: Replace a PA-7500 Series Firewall SFC in a NGFW Cluster
Focus
Focus

Replace a PA-7500 Series Firewall SFC in a NGFW Cluster

Table of Contents

Replace a PA-7500 Series Firewall SFC in a NGFW Cluster

Learn how to remove and replace a PA-7500 SFC in a NGFW clustering configuration.
  1. (If the faulty SFC still works and the node is connected to Panorama)
    1. Suspend the node either by using Panorama or the following CLI command: request cluster node state suspend.
    2. Wait until the node is in the Suspended state. Verify the state using the following CLI command: show cluster local state.
  2. Power off the firewall.
  3. Unlock the SFC and remove it from the chassis.
  4. Install the replacement SFC.
  5. Log in to the serial console of the firewall using a terminal emulation application such as PuTTY, then perform a factory reset of the firewall.
  6. After the factory reset has completed, connect to the MPC through the serial console and re-configure the management IP address. Commit the change and verify that there is a management network connection.
  7. Reconfigure your network settings such as hostname, management IP, and DNS servers.
  8. Connect to the firewall's management IP and retrieve the license for the device. Upgrade the device to the same software version as the former node of the cluster.
  9. Reconfigure your Panorama server and commit the changes. Verify that the node is connected.
    If Panorama shows the node as not connected, reset the connection to Panorama.
  10. After the node has reconnected to Panorama, issue the following command to initiate the cluster update to the node: request cluster-update name [cluster_name]. Once the update is finished, the node reboots.
  11. Use either Panorama or the CLI to push the firewall cluster from Panorama to the cluster on the node.
    • Panorama— Select Commit, then Push to Devices. Select the firewall cluster tab, then Push the cluster configuration.
    • CLI— Enter the following command: commit-all firewall-cluster name [cluster_name].
    Use the following command to monitor the cluster setup progress: show cluster local state.
  12. Verify that all the nodes in the cluster are online by issuing the following command: show cluster nodes.
  13. From Panorama, re-push the template and device-group settings to the cluster. Select Commit, then Push to Devices.