Panorama-Local Config Merge in HA

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

Panorama-Local Config Merge in HA

L1 Bithead

We have a project to clean up the Panorama environment in order to manage changes from Panorama as much as possible. We have a pair of 3020 in A/P HA, already synced to Panorama with some local overrides. I performed the exact steps recommended by Palo on another HA set and it failed initially but was eventually fixed once we figured that "force template values" and sending to both firewalls will make them exactly the same as each other, HA and all. We did it this way:

  1. Followed KB article: https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g0000008UIPCA2
  2. Performed the steps for both firewalls in tandem, added them to new device group and template, forced template values for the last step, committed/pushed, and ended up with two identical firewalls. We updated HA settings to get them back online and synced.

What would be the recommended approach so we don't end up with the same issue? I'm thinking the following:

  • Turn off HA sync on both firewalls before going through the article steps.
  • Per article, add both devices to Panorama device group and template but bypass steps 8 and 9 for the passive firewall.
  • Finish steps 8 and 9 for the active firewall, export config bundle, then commit/push config to only the active firewall.
  • Log into both firewalls, make sure MGMT and HA settings are different, re-enable sync and allow active to sync or force sync.
1 accepted solution

Accepted Solutions

Cyber Elite
Cyber Elite

Hi @shawnmuas ,

 

Hear is an article on how to migrate an HA pair to Panorama.  https://docs.paloaltonetworks.com/panorama/9-1/panorama-admin/manage-firewalls/transition-a-firewall...  I have used it many times.

 

It is similar to your process, but a little different.

 

  1. Panorama will not overwrite the Mgmt interface settings, even if you check Force Template Values.
  2. I am pretty sure a local sync config will NOT sync the Panorama pushed settings, only the local configuration.  So, you will need to do steps 8 and 9 for each NGFW as mentioned in this document.
  3. With regard to the HA settings, you could (1) click the Remove All button under the template and manage it locally, (2) use template variables, or (3) override locally.

Thanks,

 

Tom

Help the community: Like helpful comments and mark solutions.

View solution in original post

1 REPLY 1

Cyber Elite
Cyber Elite

Hi @shawnmuas ,

 

Hear is an article on how to migrate an HA pair to Panorama.  https://docs.paloaltonetworks.com/panorama/9-1/panorama-admin/manage-firewalls/transition-a-firewall...  I have used it many times.

 

It is similar to your process, but a little different.

 

  1. Panorama will not overwrite the Mgmt interface settings, even if you check Force Template Values.
  2. I am pretty sure a local sync config will NOT sync the Panorama pushed settings, only the local configuration.  So, you will need to do steps 8 and 9 for each NGFW as mentioned in this document.
  3. With regard to the HA settings, you could (1) click the Remove All button under the template and manage it locally, (2) use template variables, or (3) override locally.

Thanks,

 

Tom

Help the community: Like helpful comments and mark solutions.
  • 1 accepted solution
  • 1454 Views
  • 1 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!