This is the retired Shane Killen personal blog, an IT technical blog about configs and topics related to the Network and Security Engineer working with Cisco, Brocade, Check Point, and Palo Alto and Sonicwall. I hope this blog serves you well. -- May The Lord bless you and keep you. May He shine His face upon you, and bring you peace.
Tuesday, September 15, 2015
Palo Alto: HA Install
I really like the Palo Alto product and its capabilities. Its a good security choice. In fact, its in my top two of choice firewalls for enterprise environments. Here below, Im putting in two PAs in high availability.
Subscribe to: Post Comments (Atom)
Is Checkpoint your other favorite then? I really like Checkpoint, but it was many years ago when I last used it...back when it ran on Sun Sparc hardware and Solaris Unix.ReplyDelete
I'll tell you that my experiences with check point have been painful in more advanced solutions. But, it's a great product.Delete
Checkpoint has got a really complex licensing model compared to PAN and you have to license a lot compared to Palo Alto Networks Basic/Threat Prevention feature set. My favourite Firewall vendor is definitively Palo Alto Networks.Delete
Do you have any guides on setting up those devices in HA? Also, what type of HA did you use for those palo altos?ReplyDelete
Hi! It´s best practice to install them in active/passive mode. For guidelines enabling HA on PAN OS have a look at:Delete