Need to replace an HA pair of Panorama managed, currently deployed firewalls (PA-5220s) with a different pair of Panorama managed firewalls (also PA-5220s), with minimum/no downtime; device licensing is different between #1 & #2 pairs, necessitating the swap. Proposed procedure (detailed in attached picture) - Copy Panorama DG/Template for HA pair #1 to replacement DG/Template for HA pair #2 - Push Panorama config to HA pair #2 - Replace current passive firewall (1b) with it's replacement (2d), sync sessions - Swap HA roles (1b is now active) - Replace current passive firewall (1a) with it's replacement (2c) - Swap HA roles - Delete DG/Template #1 Hardware is identical (HA requires this) HA configs are identical: timers, peer IP addresses, etc. Anyone see issues with the proposed procedure? Suggestions for alternative procedure? Thought about using Panorama RMA procedure to just replace #1 firewalls one at a time and using HA to minimize downtime, maybe similar to above, start by serial number swap for passive firewall, HA swap, replace serial number for formerly active device, swap, etc hardware
... View more