176
•
Panorama
6.1
Administrator’s
Guide
©
Palo
Alto
Networks,
Inc.
Panorama
HA
Prerequisites
Panorama
High
Availability
Panorama
HA
Prerequisites
To
configure
Panorama
in
HA,
you
require
a
pair
of
identical
Panorama
servers
with
the
following
requirements
on
each:
The
same
form
factor
—Must
both
be
hardware
‐
based
appliances
(M
‐
100
appliances)
or
virtual
appliances.
For
HA,
the
M
‐
100
appliances
must
be
in
Panorama
mode;
M
‐
100
appliances
in
Log
Collector
mode
do
not
support
HA.
The
same
Panorama
OS
version
—Must
be
running
the
same
version
of
Panorama
in
order
to
synchronize
configuration
information
and
maintain
parity
for
a
seamless
failover.
The
same
set
of
licenses—
Must
purchase
and
install
the
same
device
management
capacity
license
for
each
Panorama.
(Panorama
virtual
appliance
only)
Unique
serial
number
—Must
have
a
unique
serial
number
for
each
Panorama
virtual
appliance;
if
the
serial
number
is
duplicated,
both
instances
of
Panorama
will
be
placed
in
a
suspended
mode
until
you
resolve
the
issue.
The
Panorama
servers
in
the
HA
configuration
are
peers
and
you
can
use
either
(active
‐
primary
or
passive
‐
secondary)
to
centrally
manage
the
devices
with
a
few
exceptions
(see
).
The
HA
peers
use
the
management
port
to
synchronize
the
configuration
elements
pushed
to
the
managed
devices
and
to
maintain
state
information.
Typically,
Panorama
HA
peers
are
geographically
located
in
different
sites,
so
you
need
to
make
sure
that
the
management
port
IP
address
assigned
to
each
peer
is
routable
through
your
network.
HA
connectivity
uses
TCP
port
28
with
encryption
enabled.
If
encryption
is
not
enabled,
ports
28769
and
28260
are
used
for
HA
connectivity
and
to
synchronize
configuration
between
the
HA
peers.
We
recommend
less
than
500ms
latency
between
the
peers.
To
determine
the
latency,
use
Ping
during
a
period
of
normal
traffic.