This website uses cookies essential to its operation, for analytics, and for personalized content. By continuing to browse this site, you acknowledge the use of cookies. For details on cookie usage on our site, read our Privacy Policy
Hi, I have setup 2 VM series FW in Azure in HA, however in the HA section there's no Operational Commands tab to go in and issue a suspend so it can failover to the secondary FW. I know in CLI you can put in a command to do this, but I'm interested to see if there is a fix for this. I'm running PAN-OS 10.0.6. Thanks
... View more
Hi all, I've setup 2 VM series in a sandwich topology and want to know the following in terms of the setup: How to configure the 2 virtual routers being trust and untrust for the static routes that point to the ELB? How to configure the NAT for outbound traffic? What are the advantages of having a ILB, if there's no applications that require LB, then is there any advantage? Is it still best practise to setup HA with the 2 VMs while having the ELB do the failover? I have read that the VM HA failover can take 3-10 mins because of the time it takes for the floating IP to move across. For the 2 VM series I have them on 10.0.6 and I have also read that any versions higher HA has issues. The main requirement is to have the secondary VM to take over when the primary is doing a firmware upgrade or any other maintenance tasks. Thanks in advance.
... View more
Hi Dashnet, Do you have to change the static routes in the trust and untrust VR to point to the LB? Can you please share a screenshot of your PA NAT and security rules? The ELB only has a public IP which points and checks the untrust interface of the PA. I don't believe the ELB requires an internal IP which the PA NATs to.
... View more