{"id":2450,"date":"2022-09-21T20:36:48","date_gmt":"2022-09-21T17:36:48","guid":{"rendered":"https:\/\/artem.services\/?p=2416"},"modified":"2022-11-07T12:16:32","modified_gmt":"2022-11-07T09:16:32","slug":"2450","status":"publish","type":"post","link":"https:\/\/artem.services\/?p=2450&lang=en","title":{"rendered":"Palo Alto VM-Series Firewall: AWS HA Multi AZ for GlobalProtect &#8212; Part 2"},"content":{"rendered":"<p><img loading=\"lazy\" class=\"alignnone size-large wp-image-2328\" src=\"https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/palo-alto-logo-1024x186.png\" alt=\"\" width=\"954\" height=\"173\" srcset=\"https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/palo-alto-logo-1024x186.png 1024w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/palo-alto-logo-300x54.png 300w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/palo-alto-logo-768x140.png 768w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/palo-alto-logo-1536x279.png 1536w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/palo-alto-logo-2048x372.png 2048w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/palo-alto-logo-954x173.png 954w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/palo-alto-logo-1354x246.png 1354w\" sizes=\"(max-width: 954px) 100vw, 954px\" \/><\/p>\n<p>&nbsp;<\/p>\n<h2>VM-Series Firewall<\/h2>\n<h4>SSH<\/h4>\n<p>To use WebUI, we need to set an administrator password, for this, need to connect via SSH.<\/p>\n<blockquote><p>After creating instances, it takes 10-15 minutes before the Firewall is initialized and will be available via SSH<\/p><\/blockquote>\n<p>Connect to the first instance, SSH user &#8212; &quot;<strong>admin<\/strong>&quot;<\/p>\n<p>And execute the following commands:<\/p>\n<pre class=\"brush: bash; title: ; notranslate\" title=\"\">\r\nconfigure\r\nset mgt-config users admin password\r\n<\/pre>\n<p>Enter the password 2 times and save the changes:<\/p>\n<pre class=\"brush: bash; title: ; notranslate\" title=\"\">\r\ncommit\r\n<\/pre>\n<p><img loading=\"lazy\" class=\"alignnone size-full wp-image-2398\" src=\"https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-20-at-16.39.50.png\" alt=\"\" width=\"1218\" height=\"930\" srcset=\"https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-20-at-16.39.50.png 1218w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-20-at-16.39.50-300x229.png 300w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-20-at-16.39.50-1024x782.png 1024w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-20-at-16.39.50-768x586.png 768w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-20-at-16.39.50-954x728.png 954w\" sizes=\"(max-width: 1218px) 100vw, 1218px\" \/><\/p>\n<p>Repeat the same on the second instance.<\/p>\n<p><!--more--><\/p>\n<h4>WebUI<\/h4>\n<h4>Basic<\/h4>\n<p>Now you can log in to the WebUI at the following address<\/p>\n<blockquote><p>https:\/\/&lt;MGMT-PUBLIC-IP&gt;<\/p><\/blockquote>\n<ul>\n<li>Login: admin<\/li>\n<li>Password: the one that was set via SSH<\/li>\n<\/ul>\n<p><img loading=\"lazy\" class=\"alignnone size-full wp-image-2400\" src=\"https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-20-at-17.25.17.png\" alt=\"\" width=\"1566\" height=\"1068\" srcset=\"https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-20-at-17.25.17.png 1566w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-20-at-17.25.17-300x205.png 300w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-20-at-17.25.17-1024x698.png 1024w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-20-at-17.25.17-768x524.png 768w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-20-at-17.25.17-1536x1048.png 1536w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-20-at-17.25.17-954x651.png 954w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-20-at-17.25.17-1354x923.png 1354w\" sizes=\"(max-width: 1566px) 100vw, 1566px\" \/><\/p>\n<p>For convenience, let&#8217;s set the <strong>Hostname<\/strong>, for this we go to &quot;<strong>Device<\/strong>&quot; -&gt; &quot;<strong>Setup<\/strong>&quot; -&gt; &quot;<strong>Management<\/strong>&quot; -&gt; &quot;<strong>General settings<\/strong>&quot;<\/p>\n<p><img loading=\"lazy\" class=\"alignnone size-full wp-image-2401\" src=\"https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-20-at-17.33.14.png\" alt=\"\" width=\"950\" height=\"1168\" srcset=\"https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-20-at-17.33.14.png 950w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-20-at-17.33.14-244x300.png 244w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-20-at-17.33.14-833x1024.png 833w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-20-at-17.33.14-768x944.png 768w\" sizes=\"(max-width: 950px) 100vw, 950px\" \/><\/p>\n<p>Save the changes, for this, in the upper right corner, select &quot;<strong>Commit<\/strong>&quot;. After refreshing the browser tab, the name of the tab will change.<\/p>\n<h4>HA: Enable<\/h4>\n<p>Turn on the HA mode, for this we go to &quot;<strong>Device<\/strong>&quot; -&gt; &quot;<strong>Setup<\/strong>&quot; -&gt; &quot;<strong>High Availability<\/strong>&quot; -&gt; &quot;<strong>General<\/strong>&quot; -&gt; &quot;<strong>Setup<\/strong>&quot; and select the &quot;gear&quot;<\/p>\n<p>Enable &quot;<strong>HA<\/strong>&quot; mode, &quot;<strong>Group ID<\/strong>&quot; &#8212; any value from 1 to 63, and &quot;<strong>Peer HA1 IP Address<\/strong>&quot; &#8212; private IP address of the <strong>MGMT<\/strong> interface of the second instance (AZ B)<\/p>\n<p><img loading=\"lazy\" class=\"alignnone size-full wp-image-2402\" src=\"https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-20-at-17.48.24.png\" alt=\"\" width=\"888\" height=\"508\" srcset=\"https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-20-at-17.48.24.png 888w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-20-at-17.48.24-300x172.png 300w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-20-at-17.48.24-768x439.png 768w\" sizes=\"(max-width: 888px) 100vw, 888px\" \/><\/p>\n<p>Now you need to change the &quot;<strong>Device priority<\/strong>&quot; for the active instance, the lower the value, the higher the priority. The default value is &quot;<strong>100<\/strong>&quot;, set the value for instance &quot;<strong>A<\/strong>&quot; to &quot;<strong>50<\/strong>&quot;<\/p>\n<p><img loading=\"lazy\" class=\"alignnone size-full wp-image-2403\" src=\"https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-20-at-18.42.53.png\" alt=\"\" width=\"788\" height=\"352\" srcset=\"https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-20-at-18.42.53.png 788w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-20-at-18.42.53-300x134.png 300w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-20-at-18.42.53-768x343.png 768w\" sizes=\"(max-width: 788px) 100vw, 788px\" \/><\/p>\n<h4>Security zones<\/h4>\n<p>Before configuring the interfaces, let&#8217;s create two zones:<\/p>\n<ul>\n<li>untrust-zone<\/li>\n<li>trust-zone<\/li>\n<\/ul>\n<p>Go to the tab &quot;<strong>Network<\/strong>&quot; -&gt; &quot;<strong>Zones<\/strong>&quot; and add a new zone by clicking &quot;<strong>Add<\/strong>&quot; in the lower left corner. We set the name and specify Type: &quot;<strong>Layer3<\/strong>&quot;, the rest is left by default.<\/p>\n<p><img loading=\"lazy\" class=\"alignnone size-full wp-image-2441\" src=\"https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-21-at-19.46.29.png\" alt=\"\" width=\"1592\" height=\"1156\" srcset=\"https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-21-at-19.46.29.png 1592w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-21-at-19.46.29-300x218.png 300w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-21-at-19.46.29-1024x744.png 1024w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-21-at-19.46.29-768x558.png 768w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-21-at-19.46.29-1536x1115.png 1536w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-21-at-19.46.29-954x693.png 954w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-21-at-19.46.29-1354x983.png 1354w\" sizes=\"(max-width: 1592px) 100vw, 1592px\" \/><\/p>\n<h4>Network interfaces<\/h4>\n<p>Now go to the tab &quot;<strong>Network<\/strong>&quot; -&gt; &quot;<strong>Interfaces<\/strong>&quot; -&gt; &quot;<strong>Ethernet<\/strong>&quot; and select the interface &quot;<strong>ethernet1\/1<\/strong>&quot;, specify that the &quot;<strong>Interface Type<\/strong>&quot; will be &quot;<strong>HA<\/strong>&quot; and click &quot;<strong>OK<\/strong>&quot;<\/p>\n<p><img loading=\"lazy\" class=\"alignnone size-full wp-image-2409\" src=\"https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-20-at-19.51.55.png\" alt=\"\" width=\"1472\" height=\"558\" srcset=\"https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-20-at-19.51.55.png 1472w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-20-at-19.51.55-300x114.png 300w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-20-at-19.51.55-1024x388.png 1024w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-20-at-19.51.55-768x291.png 768w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-20-at-19.51.55-954x362.png 954w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-20-at-19.51.55-1354x513.png 1354w\" sizes=\"(max-width: 1472px) 100vw, 1472px\" \/><\/p>\n<p><span class=\"VIiyi\" lang=\"en\"><span class=\"JLqJ4b ChMk0b\"><span class=\"Q4iAWc\">Interface<\/span><\/span><\/span> &quot;<strong>ethernet1\/2<\/strong>&quot;:<\/p>\n<ul>\n<li>Interface Type: <strong>Layer3<\/strong><\/li>\n<\/ul>\n<p><strong>Config<\/strong>:<\/p>\n<ul>\n<li>Virtual Router: <strong>default<\/strong><\/li>\n<li>Security Zone: <strong>untrust-zone<\/strong><\/li>\n<\/ul>\n<p><img loading=\"lazy\" class=\"alignnone size-full wp-image-2442\" src=\"https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-21-at-19.52.21.png\" alt=\"\" width=\"1476\" height=\"656\" srcset=\"https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-21-at-19.52.21.png 1476w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-21-at-19.52.21-300x133.png 300w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-21-at-19.52.21-1024x455.png 1024w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-21-at-19.52.21-768x341.png 768w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-21-at-19.52.21-954x424.png 954w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-21-at-19.52.21-1354x602.png 1354w\" sizes=\"(max-width: 1476px) 100vw, 1476px\" \/><\/p>\n<p><strong>IPv4<\/strong><\/p>\n<p>Type: <strong>DHCP Client<\/strong><\/p>\n<p><img loading=\"lazy\" class=\"alignnone size-full wp-image-2443\" src=\"https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-21-at-19.56.02.png\" alt=\"\" width=\"1458\" height=\"528\" srcset=\"https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-21-at-19.56.02.png 1458w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-21-at-19.56.02-300x109.png 300w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-21-at-19.56.02-1024x371.png 1024w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-21-at-19.56.02-768x278.png 768w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-21-at-19.56.02-954x345.png 954w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-21-at-19.56.02-1354x490.png 1354w\" sizes=\"(max-width: 1458px) 100vw, 1458px\" \/><\/p>\n<p>Interface &quot;<strong>ethernet1\/3<\/strong>&quot; we repeat the same steps as for &quot;<strong>ethernet1\/2<\/strong>&quot; with the exception of &quot;<strong>Security Zone<\/strong>&quot;, for this interface we specify &quot;<strong>trust-zone<\/strong>&quot;<\/p>\n<p>As a result, 3 interfaces must be configured<\/p>\n<p><img loading=\"lazy\" class=\"alignnone size-full wp-image-2444\" src=\"https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-21-at-20.11.26.png\" alt=\"\" width=\"1610\" height=\"284\" srcset=\"https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-21-at-20.11.26.png 1610w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-21-at-20.11.26-300x53.png 300w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-21-at-20.11.26-1024x181.png 1024w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-21-at-20.11.26-768x135.png 768w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-21-at-20.11.26-1536x271.png 1536w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-21-at-20.11.26-954x168.png 954w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-21-at-20.11.26-1354x239.png 1354w\" sizes=\"(max-width: 1610px) 100vw, 1610px\" \/><\/p>\n<h4>HA: Data link<\/h4>\n<p>We return back to the HA setting, go to &quot;<strong>Device<\/strong>&quot; -&gt; &quot;<strong>Setup<\/strong>&quot; -&gt; &quot;<strong>High Availability<\/strong>&quot; -&gt; &quot;<strong>HA Communications<\/strong>&quot; -&gt; &quot;<strong>Data Links<\/strong>&quot;<\/p>\n<ul>\n<li>Port: ethernet1\/1<\/li>\n<li>IPv4\/IPv6 Address: IP address of the HA interface of the same instance<\/li>\n<li>Netmask: Netmask of our subnet<\/li>\n<li>Gateway: The first IP address in our network, is a required parameter, because instances are on different subnets<\/li>\n<\/ul>\n<p><img loading=\"lazy\" class=\"alignnone size-full wp-image-2410\" src=\"https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-20-at-19.59.33.png\" alt=\"\" width=\"948\" height=\"626\" srcset=\"https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-20-at-19.59.33.png 948w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-20-at-19.59.33-300x198.png 300w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-20-at-19.59.33-768x507.png 768w\" sizes=\"(max-width: 948px) 100vw, 948px\" \/><\/p>\n<p>We also need to make sure we use &quot;<strong>secondary-ip<\/strong>&quot; as the HA mode. To do this, go to the &quot;<strong>Device<\/strong>&quot; tab and find the item &quot;<strong>VM-Series<\/strong>&quot;<\/p>\n<p><img loading=\"lazy\" class=\"alignnone size-full wp-image-2446\" src=\"https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-21-at-20.15.26.png\" alt=\"\" width=\"1024\" height=\"530\" srcset=\"https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-21-at-20.15.26.png 1024w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-21-at-20.15.26-300x155.png 300w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-21-at-20.15.26-768x398.png 768w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-21-at-20.15.26-954x494.png 954w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/p>\n<p>And now we need to save our changes, for this select the &quot;<strong>Commit<\/strong>&quot; button in the upper right corner.<\/p>\n<p>We repeat all the steps on the second instance, except that &quot;<strong>Device priority<\/strong>&quot; is left by default &#8212; &quot;<strong>100<\/strong>&quot;<\/p>\n<h4>HA Widget<\/h4>\n<p>In order to see the HA status in the Web console, you need to add a widget to the main panel, to do this, go to the &quot;<strong>Dashboard<\/strong>&quot; tab and select &quot;<strong>Widgets<\/strong>&quot; -&gt; &quot;<strong>System<\/strong>&quot; -&gt; &quot;<strong>High Availability<\/strong>&quot;<\/p>\n<p><img loading=\"lazy\" class=\"alignnone size-full wp-image-2411\" src=\"https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-20-at-20.19.31.png\" alt=\"\" width=\"1250\" height=\"520\" srcset=\"https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-20-at-20.19.31.png 1250w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-20-at-20.19.31-300x125.png 300w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-20-at-20.19.31-1024x426.png 1024w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-20-at-20.19.31-768x319.png 768w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-20-at-20.19.31-954x397.png 954w\" sizes=\"(max-width: 1250px) 100vw, 1250px\" \/><\/p>\n<p>If you configured everything correctly, you will see the following on the widget<\/p>\n<p><img loading=\"lazy\" class=\"alignnone size-full wp-image-2412\" src=\"https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-20-at-20.19.59.png\" alt=\"\" width=\"912\" height=\"710\" srcset=\"https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-20-at-20.19.59.png 912w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-20-at-20.19.59-300x234.png 300w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-20-at-20.19.59-768x598.png 768w\" sizes=\"(max-width: 912px) 100vw, 912px\" \/><\/p>\n<p>Run configuration synchronization<\/p>\n<p><img loading=\"lazy\" class=\"alignnone size-full wp-image-2413\" src=\"https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-20-at-20.20.20.png\" alt=\"\" width=\"1102\" height=\"290\" srcset=\"https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-20-at-20.20.20.png 1102w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-20-at-20.20.20-300x79.png 300w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-20-at-20.20.20-1024x269.png 1024w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-20-at-20.20.20-768x202.png 768w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-20-at-20.20.20-954x251.png 954w\" sizes=\"(max-width: 1102px) 100vw, 1102px\" \/><\/p>\n<p>And after a couple of minutes, synchronization should be completed<\/p>\n<p><img loading=\"lazy\" class=\"alignnone size-full wp-image-2414\" src=\"https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-20-at-20.25.46.png\" alt=\"\" width=\"910\" height=\"706\" srcset=\"https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-20-at-20.25.46.png 910w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-20-at-20.25.46-300x233.png 300w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-20-at-20.25.46-768x596.png 768w\" sizes=\"(max-width: 910px) 100vw, 910px\" \/><\/p>\n<h4>HA Test<\/h4>\n<p>Now we need to check that the HA mode is working, for this, we do not need to stop the active instance or otherwise simulate an accident from the AWS side. It is enough to go to the &quot;<strong>Device<\/strong>&quot; tab on the active firewall and then &quot;<strong>Setup<\/strong>&quot; -&gt; &quot;<strong>High Availability<\/strong>&quot; -&gt; &quot;<strong>Operational Commands<\/strong>&quot; and click &quot;<strong>Suspend local device for high availability<\/strong>&quot;<img loading=\"lazy\" class=\"alignnone size-full wp-image-2436\" src=\"https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-21-at-18.33.45.png\" alt=\"\" width=\"908\" height=\"148\" srcset=\"https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-21-at-18.33.45.png 908w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-21-at-18.33.45-300x49.png 300w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-21-at-18.33.45-768x125.png 768w\" sizes=\"(max-width: 908px) 100vw, 908px\" \/><\/p>\n<p>Confirm that we want to suspend HA mode<\/p>\n<p><img loading=\"lazy\" class=\"alignnone size-full wp-image-2437\" src=\"https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-21-at-18.34.00.png\" alt=\"\" width=\"1116\" height=\"284\" srcset=\"https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-21-at-18.34.00.png 1116w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-21-at-18.34.00-300x76.png 300w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-21-at-18.34.00-1024x261.png 1024w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-21-at-18.34.00-768x195.png 768w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-21-at-18.34.00-954x243.png 954w\" sizes=\"(max-width: 1116px) 100vw, 1116px\" \/><\/p>\n<p>Then go to the &quot;<strong>Dashboard<\/strong>&quot; panel and check that the HA mod is paused and <strong>Peer<\/strong> is now the active firewall<\/p>\n<p><img loading=\"lazy\" class=\"alignnone size-full wp-image-2438\" src=\"https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-21-at-18.39.11.png\" alt=\"\" width=\"908\" height=\"702\" srcset=\"https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-21-at-18.39.11.png 908w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-21-at-18.39.11-300x232.png 300w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-21-at-18.39.11-768x594.png 768w\" sizes=\"(max-width: 908px) 100vw, 908px\" \/><\/p>\n<p>Also, make sure the firewalls are swapped, check the &quot;<strong>High Availability<\/strong>&quot; widget on the second firewall<\/p>\n<p><img loading=\"lazy\" class=\"alignnone size-full wp-image-2439\" src=\"https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-21-at-18.45.18.png\" alt=\"\" width=\"906\" height=\"696\" srcset=\"https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-21-at-18.45.18.png 906w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-21-at-18.45.18-300x230.png 300w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-21-at-18.45.18-768x590.png 768w\" sizes=\"(max-width: 906px) 100vw, 906px\" \/><\/p>\n<p>And the last thing left to check is that the <strong>EIP<\/strong> for <strong>GlobalProtect<\/strong> has been ported to the new active firewall. As you can see, <strong>EIP<\/strong> is successfully associated with an instance in <strong>AZ B<\/strong><\/p>\n<p><img loading=\"lazy\" class=\"alignnone size-full wp-image-2447\" src=\"https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-21-at-20.23.40.png\" alt=\"\" width=\"1898\" height=\"382\" srcset=\"https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-21-at-20.23.40.png 1898w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-21-at-20.23.40-300x60.png 300w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-21-at-20.23.40-1024x206.png 1024w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-21-at-20.23.40-768x155.png 768w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-21-at-20.23.40-1536x309.png 1536w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-21-at-20.23.40-954x192.png 954w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-21-at-20.23.40-1354x273.png 1354w\" sizes=\"(max-width: 1898px) 100vw, 1898px\" \/><\/p>\n","protected":false},"excerpt":{"rendered":"<p>&nbsp; VM-Series Firewall SSH To use WebUI, we need to set an administrator password, for this, need to connect via SSH. After creating instances, it takes 10-15 minutes before the Firewall is initialized and will be available via SSH Connect to the first instance, SSH user &#8212; &quot;admin&quot; And execute the following commands: Enter the &hellip; <a href=\"https:\/\/artem.services\/?p=2450&#038;lang=en\" class=\"more-link\">\u041f\u0440\u043e\u0434\u043e\u043b\u0436\u0438\u0442\u044c \u0447\u0438\u0442\u0430\u0442\u044c<span class=\"screen-reader-text\"> &quot;Palo Alto VM-Series Firewall: AWS HA Multi AZ for GlobalProtect &#8212; Part 2&quot;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":[],"categories":[599,1335],"tags":[543,1899,1901,1903,1905],"_links":{"self":[{"href":"https:\/\/artem.services\/index.php?rest_route=\/wp\/v2\/posts\/2450"}],"collection":[{"href":"https:\/\/artem.services\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/artem.services\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/artem.services\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/artem.services\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=2450"}],"version-history":[{"count":7,"href":"https:\/\/artem.services\/index.php?rest_route=\/wp\/v2\/posts\/2450\/revisions"}],"predecessor-version":[{"id":2602,"href":"https:\/\/artem.services\/index.php?rest_route=\/wp\/v2\/posts\/2450\/revisions\/2602"}],"wp:attachment":[{"href":"https:\/\/artem.services\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=2450"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/artem.services\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=2450"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/artem.services\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=2450"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}