当前位置:网站首页>Migrate PaloAlto ha high availability firewall to panorama
Migrate PaloAlto ha high availability firewall to panorama
2022-07-25 12:57:00 【Brother Xing plays with the clouds】
For multiple PaloAlto Firewalls need unified management for enterprises ,Panorama It's a good choice , utilize Panorama It can achieve the purpose of centralization and unified management . Here is a brief introduction demo How to deal with the existing PaloAlto HA The highly available firewall is migrated to Panorama On .
Introduction to the environment :
- Panorama:192.168.55.5
- PA-PRIMARY:192.168.55.10
- PA-SECONDARY:192.168.55.11
here demo Of HA The pattern is Active/Standby Pattern , As shown in the figure below :
Step1( First step ): It's on two HA Disable configuration synchronization on the firewall of Disable Config Sync
In the main firewall (PA-PRIMARY) Switch to “Device( equipment )” tab , Then select... In the menu bar on the left “High Availability( High availability )”, By default “Enable Config Sync( Enable configuration synchronization )” It's checked . As shown in the figure below :
stay “Setup( Set up )” Interface , Click the gear icon in the upper right corner , Cancel in the pop-up dialog “Enable Config Sync( Enable configuration synchronization )” Ahead √, As shown in the figure below :
next , Commit the changes you just made to save the configuration :
In the second standby firewall (PA-SECONDARY) Do the same thing on the computer :
Step2( The second step ): Specify Panorama Management address of :
In the main firewall (PA-PRIMARY) Switch to “Device( equipment )” tab , Select... From the menu on the left “Setup( Set up )” And then click “Management( management )” tab , Finally, click “Panorama Settings(Panorama Set up )” The gear setting button in the upper right corner :
In the pop-up “Panorama Settings(Panorama Set up )” In the dialog box , Input Panorama Management address of . Here's what's interesting “Disable Panorama Policy and Objects” and “Disable Device and Template” Two option buttons ,disable Indicates that it is enabled , That means acceptance comes from Panorama These settings of :
Submit changes , Save configuration :
Do the same on the standby firewall and submit :
Step3( The third step ): stay Panorama Add two managed firewall devices on
Copy the of two firewalls respectively SN Number , In order to be in Panorama Add :
stay Panorama On the device , Switch to “Panorama” tab , Operate in the following order and paste the firewall just copied above SN Number :
Add a second standby firewall with the same operation :
Submit and save the operation just now :
If the operation is correct , After submitting the changes and saving the configuration, you can see the following status : Pay attention to the bottom “Group HA Peers” Is checked , To display “HA Status”
Step4:( Step four ): From the two HA Import the configuration on the high availability firewall to Panorama
stay Panorama Click the left mouse button on the device according to the following numerical number :
Select the device to import the configuration , And change the name of the device and template as needed : It's worth noting that , Remember to keep other options checked by default .
The same operation imports another firewall configuration : It should be noted here that the template and device name do not need to be consistent with the one imported into the first firewall device , This will be explained below !
After successfully importing the configuration of two firewalls , stay “Template( Templates )” Next , You can see the template related information :
We don't need two templates here (Template) And two device groups (Device Group) So let's delete the second template :
Then go to the first Template( Templates ), Check the second firewall , And then click “Ok” In order to move the second firewall to the same Template( Templates ):
In the same way “Device Group( Equipment group )” Do the same under :
Submit changes , Save configuration :
Step5( Step five ): Export configuration applied to firewall devices
Do it here , We are “Managed Devices( Managed devices )” notice “Share Policy( Sharing strategy )” and “Template( Templates )” It's all in “Out of sync( asynchronous )” state :
Click the left mouse button according to the sequence number of the following pictures :
In the pop-up dialog , We choose to apply the configuration to the second standby firewall (PA-SECONDARY), The purpose of this is to prevent the main firewall in the production environment from being affected :
single click “Ok”
next , In the pop-up dialog box, click “Push & Commit( Push and submit )” In order to push the configuration file to the standby firewall device :
stay “Commit( Submit )” Select “Push to Devices”
Then select the first line in the pop-up dialog ,Localtion Type by “Device Group( Equipment group )” Of “PA-PRIMARY”, And then choose “Edit Selecions( The editor chooses )”:
Finally, the dialog box pops up , Cancel “PA-PRIMARY” Ahead √, Finally, click “Ok” To confirm that only the configuration is pushed to the standby firewall :
Same choice Localtion Type by “Template( Templates )” Firewall device under , Confirm that only “PA-SECONDARY” The second standby firewall device :
If the operation is correct , You will see “Share Policy( Sharing strategy )” and “Template( Templates )” The status of sent changes :
Back to the active firewall PA-PRIMARY, For now “Suspend( Hang up )” operation , In order to switch the standby firewall to the main firewall :
Switch to “Dashboad” tab , To ensure that the main firewall is suspended , Standby shipment has become Active( Activities ) state :
Click the left mouse button according to the numerical number below :
Then click the left mouse button according to the number below , In order to push the configuration to the firewall in the suspended state (PA-PRIMARY)
After the synchronization is successful, you will see the status of the following pictures :
Click the left mouse button in the following numerical order , In order to restore the suspended firewall to the running state :
At this point, you can see that the firewall has been restored to the running state , But in “Standby( Standby state )”:
If you want to recover PA-PRIMARY Firewall to Active( Activities ) You can put PA-SECONDARY Hang up , etc. PA-PRIMARY become Active And then recover PA-SECONDARY You can change roles !
Okay , Let's put HA Two firewalls of successfully joined Panorama, Although the process is cumbersome , But as long as you follow the steps , I believe everyone can learn !
边栏推荐
- 【Rust】引用和借用,字符串切片 (slice) 类型 (&str)——Rust语言基础12
- 我在源头SQLServer里面登记绝对删除的数据,传到MaxComputer,在数据清洗的时候写绝对
- Software testing interview question: Please list the testing methods of several items?
- 2022.07.24 (lc_6125_equal row and column pairs)
- Azure Devops (XIV) use azure's private nuget warehouse
- [300 opencv routines] 239. accurate positioning of Harris corner detection (cornersubpix)
- 【运维、实施精品】月薪10k+的技术岗位面试技巧
- [shutter -- layout] stacked layout (stack and positioned)
- AtCoder Beginner Contest 261E // 按位思考 + dp
- yum和vim须掌握的常用操作
猜你喜欢

More accurate and efficient segmentation of organs-at-risk in radiotherapy with Convolutional Neural

Detailed explanation of flex box

The programmer's father made his own AI breast feeding detector to predict that the baby is hungry and not let the crying affect his wife's sleep

Jenkins configuration pipeline

2022.07.24(LC_6125_相等行列对)
![[ROS advanced chapter] Lecture 9 programming optimization of URDF and use of xacro](/img/a2/9b676d0f1b33cc7d413cee6c52d76d.png)
[ROS advanced chapter] Lecture 9 programming optimization of URDF and use of xacro

485通讯( 详解 )

感动中国人物刘盛兰

【历史上的今天】7 月 25 日:IBM 获得了第一项专利;Verizon 收购雅虎;亚马逊发布 Fire Phone

Make a general cascade dictionary selection control based on jeecg -dictcascadeuniversal
随机推荐
A hard journey
2022 年中回顾 | 大模型技术最新进展 澜舟科技
2022.07.24(LC_6126_设计食物评分系统)
ORAN专题系列-21:主要的玩家(设备商)以及他们各自的态度、擅长领域
485通讯( 详解 )
基于JEECG制作一个通用的级联字典选择控件-DictCascadeUniversal
"Autobiography of Franklin" cultivation
perf 性能调试
【问题解决】org.apache.ibatis.exceptions.PersistenceException: Error building SqlSession.1 字节的 UTF-8 序列的字
全球都热炸了,谷歌服务器已经崩掉了
Synergetic process
业务可视化-让你的流程图'Run'起来(3.分支选择&跨语言分布式运行节点)
Zero basic learning canoe panel (12) -- progress bar
感动中国人物刘盛兰
JS 将伪数组转换成数组
JS sorts according to the attributes of the elements in the array
Intval MD5 bypass [wustctf2020] plain
AtCoder Beginner Contest 261 F // 树状数组
[机器学习] 实验笔记 – 表情识别(emotion recognition)
[advanced C language] dynamic memory management