PaloAlto ​Firewall High Availability | Active | Passive| Concept | Configuration | LAB

แชร์
ฝัง
  • เผยแพร่เมื่อ 11 ก.พ. 2025
  • You can support my work on Patron : / bikashtech
    Hello Friends,
    This video shows how to configure HA(High Availability) Active/passive Failover in Palo Alto firewall and i have covered the concept, configuration and LAB as well. If you like this video give it a thumps up and subscribe my channel for more video. Have any question or suggestion put it on comment
    section.
    I Recommend below System configuration to run EVE-NG lab smoothly (Palo-Alto)
    Please Buy with our Affiliate Link (India and US)
    (India)
    Intel® Core™ i7-9700K Processor amzn.to/2TtGpul
    ASUS ROG Strix Z390-F Gaming Motherboard LGA1151 amzn.to/3jxSSrr
    Corsair Vengeance LPX 32GB (2x16GB) 3200MHz amzn.to/3mmQLIP
    Gigabyte AORUS GeForce RTX 2080 amzn.to/34vtkqx
    ZOTAC Gaming GeForce RTX 2060 amzn.to/3jxBdzY
    LG 27GL83A-B 27 Inch Ultragear QHD IPS amzn.to/31Hke8g
    Corsair RMX Series, RM750x amzn.to/2TokxAq
    (US)
    Intel Core i7-9700K Desktop Processor amzn.to/3dZFT0s
    ASUS ROG Strix Z390-F Gaming Motherboard LGA1151 amzn.to/2J16Lli
    Corsair Vengeance LPX 32GB (2x16GB) 3200MHz amzn.to/2ToAd6T
    Gigabyte AORUS GeForce RTX 2080 amzn.to/3dVrBOw
    ZOTAC Gaming GeForce RTX 2060 amzn.to/3oqOyxP
    LG 27GL83A-B 27 Inch Ultragear QHD IPS amzn.to/37J73Yw
    Corsair RMX Series, RM750x amzn.to/37Mf7rk
    Facebook group URL
    / 197882327937667
    Please find the link below for downloading images of network devices and EVE-ng file
    drive.google.c...
    Please check my earlier Video
    How to Configure URL Filtering and Application control | in Palo Alto | Understanding | concept
    • How to Configure URL ...
    How to Configure SSL Decryption | Palo Alto | Firewall | SSL Inspection| Concept | LAB
    • How to Configure SSL D...
    How to |Virtual-Wire | Palo Alto Networks FireWall | Conguration | Concept
    • How to |Virtual-Wire |...
    Configure Palo Alto firewall | For Selective Log Forwarding | to External Syslog Server
    • Configure Palo Alto fi...
    Palo Alto Firewall Basic Configuration | Zone | Security Policy | NAT | Virtual Router
    • Palo Alto Firewall Bas...
    Palo-Alto Firewall- Initialization- Basic
    • Palo-Alto Firewall- In...
    Palo Alto Firewall Interface Type - Explained
    • Palo Alto Firewall In...
    E-mail ID : bikashshaw261@gmail.com
    #Paloaltofirewall #URLfiltering #bikashtech

ความคิดเห็น • 38

  • @niteshmishra4650
    @niteshmishra4650 หลายเดือนก่อน

    Your teaching ability are so perfect which make's easy to get each and every point & concepts to be clear. Thank you so much.

  • @kanwaljeetsingh4783
    @kanwaljeetsingh4783 ปีที่แล้ว

    Excellent work Bikash ! you explained everything in a. very simple way .

  • @p0p09apk5
    @p0p09apk5 2 ปีที่แล้ว

    Thank you so much sir ......i was struggling to find a way but getting error for HA 1 down ...so followed all your step post restart by HA pa....allll gooood 🙏

  • @mdmasumali2258
    @mdmasumali2258 3 ปีที่แล้ว

    Hi Bikash, I just watched your video. You have done a great job. You have explained PA HA clearly. I subscribed to your channel. Congratulation and good luck with your channel!!!!!!!!!!

  • @anupvishwakarma8162
    @anupvishwakarma8162 2 ปีที่แล้ว

    thanks for explaining my dought has clear for active and passive

  • @nileshpardeshi6279
    @nileshpardeshi6279 ปีที่แล้ว

    Very informative 👏 👌

  • @sajansisodiya8095
    @sajansisodiya8095 3 ปีที่แล้ว

    The Ip you gave for the HA we can give anything the only thing is it should be same on both the sides or we have to do any other config to in order me make this topology work?

  • @vivekprajapati7911
    @vivekprajapati7911 4 ปีที่แล้ว

    Thanks sir you are a great teacher ...Guru ji...thanks a lot...

  • @tharakeshk8594
    @tharakeshk8594 3 ปีที่แล้ว

    Thank you Bikash sir

  • @dan-night-owl
    @dan-night-owl 4 ปีที่แล้ว

    What is your PC default gateway. since the two firewall have different ip address that are connected to inside network

  • @env_d_ak
    @env_d_ak 3 ปีที่แล้ว

    Can we get the steps in text format about firewall movement from copper cable connectivity to fibre cable connectivity into a HA setup

  • @SUNNY-gg1vd
    @SUNNY-gg1vd 4 ปีที่แล้ว

    What configuration have you done on Inside two SW connected to PA in HA..................Does link b/w SW & PA is Layer 3 or Layer 2 (Trunk).....

  • @bishtsunny
    @bishtsunny 3 ปีที่แล้ว

    Great video.
    I still have one simple question though, how the failover works in PA.
    Is it like ASA where primary IP gets assigned to the active firewall or both firewall retain their respective IPs and the active one starts advertising it's own IP address?

  • @rajeshranade5473
    @rajeshranade5473 4 ปีที่แล้ว

    Very Good Video . thanks, for sharing.

  • @karthikr9484
    @karthikr9484 3 ปีที่แล้ว

    Great effort ... thanks you so much ...I need to arrange Same setup for practice...help me how to do

  • @roshanpawar9560
    @roshanpawar9560 2 ปีที่แล้ว

    Doubt : If we change the Management IP will the HA impacted?

  • @venkatnarayanans6145
    @venkatnarayanans6145 2 ปีที่แล้ว

    How we do this in virtual machine

  • @damanv3493
    @damanv3493 4 ปีที่แล้ว

    Great video

  • @nikhilsatpute7551
    @nikhilsatpute7551 4 ปีที่แล้ว

    Good one.. 👍

  • @sajidmasood5403
    @sajidmasood5403 5 ปีที่แล้ว

    Do you have any lecture on configuring Backup links for HA1 and HA2 and also Floating IPS

    • @BikashsTech
      @BikashsTech  5 ปีที่แล้ว

      Thanks for comment. No i don't have it. If i get more like and subscriber i can built one.

  • @priyas3636
    @priyas3636 4 ปีที่แล้ว

    Thank you soo much sir!!!!!!

  • @priyadharshan9443
    @priyadharshan9443 5 ปีที่แล้ว +1

    What will gratitious arp do? When active gets fail?

    • @BikashsTech
      @BikashsTech  5 ปีที่แล้ว

      If Active gets Fail, the Standby will do gratitious arp (update the arp table of switch ) So that switch will start forwarding the traffic to standby (Which became Active after failover). :-)

    • @ijasahmed5514
      @ijasahmed5514 2 ปีที่แล้ว

      Does GARP happen on all the interfaces of the passive device when active fails?

  • @ronniemerritt8785
    @ronniemerritt8785 5 ปีที่แล้ว +1

    In your diagram, what will happen if PaloAlto1 is the active firewall AND Switch2 goes down?

    • @hvcool
      @hvcool 4 ปีที่แล้ว

      Warm-up your resume :)

    • @jopiyu
      @jopiyu 4 ปีที่แล้ว

      @@hvcool what does it mean

  • @manivhannankanags9959
    @manivhannankanags9959 4 ปีที่แล้ว

    Can you share the configs of the switches?

    • @BikashsTech
      @BikashsTech  4 ปีที่แล้ว

      it sample topology. I have not done any configuration in switch.

  • @jitugold
    @jitugold 5 ปีที่แล้ว

    You must mention IP addressing as well on diagram for better understating

    • @BikashsTech
      @BikashsTech  5 ปีที่แล้ว

      Thanks for your feedback. I will mentioned in coming videos.

  • @ranghelsoto6516
    @ranghelsoto6516 4 ปีที่แล้ว +1

    Hi friend. Thanks for sharing knowledge with the community. I would like to ask you three questions, the first is, What version of IOS of PAN do you use for these labs? These same labs can be emulated in GNS3, right? And finally, could you give me the name of the DIGITAL BOARD that you use, to be able to download it? I mean that program that lets you make lines and drawings on the screen. Thanks for your answers. Greetings.

    • @BikashsTech
      @BikashsTech  4 ปีที่แล้ว

      Hi Ranghel,
      Thanks for comment.
      1. I am using PAN 8.0.1
      2. I am not sure, either it can be emulated in gns3 as i am using eve-ng instead.
      3. I am using Epic Pen application to write on screen.
      Please find the below link for setting the eve-ng lab
      th-cam.com/video/2uRWAq-IQ_0/w-d-xo.html