Hello,
we have a PA-3020 Active/Passive HA Cluster.
Because of cost cutting I have to break up our cluster and just use one of the firewalls as standalone. The thing is, the license of the passive firewall will last longer than the one from the active. The goal is to use the passive firewall as standalone and to factory reset the active so it can be used as cold spare ... or you know, as paperweight.
Is this the right procedure to break up the Active/Passive HA Cluster correctly and use the passive as standalone firewall:
- Config Backup from active and passive
- Disable preemptive failover
- Manual failover to the passive firewall so that it becomes the active
- Shut down the formerly active (now passive) firewall
- Disable Config Sync and disable HA
- Commit the configuration
- Strip the HA links between the firewalls and everything else from the formerly active (now passive)
- Factory reset the formerly active (now passive) firewall (via direct connection Notebook <-> Mgmt port firewall)
- Pray there are no problems in the future
Is this correct or is there another/better way to do this?
Best regards,
J. Veentjer
... View more