Firewall has the IPSec tunnel but Panorama don't. How to fix?

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Firewall has the IPSec tunnel but Panorama don't. How to fix?

L0 Member

Hi Guys,

We have one of the IPSec tunnel missing on Panorama but it is configured on individual Firewalls (HA pair). The tunnel is up and running. We don't want any downtime on VPN tunnel.

Can I simply add missing IPSec tunnel to Panorama and do just " Commit to Panorama"?

Or is there something else needs to be done?

 

1 REPLY 1

Cyber Elite
Cyber Elite

Hello @MINKU2

 

from your post it looks like you are considering to move IPsec local Firewall configuration to Panorama managed configuration. If this is the case, then there are a few things to consider.

 

You will have to configure IPsec in Panorama's Template, then commit and push it to Firewall. If the IPsec configuration is identical, the local configuration will have precedence, then you will have to override it locally in Firewall to use Panorama's configuration. This will have to be committed to take an effect. During commit the configuration will be replaced that will likely cause IPsec tunnel reset. If you are concerned about down time, then migration from local to Panorama configuration on one to one bases should be performed during a maintenance window.

 

There might be some work arounds to make this transition without down time. For example push from Panorama IPsec configuration with unique names to prevent overriding it locally, then if you are using any routing protocol to shift traffic to new tunnel. This will required more information about your setup and more planning.

 

Kind Regards

Pavel

Help the community: Like helpful comments and mark solutions.
  • 894 Views
  • 1 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!