<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Ha config not in sync in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/ha-config-not-in-sync/m-p/563041#M114047</link>
    <description>&lt;P&gt;We had similar issue.&lt;/P&gt;
&lt;P&gt;The fix is to reboot both firewalls in the HA pair as&amp;nbsp;&lt;SPAN&gt;SYSD_PEER_DOWN.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Reboot will fix this issue right away.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Tried restarting manual sync, mgmt server reboot before reboot of PAN and no luck.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Hope this helps&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Cheers,&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Mayur&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 25 Oct 2023 03:46:09 GMT</pubDate>
    <dc:creator>MayurLaddha4545</dc:creator>
    <dc:date>2023-10-25T03:46:09Z</dc:date>
    <item>
      <title>Ha config not in sync</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ha-config-not-in-sync/m-p/561700#M113791</link>
      <description>&lt;P&gt;Hi Guys.&lt;/P&gt;
&lt;P&gt;I have a Palo 220 in HA A/P managed by the panorama.&lt;/P&gt;
&lt;P&gt;The customer made mgmt IP change and Added a Zone but then ever since the config is out of Sync Between the HA pairs.&lt;/P&gt;
&lt;P&gt;So all the articles are referenced,&amp;nbsp;&lt;SPAN&gt;request high-availability sync-to-remote running-config'&lt;/SPAN&gt; has been performed from both passive and active fw, force committed, pushed the template values from Panorama with all the force values and others selected, nothing works.&lt;/P&gt;
&lt;P&gt;Pano is on&amp;nbsp;&lt;A href="https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-release-notes" target="_blank" rel="noopener nofollow noreferrer"&gt;9.1.16&lt;/A&gt;&amp;nbsp;and the Firewalls are on 9.1.14-h4.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;the only option left is to manual sync from the xml file which the customer is hesitant to do.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;ha-agent logs gives below error from the passive Firewall&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="batang,apple gothic"&gt;&lt;EM&gt;&lt;STRONG&gt;(Peer namespace on peer device missing too long, trying to restart)&lt;/STRONG&gt;&lt;/EM&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="batang,apple gothic"&gt;&lt;EM&gt;&lt;STRONG&gt;LV[3]: type 11 (SYSD_PEER_DOWN); len 4; value:&lt;BR /&gt;&lt;A href="tel:00000001" target="_blank" rel="noopener"&gt;00000001&lt;/A&gt;&lt;/STRONG&gt;&lt;/EM&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Msg Hdr&lt;BR /&gt;-------&lt;BR /&gt;version : 1&lt;BR /&gt;groupID : 1&lt;BR /&gt;type : Hello (2)&lt;BR /&gt;token : 0x1b4e&lt;BR /&gt;flags : 0x1 (req:)&lt;BR /&gt;length : 122&lt;/P&gt;
&lt;P&gt;Hello Msg&lt;BR /&gt;---------&lt;BR /&gt;flags : 0x1 (preempt:)&lt;BR /&gt;state : Active (5)&lt;BR /&gt;priority : 100&lt;BR /&gt;cookie : 17043&lt;BR /&gt;num tlvs : 3&lt;BR /&gt;Printing out 3 tlvs&lt;BR /&gt;TLV[1]: type 62 (CONFIG_MD5_PRE); len 33; value:&lt;BR /&gt;&lt;A href="tel:62656362 63383863" target="_blank" rel="noopener"&gt;62656362 63383863&lt;/A&gt; &lt;A href="tel:64663634 36636336" target="_blank" rel="noopener"&gt;64663634 36636336&lt;/A&gt; &lt;A href="tel:39373337 32356162" target="_blank" rel="noopener"&gt;39373337 32356162&lt;/A&gt;&lt;BR /&gt;&lt;A href="tel:39373436 64333362" target="_blank" rel="noopener"&gt;39373436 64333362&lt;/A&gt; 00&lt;BR /&gt;TLV[2]: type 2 (CONFIG_MD5SUM); len 33; value:&lt;BR /&gt;&lt;A href="tel:35653537 63313638" target="_blank" rel="noopener"&gt;35653537 63313638&lt;/A&gt; &lt;A href="tel:36646165 66623137" target="_blank" rel="noopener"&gt;36646165 66623137&lt;/A&gt; &lt;A href="tel:39323163 38306263" target="_blank" rel="noopener"&gt;39323163 38306263&lt;/A&gt;&lt;BR /&gt;&lt;A href="tel:31663966 33333466" target="_blank" rel="noopener"&gt;31663966 33333466&lt;/A&gt; 00&lt;BR /&gt;TLV[3]: type 11 (SYSD_PEER_DOWN); len 4; value:&lt;BR /&gt;&lt;A href="tel:00000001" target="_blank" rel="noopener"&gt;00000001&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;2023-10-13 13:11:25.309 +1100 Error: ha_peer_hello_callback(src/ha_peer.c:5076): Group 1 (HA1-MAIN): Peer namespace on peer device missing too long, trying to restart&lt;BR /&gt;2023-10-13 13:11:25.309 +1100 debug: ha_sysd_peerip_modify(src/ha_sysd.c:3353): Attempting 1 modify for sw.sysd.peers&lt;BR /&gt;2023-10-13 13:11:25.309 +1100 debug: ha_sysd_peerip_modify(src/ha_sysd.c:3394): Setting up to modify sw.sysd.peers to peer. -&amp;gt; peerip:10…..xxx; sourceip:10.117.21.XXX; port:0x6e64&lt;BR /&gt;2023-10-13 13:11:25.309 +1100 debug: ha_sysd_peerip_modify(src/ha_sysd.c:3418): Setting sysd node to: { 'peer.': { 'peerip': 10…..'port': 28260, 'reset': True, 'sourceip': 10.xxxXXX, }, }&lt;BR /&gt;2023-10-13 13:11:25.309 +1100 debug: sysd_queue_wr_event_add(sysd_queue.c:915): QUEUE: queue write event already added&lt;BR /&gt;2023-10-13 13:11:25.329 +1100 debug: ha_sysd_peerip_modify_callback(src/ha_sysd.c:3322): Successfully modified sw.sysd.peers&lt;BR /&gt;2023-10-13 13:12:45.388 +1100 Error: ha_peer_hello_callback(src/ha_peer.c:5076): Group 1 (HA1-MAIN): Peer namespace on peer device missing too long, trying to restart&lt;BR /&gt;2023-10-13 13:12:45.388 +1100 debug: ha_sysd_peerip_modify(src/ha_sysd.c:3353): Attempting 1 modify for sw.sysd.peers&lt;BR /&gt;2023-10-13 13:12:45.389 +1100 debug: ha_sysd_peerip_modify(src/ha_sysd.c:3394): Setting up to modify sw.sysd.peers to peer. -&amp;gt; peerip:10.xxxxxx; sourceip:10…xxx; port:0x6e64&lt;BR /&gt;2023-10-13 13:12:45.389 +1100 debug: ha_sysd_peerip_modify(src/ha_sysd.c:3418): Setting sysd node to: { 'peer.': { 'peerip': 10….. Xxx, 'port': 28260, 'reset': True, 'sourceip': 10…XXX, }, }&lt;BR /&gt;2023-10-13 13:12:45.389 +1100 debug: sysd_queue_wr_event_add(sysd_queue.c:915): QUEUE: queue write event already added&lt;BR /&gt;2023-10-13 13:12:45.408 +1100 debug: ha_sysd_peerip_modify_callback(src/ha_sysd.c:3322): Successfully modified sw.sysd.peers&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;2023-10-13 13:14:05.466 +1100 Error: ha_peer_hello_callback(src/ha_peer.c:5076): Group 1 (HA1-MAIN): Peer namespace on peer device missing too long, trying to restart&lt;BR /&gt;2023-10-13 13:14:05.466 +1100 debug: ha_sysd_peerip_modify(src/ha_sysd.c:3353): Attempting 1 modify for sw.sysd.peers&lt;BR /&gt;2023-10-13 13:14:05.467 +1100 debug: ha_sysd_peerip_modify(src/ha_sysd.c:3394): Setting up to modify sw.sysd.peers to peer. -&amp;gt; peerip:10.xx; sourceip:10..1.XXX; port:0x6e64&lt;BR /&gt;2023-10-13 13:14:05.467 +1100 debug: ha_sysd_peerip_modify(src/ha_sysd.c:3418): Setting sysd node to: { 'peer.': { 'peerip': 10.117… 'port': 28260, 'reset': True, 'sourceip': 10.117…XXX, }, }&lt;BR /&gt;2023-10-13 13:14:05.467 +1100 debug: sysd_queue_wr_event_add(sysd_queue.c:915): QUEUE: queue write event already added&lt;BR /&gt;2023-10-13 13:14:05.486 +1100 debug: ha_sysd_peerip_modify_callback(src/ha_sysd.c:3322): Successfully modified sw.sysd.peers&lt;BR /&gt;^Z2023-10-13 13:15:25.568 +1100 Error: ha_peer_hello_callback(src/ha_peer.c:5076): Group 1 (HA1-MAIN): Peer namespace on peer device missing too long, trying to restart&lt;BR /&gt;2023-10-13 13:15:25.568 +1100 debug: ha_sysd_peerip_modify(src/ha_sysd.c:3353): Attempting 1 modify for sw.sysd.peers&lt;BR /&gt;2023-10-13 13:15:25.569 +1100 debug: ha_sysd_peerip_modify(src/ha_sysd.c:3394): Setting up to modify sw.sysd.peers to peer. -&amp;gt; peerip:10.117…; sourceip:10.117….XXX; port:0x6e64&lt;BR /&gt;2023-10-13 13:15:25.569 +1100 debug: ha_sysd_peerip_modify(src/ha_sysd.c:3418): Setting sysd node to: { 'peer.': { 'peerip': 10.117.. 'port': 28260, 'reset': True, 'sourceip': 10.117….XX, }, }&lt;BR /&gt;2023-10-13 13:15:25.569 +1100 debug: sysd_queue_wr_event_add(sysd_queue.c:915): QUEUE: queue write event already added&lt;BR /&gt;2023-10-13 13:15:25.589 +1100 debug: ha_sysd_peerip_modify_callback(src/ha_sysd.c:3322): Successfully modified sw.sysd.peers&lt;BR /&gt;^PA-220-02(passive)&amp;gt;&lt;BR /&gt;PA-220-02(passive)&amp;gt;&lt;BR /&gt;PA-220-02(passive)&amp;gt; debug software resstart process management-server&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Many Thanks,&lt;/P&gt;
&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/11943" target="_blank" rel="noopener"&gt;@kiwi&lt;/A&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480" target="_blank" rel="noopener"&gt;@BPry&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 14 Oct 2023 11:16:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ha-config-not-in-sync/m-p/561700#M113791</guid>
      <dc:creator>Pras</dc:creator>
      <dc:date>2023-10-14T11:16:35Z</dc:date>
    </item>
    <item>
      <title>Re: Ha config not in sync</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ha-config-not-in-sync/m-p/561706#M113793</link>
      <description>&lt;P&gt;Firewalls are fully managed from Panorama so zone was added into Panorama template and pushed to firewall?&lt;/P&gt;
&lt;P&gt;Management IP change was done inside active firewall right? Not in the Panorama. Mgmt IP needs to be different on both firewalls (management interface IP is not syncronized with HA sync).&lt;/P&gt;</description>
      <pubDate>Sat, 14 Oct 2023 22:30:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ha-config-not-in-sync/m-p/561706#M113793</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2023-10-14T22:30:00Z</dc:date>
    </item>
    <item>
      <title>Re: Ha config not in sync</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ha-config-not-in-sync/m-p/561723#M113801</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/15603"&gt;@Raido_Rattameister&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Yes thats correct.&amp;nbsp;&lt;BR /&gt;ips are different in both Fws and Yes, zone pushed from Panorama. &amp;nbsp; Also this was working fine before.&amp;nbsp;&lt;BR /&gt;Forgot to mention, with all this happening with HA ,the Panorama actually says its in sync and theres no issue there.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;Note: No zombie processes are running on the firewalls but the sysd msg and "&lt;SPAN&gt;Peer namespace on peer device missing too long, trying to restart" msg seem to be the clue for the issue.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 15 Oct 2023 21:17:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ha-config-not-in-sync/m-p/561723#M113801</guid>
      <dc:creator>Pras</dc:creator>
      <dc:date>2023-10-15T21:17:12Z</dc:date>
    </item>
    <item>
      <title>Re: Ha config not in sync</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ha-config-not-in-sync/m-p/563041#M114047</link>
      <description>&lt;P&gt;We had similar issue.&lt;/P&gt;
&lt;P&gt;The fix is to reboot both firewalls in the HA pair as&amp;nbsp;&lt;SPAN&gt;SYSD_PEER_DOWN.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Reboot will fix this issue right away.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Tried restarting manual sync, mgmt server reboot before reboot of PAN and no luck.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Hope this helps&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Cheers,&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Mayur&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 25 Oct 2023 03:46:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ha-config-not-in-sync/m-p/563041#M114047</guid>
      <dc:creator>MayurLaddha4545</dc:creator>
      <dc:date>2023-10-25T03:46:09Z</dc:date>
    </item>
    <item>
      <title>Re: Ha config not in sync</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ha-config-not-in-sync/m-p/563177#M114075</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/312888"&gt;@MayurLaddha4545&lt;/a&gt;&lt;FONT color="#f3723c"&gt;&lt;U&gt;4545: &lt;/U&gt;&lt;/FONT&gt;Thanks&amp;nbsp;!!!!&amp;nbsp; I forgot to update here but that's exactly what was done to resolve the issue, manually sync'd the config and then restarted the Firewalls, as you said.&lt;/P&gt;</description>
      <pubDate>Wed, 25 Oct 2023 23:29:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ha-config-not-in-sync/m-p/563177#M114075</guid>
      <dc:creator>Pras</dc:creator>
      <dc:date>2023-10-25T23:29:20Z</dc:date>
    </item>
  </channel>
</rss>

