How to do hardware refresh of a hub firewall(HA) in a PAN-OS SDWAN setup connected to a lot of branches

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

How to do hardware refresh of a hub firewall(HA) in a PAN-OS SDWAN setup connected to a lot of branches

L1 Bithead

Anyone got any suggestions how to do this without loosing the branches?

 

I mean, it is pretty easy to migrate to a new platform if you got "normal" ipsec tunnels but when using SDWAN that config are made by Panorama when adding fw's to the SDWAN Cluster in Panorama.

 

So how to replace old firewall cluster with new one without loosing the Panorama SDWAN generated ipsec tunnels that makes all branches to disconnect Panorama and datacenter

3 REPLIES 3

L2 Linker

This sounds like PAN-OS SDWAN rather than Prisma SD-WAN.

You might try posting this in one of the NGFW/PAN-OS discussion groups.

Your right but I didn't put it here. I wrote in general topics and can see that configuration would have been better but I don't know how to move this posting 😞

L2 Linker

Are you able to access:

live.paloaltonetworks.com > Discussions > Configuration Discussions > Next-Generation Firewall Configuration Discussions

or

live.paloaltonetworks.com > Discussions > Configuration Discussions > Panorama Configuration Discussions

 

And just copy your question as a new post there?

  • 1341 Views
  • 3 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!