Using Panorama to change controlled firewalls Active/Passive

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

Using Panorama to change controlled firewalls Active/Passive

L1 Bithead

I am upgrading all my controlled firewalls using Panorama. I am able to upload, install, and reboot my passive firewalls. But now I need to switch my active/passive firewalls. Is there a way to do this in Panorama? Before I would manually login (GUI or CLI) to each active firewall and use the suspend function to force fail-over. 

 

If there is a way to do this or something similar in Panorama, please let me know. Thank you.

2 accepted solutions

Accepted Solutions

Cyber Elite
Cyber Elite

Hello @J_Healy

 

thanks for posting.

 

To my knowledge there is no way to trigger Firewall failover directly from Panorama. I think the technical reason for this is Panorama is primarily designed for central configuration and log management and not direct real time operations.

 

In the past when I was doing Firewall upgrades, I had exactly the same question as you. Having Firewall failover capability directly from Panorama was feature I was missing. I eventually limited Panorama triggered upgrades only for stand alone Firewalls. HA pairs, I used to upgrade directly from Firewalls.

 

Kind Regards

Pavel  

Help the community: Like helpful comments and mark solutions.

View solution in original post

Cyber Elite
Cyber Elite

Hi @J_Healy ,

 

Like you I use Panorama to upgrade my NGFWs because it saves me from having to download and install on each one.  I still log in to each one to suspend and make functional because I make sure the standby is in a passive state before I fail over.  In the long run, it would be good for Panorama to do it all with one click.

 

Upgrade HA Pair button:

  1. Upgrade passive.
  2. Wait and verify passive is ready for failover.
  3. Suspend active and upgrade.
  4. Verify all HA checks passed.

You could even have it make the original one active again.

 

It is interesting that you can suspend the NGFW with SCM.

 

Thanks,

 

Tom

Help the community: Like helpful comments and mark solutions.

View solution in original post

4 REPLIES 4

Cyber Elite
Cyber Elite

Hello @J_Healy

 

thanks for posting.

 

To my knowledge there is no way to trigger Firewall failover directly from Panorama. I think the technical reason for this is Panorama is primarily designed for central configuration and log management and not direct real time operations.

 

In the past when I was doing Firewall upgrades, I had exactly the same question as you. Having Firewall failover capability directly from Panorama was feature I was missing. I eventually limited Panorama triggered upgrades only for stand alone Firewalls. HA pairs, I used to upgrade directly from Firewalls.

 

Kind Regards

Pavel  

Help the community: Like helpful comments and mark solutions.

Cyber Elite
Cyber Elite

Hi @J_Healy ,

 

Like you I use Panorama to upgrade my NGFWs because it saves me from having to download and install on each one.  I still log in to each one to suspend and make functional because I make sure the standby is in a passive state before I fail over.  In the long run, it would be good for Panorama to do it all with one click.

 

Upgrade HA Pair button:

  1. Upgrade passive.
  2. Wait and verify passive is ready for failover.
  3. Suspend active and upgrade.
  4. Verify all HA checks passed.

You could even have it make the original one active again.

 

It is interesting that you can suspend the NGFW with SCM.

 

Thanks,

 

Tom

Help the community: Like helpful comments and mark solutions.

Thank you @PavelK. I was afraid you were going to say that. 🙂

Thank you @TomYoung

  • 2 accepted solutions
  • 1487 Views
  • 4 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!