- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
Enhanced Security Measures in Place: To ensure a safer experience, we’ve implemented additional, temporary security measures for all users.
04-04-2024 04:18 PM - edited 04-04-2024 04:24 PM
Hi Guys,
We have one of the IPSec tunnel missing on Panorama but it is configured on individual Firewalls (HA pair). The tunnel is up and running. We don't want any downtime on VPN tunnel.
Can I simply add missing IPSec tunnel to Panorama and do just " Commit to Panorama"?
Or is there something else needs to be done?
04-05-2024 09:27 PM
Hello @MINKU2
from your post it looks like you are considering to move IPsec local Firewall configuration to Panorama managed configuration. If this is the case, then there are a few things to consider.
You will have to configure IPsec in Panorama's Template, then commit and push it to Firewall. If the IPsec configuration is identical, the local configuration will have precedence, then you will have to override it locally in Firewall to use Panorama's configuration. This will have to be committed to take an effect. During commit the configuration will be replaced that will likely cause IPsec tunnel reset. If you are concerned about down time, then migration from local to Panorama configuration on one to one bases should be performed during a maintenance window.
There might be some work arounds to make this transition without down time. For example push from Panorama IPsec configuration with unique names to prevent overriding it locally, then if you are using any routing protocol to shift traffic to new tunnel. This will required more information about your setup and more planning.
Kind Regards
Pavel
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!