We have a pair of Panorama devices for managing couple of pairs of Firewalls ( in HA ) all in Azure. We have scheduled the config export which is scheduled everyday to store the config backups of Panorama+Firewalls in a server.
If there were a scenario ( I know its very unlikely on Azure since there are Availabilty Zones configured ) but in the very rare case that both availability zones are down ( which host one firewall each in HA ), then , will the config backups be enough to restore the firewalls. The steps for restoration in this case as follows:
1. We would want the firewalls up and running (post all the backend networking configured in some new region ), for this we would run the ARM templates.
2. To restore the config backups which are stored (and backed up by Azure ) to the newly built firewalls.
However in the above case, we would require Device states of the firewalls and config backups are of no use in this scenario because our policies which are managed by Device Templates can be restored. ( At this point there isnt any newly rebuilt Panoramas in the picture and we would like to build it at the end to get the services up and running first and foremost )
Keeping the scenario in mind, How does one schedule a export of Device states of firewalls because they are very useful in such scenarios. Please let me know any suggestions on this.
... View more