: Panorama > Firewall Clusters
Focus
Focus

Panorama > Firewall Clusters

Table of Contents

Panorama > Firewall Clusters

Configure and view CN-Series and PA-Series clusters.
  • Panorama
    Firewall Clusters
(Available on CN-Series and PA-7500 Series Firewalls Only)
Create and configure a CN-Series or PA-Series firewall cluster, view the cluster summary, and monitor health information in
Panorama
under
Firewall Clusters
. Only PA-7500 Series firewalls support PA-Series firewall clusters.
You must install a Panorama Clustering plugin version (that is compatible with the PAN-OS version) from
Device
Plugins
to view the cluster details under
Firewall Clusters
.

Create and Edit a Firewall Cluster

Select
Create Cluster
to create a cluster and specify the type; click OK. Then select the cluster to access the Edit Cluster screen, where you select the members and further configure the cluster.
To control which clusters are displayed for editing, in the
Clusters
field, select
CN-Series
,
PA-Series
, or
All Clusters
.
Field
Description
Cluster Name
Enter a cluster name containing zero or more alphanumeric characters, underscores (_), hyphens (-), dots (.), or spaces.
Cluster Type
Select the type of cluster:
CN
(CN-Series cluster) or
PA
(PA-Series cluster, which is an NGFW cluster).
Description
Enter a description of the cluster.
Group ID
Enter a Group ID in the range 1 to 63; default is 1. The Group ID helps differentiate MAC addresses when two HA pairs (or an HA pair and an NGFW cluster) in the same Layer 2 network share MAC addresses.
Members
Select the members of the cluster. The first node that you select as a cluster member becomes Node 1. For a PA-Series cluster, the members must be no more than two PA-7500 Series firewalls. Only PA-7500 Series firewalls appear in the list of potential members of a PA-Series cluster.
General
Device
Device serial number; not configurable.
ID
(
PA-Series Clusters only
) Node ID (1 or 2); not configurable. The node that you select first when selecting cluster members is Node 1. The node with the lowest Node ID is elected as leader of the cluster.
Communications
(
PA-Series Clusters only
) [Reserved for future use.]
System Monitoring
State Upon Capacity Loss
(
PA-Series Clusters only
) Select one of the following:
  • degraded
    —Specifies that the firewall will be in a degraded state if the count of functional network cards or data processing cards goes below the configured Minimum Network Cards or Minimum Data Processing Cards, respectively.
  • failed
    —Specifies that the firewall will be in a failed state if the count of functional network cards or data processing cards goes below the configured Minimum Network Cards or Minimum Data Processing Cards, respectively.
Minimum Network Cards
(
PA-Series Clusters only
) Minimum number of network cards required to be functional; range is 1 to 7, default is 1. If the cluster drops below this minimum, the cluster state transitions to the State Upon Capacity Loss that you configured (degraded or failed).
Minimum Data Processing Cards
(
PA-Series Clusters only
) Minimum number of data processing cards required to be functional; range is 1 to 7, default is 1. If the cluster drops below this minimum, the cluster state transitions to the State Upon Capacity Loss that you configured (degraded or failed).

Summary View

View CN-Series and PA-Series firewall cluster summary.
View the information about the CN-Series or PA-Series clusters captured by the firewall in the last five minutes. Click the refresh button to load the latest details.
Field
Description
Cluster Name
Name of the firewall cluster.
Software Version
PAN-OS version.
Plugins Used on the Cluster
List of plugins used on the cluster.
Template Stack
Name of the template stack associated with the cluster.
Device Group
Name of the device group associated with the cluster.
Cluster State
Displays whether the cluster is impacted or not.
Cluster Type
Type of cluster (CN or PA).
Members Affected
Number of impacted cluster members and their names.
System Log Details
Details of the system events.
Specific Error
List of specific errors in the cluster. Click the link to view more details about the error under
Monitor
Logs
System
where you can view logs.
Pod Name
Name of the pod.
CPU Count
Number of CPUs used.
Config Sync Status
Status can be In Sync or Out of Sync. After you successfully add firewalls to the cluster, commit, and push, the Config Sync Status displays as In Sync.
Last Commit State
(
PA-Series Clusters only
) State of the cluster after the last commit.
Node Sync Status
(
PA-Series Clusters only
)
Node Status
(
PA-Series Clusters only
)

Monitoring

View CN-Series and PA-Series firewall clusters monitoring information.
View the CN-Series or PA-Series firewall cluster health information.
Field
Description
Managed Software Cluster
Select a firewall cluster.
Impacted
List of impacted firewall clusters.
  • CN Clusters
    or
    PA Clusters
    —Number of impacted CN-Series or PA-Series firewall clusters, respectively.
  • Clusters Impacted
    —List of clusters that are impacted.
Click to view detailed information about the clusters in the
Interconnect Status
and
Cluster Utilization
dashboards.
OK
List of firewall clusters that are not impacted.
  • CN-Clusters
    or
    PA Clusters
    —Number of CN-Series or PA-Series firewall clusters that are not impacted, respectively.
  • Clusters Impacted
    —List of clusters that are not impacted.
Click to view detailed information about the clusters in the
Interconnect Status
and
Cluster Utilization
dashboards.
Interconnect Status
View the cluster interconnect details for a selected time frame.
Select
Last 5 Mins
to view the following details.
  • Cluster Name
    —Name of the firewall cluster.
  • Cluster Type
    —Type of cluster (CN or PA).
  • Cluster Creation Time
    —Time of cluster creation.
  • Cluster State
    —Displays whether the cluster is impacted or not.
    • Current Cluster Detail
      —Click the cluster state link to view more details about the impacted cluster.
  • Cluster Interconnect State
    —Displays whether the cluster is impacted or not.
    • Current Cluster Detail
      —Click the interconnect state link to view more details about the impacted cluster.
  • Traffic Interconnect
    —Status of traffic interconnectivity.
  • External Connection
    —Status of external connectivity.
  • Impacted Links
    —Number of impacted links.
  • Management Connectivity
    —Number of management connections.
  • Impacted Cluster Member
    —List of impacted cluster members.
  • Time Stamp Hi-Res Uptime
    —Uptime time stamp.
  • Time Stamp Hi-Res Downtime
    —Downtime time stamp.
Selecting any time frame other than
Last 5 Mins
displays the following information only.
  • Cluster Name
  • Cluster Type
  • Cluster Creation Time
  • Current Cluster State
  • Cluster Interconnect Status
  • Traffic Interconnect
  • External Connection
Cluster Utilization
View the firewall cluster throughput, memory, and data utilization.
  • Cluster Name
    —Name of the firewall cluster.
    • Cluster Details
      —Click the cluster name link to view the throughput, memory, and data utilization details of the selected cluster.
  • Cluster Type
    —Type of cluster (CN or PA).
  • Cluster State
    —Displays the health of the cluster.
  • Cluster Throughput (gbps)
    —Firewall cluster throughput in Gbps.
  • CPS
    —Number of connections per second.
  • Session Count (Sessions)
    —Number of sessions.
  • Average Data Plane (%) Within Health Threshold
    —Average dataplane threshold in percentage.
  • Management Plane CPU (%)
    —Management plane CPU utilization in percentage.
  • Management Plane Mem (%)
    —Management plane memory utilization in percentage.
  • Logging Rate (Log/Sec)
    —Rate at which the logs are being generated on the cluster.
  • DP Auto-Scale Status
    —Dataplane autoscale details.

Recommended For You