make this change. That's why I would recommend spending the money to do this in conjunction with a professional who has done these types of migrations before instead of relying on forum assistance. 

 

  • 936 Views
  • 3 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!