Error:
An unexpected error occurred. Please click Reload to try again.
Error:
An unexpected error occurred. Please click Reload to try again.
Which Ports Need to be Opened for PAN-OS in HA to Sync and Comm... - Knowledge Base - Palo Alto Networks

Which Ports Need to be Opened for PAN-OS in HA to Sync and Communicate?

37006
Created On 09/26/18 13:48 PM - Last Modified 04/20/20 23:38 PM


Resolution


Overview

The table below represents PAN-OS running as Panorama on a Palo Alto Networks M-100 or as a firewall on an appliance. These are the protocols and ports that a high availability pair will use, and therefore must be allowed by any filtering device that is in between the pair.


Communicating DevicesPorts Used (5.0 and 5.1)Ports Used (6.0 and 6.1)Description
Panorama to Panorama HATCP/28, ICMPTCP/28, ICMPFor HA connectivity and synchronization if encryption is enabled
TCP/28769, TCP/49160, ICMPTCP/28769, TCP/28260, ICMPFor HA connectivity and synchronization if encryption is NOT enabled.
PAN-OS HA1TCP/28TCP/28For HA connectivity and synchronization if encryption is enabled
TCP/28769 and TCP/49160TCP/28769 and TCP/28260For HA connectivity and synchronization if encryption is NOT enabled
ICMPICMPFor heartbeat
PAN-OS HA1-BackupTCP/28770 and TCP/49160TCP/28770 and TCP/28260For HA connectivity and synchronization if encryption is NOT enabled
ICMPICMPFor heartbeat
Heartbeat Backup through Management PortTCP/28771TCP/28771Heartbeat backup
PAN-OS HA2Ethernet type 0x7261, IP protocol 99, or UDP/29281Ethernet type 0x7261, IP protocol 99, or UDP/29281

HA session synchronization. Encryption is not supported.

If data confidentiality and integrity is required, then a tunnel should be

configured between the HA pair and routing should force the packets to

use the tunnel.

PAN-OS HA3

Not applicableNot applicableA Palo Alto Networks Active-Active HA pair must have the dedicated HA3 ports directly connected.


owner: jjosephs



Actions
  • Print
  • Copy Link

    https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClpBCAS&refURL=http%3A%2F%2Fknowledgebase.paloaltonetworks.com%2FKCSArticleDetail

Choose Language