
PA-7000 Series Firewall Installation
STEP 4 |
Install the second DPC in the other chassis in the HA pair in the same slot you installed
the DPC in the first chassis. For example, if you installed the first DPC in slot 3 of the first
chassis, install the second DPC in slot 3 of the second chassis.
After you install the firewall in the rack and power it on as described in
, use the CLI to bring up the DPCs in the HA pair.
Run the following command to power-on both DPCs in the HA pair:
admin@PA-7050>
request chassis power-on slot <slot-number> target
ha-pair
For example, if you installed the DPCs in slot 3 of each chassis, run the following command:
admin@PA-7050>
request chassis power-on slot s3 target ha-pair
This will simultaneously power-on both cards in each chassis.
Enable the DPCs by running the following command:
admin@PA-7050>
request chassis enable slot s3 target ha-pair
It is recommended that you observe the enabled cards for about two minutes to check
for internal path monitoring failures. If there is no failure, proceed to the next step.
Check the status of the card in slot 3 on either chassis by running:
admin@PA-7050>
show chassis status slot s3
If the cards are functioning properly, the status will show an output similar to the following:
Slot...Component........Card Status.....Config Status
3.......PA-7000-DPC ...Up..................Success
STEP 5 |
Ensure that the DPC's session distribution policy is set to
session-load
.
1. Run the following command to check the DPC's current distribution policy:
admin@PA-7050>
show session distribution policy
2. If the
Ownership Distribution Policy
reads as any value other than
session-load
, run the
following command:
admin@PA-7050>
set session distribution-policy session-load
3. Running the
show session distribution policy
command should now read
Ownership Distribution Policy: session-load
.
PA-7000 Series Firewall Hardware Reference
106
©
2023 Palo Alto Networks, Inc.