Which Ports Need to be Opened for PAN-OS in HA to Sync and Communicate?

Which Ports Need to be Opened for PAN-OS in HA to Sync and Communicate?

30892
Created On 09/26/18 13:48 PM - Last Modified 04/20/20 23:38 PM


Resolution


Overview

The table below represents PAN-OS running as Panorama on a Palo Alto Networks M-100 or as a firewall on an appliance. These are the protocols and ports that a high availability pair will use, and therefore must be allowed by any filtering device that is in between the pair.


Communicating DevicesPorts Used (5.0 and 5.1)Ports Used (6.0 and 6.1)Description
Panorama to Panorama HATCP/28, ICMPTCP/28, ICMPFor HA connectivity and synchronization if encryption is enabled
TCP/28769, TCP/49160, ICMPTCP/28769, TCP/28260, ICMPFor HA connectivity and synchronization if encryption is NOT enabled.
PAN-OS HA1TCP/28TCP/28For HA connectivity and synchronization if encryption is enabled
TCP/28769 and TCP/49160TCP/28769 and TCP/28260For HA connectivity and synchronization if encryption is NOT enabled
ICMPICMPFor heartbeat
PAN-OS HA1-BackupTCP/28770 and TCP/49160TCP/28770 and TCP/28260For HA connectivity and synchronization if encryption is NOT enabled
ICMPICMPFor heartbeat
Heartbeat Backup through Management PortTCP/28771TCP/28771Heartbeat backup
PAN-OS HA2Ethernet type 0x7261, IP protocol 99, or UDP/29281Ethernet type 0x7261, IP protocol 99, or UDP/29281

HA session synchronization. Encryption is not supported.

If data confidentiality and integrity is required, then a tunnel should be

configured between the HA pair and routing should force the packets to

use the tunnel.

PAN-OS HA3

Not applicableNot applicableA Palo Alto Networks Active-Active HA pair must have the dedicated HA3 ports directly connected.


owner: jjosephs



Actions
  • Print
  • Copy Link

    https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClpBCAS&lang=en_US&refURL=http%3A%2F%2Fknowledgebase.paloaltonetworks.com%2FKCSArticleDetail

Choose Language