<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: HA syn configuration in Next-Generation Firewall Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/ha-syn-configuration/m-p/523742#M657</link>
    <description>&lt;P&gt;Got it.You mean it will be syn complete when I import the license in passive firewall.whatever the Passive firewall was empty configuration.&lt;/P&gt;
&lt;P&gt;I worried about that because Passive firewall cannot connect to internet,so it cannot download globalprotect version and others,the HA dashboard show globalprotect&amp;nbsp; mismatch will not&amp;nbsp;impact on synchronization?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Zhangsx_1-1670618625482.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/46029iDAF646489BAD1F56/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Zhangsx_1-1670618625482.png" alt="Zhangsx_1-1670618625482.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Just need these matches in the picture.This is my understand.It's right?&lt;/P&gt;</description>
    <pubDate>Fri, 09 Dec 2022 20:44:03 GMT</pubDate>
    <dc:creator>ZhangShengXiang</dc:creator>
    <dc:date>2022-12-09T20:44:03Z</dc:date>
    <item>
      <title>HA syn configuration</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/ha-syn-configuration/m-p/523689#M655</link>
      <description>&lt;P&gt;I have 2 PA-440 configure by HA,now one of FW hardware down,And I get a new FW from RMA.now I connect this new FW.&lt;/P&gt;
&lt;P&gt;When I press "Sync to peer device", it prompts me that synchronization failed. I understand because I have not imported the license to the new firewall. If I import the license into the new firewall, can I directly synchronize the active firewall configuration to passive firewall?&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Zhangsx_0-1670573116908.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/46019iB3F9A112634CF874/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Zhangsx_0-1670573116908.png" alt="Zhangsx_0-1670573116908.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 09 Dec 2022 08:07:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/ha-syn-configuration/m-p/523689#M655</guid>
      <dc:creator>ZhangShengXiang</dc:creator>
      <dc:date>2022-12-09T08:07:20Z</dc:date>
    </item>
    <item>
      <title>Re: HA syn configuration</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/ha-syn-configuration/m-p/523702#M656</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/231285"&gt;@ZhangShengXiang&lt;/a&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;this is correct understanding.&amp;nbsp;If both firewalls do not have an identical set of licenses, they cannot synchronize configuration information. Having the same license is one of the pre-requisite:&amp;nbsp;&lt;A href="https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-admin/high-availability/set-up-activepassive-ha/prerequisites-for-activepassive-ha" target="_blank"&gt;https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-admin/high-availability/set-up-activepassive-ha/prerequisites-for-activepassive-ha&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;After, you have licensed your passive Firewall, also install corresponding PAN-OS, Threat/App version, then you should not have an issue to sync up.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Kind Regards&lt;/P&gt;
&lt;P&gt;Pavel&lt;/P&gt;</description>
      <pubDate>Fri, 09 Dec 2022 13:04:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/ha-syn-configuration/m-p/523702#M656</guid>
      <dc:creator>PavelK</dc:creator>
      <dc:date>2022-12-09T13:04:30Z</dc:date>
    </item>
    <item>
      <title>Re: HA syn configuration</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/ha-syn-configuration/m-p/523742#M657</link>
      <description>&lt;P&gt;Got it.You mean it will be syn complete when I import the license in passive firewall.whatever the Passive firewall was empty configuration.&lt;/P&gt;
&lt;P&gt;I worried about that because Passive firewall cannot connect to internet,so it cannot download globalprotect version and others,the HA dashboard show globalprotect&amp;nbsp; mismatch will not&amp;nbsp;impact on synchronization?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Zhangsx_1-1670618625482.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/46029iDAF646489BAD1F56/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Zhangsx_1-1670618625482.png" alt="Zhangsx_1-1670618625482.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Just need these matches in the picture.This is my understand.It's right?&lt;/P&gt;</description>
      <pubDate>Fri, 09 Dec 2022 20:44:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/ha-syn-configuration/m-p/523742#M657</guid>
      <dc:creator>ZhangShengXiang</dc:creator>
      <dc:date>2022-12-09T20:44:03Z</dc:date>
    </item>
    <item>
      <title>Re: HA syn configuration</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/ha-syn-configuration/m-p/523745#M658</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/231285"&gt;@ZhangShengXiang&lt;/a&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;thank you for reply.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The order of operation to bring Passive Firewall in sync should be as follows.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;- Make sure that Passive Firewall has DNS server / NTP server, Hostname / Domain name, Time Zone,..etc configured. These settings are not HA synchronized (Here is a full list of config that is not synced between Active/Passive Firewall:&amp;nbsp;&lt;A title="What Settings Don’t Sync in Active/Passive HA?" href="https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/high-availability/reference-ha-synchronization/what-settings-dont-sync-in-activepassive-ha" target="_self"&gt;Settings Don’t Sync in Active/Passive HA&lt;/A&gt;&amp;nbsp;) and some of them are required to connect to update portal to download the content (PAN-OS images, App/Threat updates,...)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;- After you complete the above step, either let Firewall fetch license online from portal or&amp;nbsp;import license manually if necessary. After Passive Firewall is properly licensed, you will be able to download content under: Device &amp;gt; Software/Global Protect/Dynamic Updates. After you install versions matching Active Firewall, you should be able to sync configuration from Active Firewall to Passive by clicking on sync to peer from Active Firewall.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;- If you get an error preventing HA sync, I would review error and take troubleshooting from there.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Kind Regards&lt;/P&gt;
&lt;P&gt;Pavel&lt;/P&gt;</description>
      <pubDate>Fri, 09 Dec 2022 21:17:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/ha-syn-configuration/m-p/523745#M658</guid>
      <dc:creator>PavelK</dc:creator>
      <dc:date>2022-12-09T21:17:50Z</dc:date>
    </item>
    <item>
      <title>Re: HA syn configuration</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/ha-syn-configuration/m-p/523777#M659</link>
      <description>&lt;P&gt;Hi PavelK&lt;/P&gt;
&lt;P&gt;I have syn the configuration to passive,but the globalprotect cannot download.should i make this FW to active,and can download version?&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Zhangsx_0-1670821262994.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/46032i7364F84EA176566B/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Zhangsx_0-1670821262994.png" alt="Zhangsx_0-1670821262994.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Zhangsx_1-1670821279098.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/46033i5137C55631443CFA/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Zhangsx_1-1670821279098.png" alt="Zhangsx_1-1670821279098.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 12 Dec 2022 05:01:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/ha-syn-configuration/m-p/523777#M659</guid>
      <dc:creator>ZhangShengXiang</dc:creator>
      <dc:date>2022-12-12T05:01:27Z</dc:date>
    </item>
    <item>
      <title>Re: HA syn configuration</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/ha-syn-configuration/m-p/523810#M665</link>
      <description>&lt;P&gt;Under "Device &amp;gt; Setup &amp;gt; Services &amp;gt; Service Route Configuration" do you use management interface or some dataplane interface to communicate with Palo Alto Networks?&lt;/P&gt;
&lt;P&gt;If management interface then both firewalls can pull updates and GlobalProtect software if dataplane interface then only active firewall can update.&lt;/P&gt;</description>
      <pubDate>Mon, 12 Dec 2022 16:08:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/ha-syn-configuration/m-p/523810#M665</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2022-12-12T16:08:01Z</dc:date>
    </item>
  </channel>
</rss>

