- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
02-13-2025 02:52 AM - edited 02-13-2025 02:53 AM
I'm configuring a pair of PA460 for the first time in SCM and a little lost at how I'm meant to do the HA.
I can only do active/passive but my question is more aimed at how I configure the interfaces for the LAN/zones on the two PAs.
Do I configure the interfaces exactly the same on both boxes e.g. IP identical and then the standby just takes over?
Usually firewall vendors will have some sort of FHRP functionality or virtual IP service, but Palo doesn't seem to support either of these hence why I'm a little lost.
Just to clarify: the actual HA config I'm good with, configured a HA1 and HA2 interface and its working as expected. This is purely about the LAN interfaces dealing with traffic
02-13-2025 10:10 AM - edited 02-13-2025 10:13 AM
Hi @M.Gill298701 ,
Yes, the configuration is exactly the same, and in the event of failover the passive then becomes active.
With active/passive HA, the configuration is exactly the same between both FWs except for a few device configurations listed here. https://docs.paloaltonetworks.com/pan-os/11-0/pan-os-admin/high-availability/reference-ha-synchroniz...
For standalone, you configure one FW and the config is synced. For Panorama, you put the HA pair in the same template (and device group). With SCM, it looks like you put them in the same parent folder and modify that configuration scope. If you configure HA in that scope, you will need to use variables as the HA links must have different IP addresses. https://live.paloaltonetworks.com/t5/next-generation-firewall/ha-configurations-in-strata-cloud-mana...
Thanks,
Tom
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!