184
•
Panorama
6.1
Administrator’s
Guide
©
Palo
Alto
Networks,
Inc.
Manage
a
Panorama
HA
Pair
Panorama
High
Availability
Manage
a
Panorama
HA
Pair
Set
Up
HA
on
Panorama
Review
the
before
performing
the
following
steps:
Set
Up
HA
on
Panorama
Step
1
Set
up
connectivity
between
the
MGT
ports
on
the
HA
peers.
The
Panorama
peers
communicate
with
each
other
using
the
MGT
port.
Make
sure
that
the
IP
addresses
you
assign
to
the
MGT
port
on
the
Panorama
servers
in
the
HA
pair
are
routable
and
that
the
peers
can
communicate
with
each
other
across
your
network.
To
set
up
the
MGT
port,
see
Pick
a
device
in
the
pair
and
complete
the
remaining
tasks.
Step
2
Enable
HA
and
(optionally)
enable
encryption
for
the
HA
connection.
1.
Select
Panorama > High Availability
and
edit
the
Setup
section.
2.
Select
Enable HA.
3.
In
the
Peer HA IP Address
field,
enter
the
IP
address
assigned
to
the
peer
device.
4.
In
the
Monitor Hold Time
field,
enter
the
length
of
time
(milliseconds)
that
the
system
will
wait
before
acting
on
a
control
link
failure
(range
is
1000
‐
60000,
default
is
3000).
5.
If
you
do
not
want
encryption,
clear
the
Encryption Enabled
check
box
and
click
OK
:
no
more
steps
are
required.
If
you
do
want
encryption,
select
the
Encryption Enabled
check
box,
click
OK
,
and
perform
the
following
tasks:
a.
Select
Panorama > Certificate Management > Certificates
.
b.
Select
Export HA key
.
Save
the
HA
key
to
a
network
location
that
the
peer
device
can
access.
c.
On
the
peer
device,
navigate
to
Panorama > Certificate
Management > Certificates
,
select
Import HA key
,
browse
to
the
location
where
you
saved
the
key,
and
import
it.