- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
08-28-2023 09:36 AM
We have a project to clean up the Panorama environment in order to manage changes from Panorama as much as possible. We have a pair of 3020 in A/P HA, already synced to Panorama with some local overrides. I performed the exact steps recommended by Palo on another HA set and it failed initially but was eventually fixed once we figured that "force template values" and sending to both firewalls will make them exactly the same as each other, HA and all. We did it this way:
What would be the recommended approach so we don't end up with the same issue? I'm thinking the following:
08-28-2023 11:26 AM
Hi @shawnmuas ,
Hear is an article on how to migrate an HA pair to Panorama. https://docs.paloaltonetworks.com/panorama/9-1/panorama-admin/manage-firewalls/transition-a-firewall... I have used it many times.
It is similar to your process, but a little different.
Thanks,
Tom
08-28-2023 11:26 AM
Hi @shawnmuas ,
Hear is an article on how to migrate an HA pair to Panorama. https://docs.paloaltonetworks.com/panorama/9-1/panorama-admin/manage-firewalls/transition-a-firewall... I have used it many times.
It is similar to your process, but a little different.
Thanks,
Tom
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!