<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cannot sync two machines in HA mode in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/cannot-sync-two-machines-in-ha-mode/m-p/170#M132</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Sounds like you should contact your Sales Engineer.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The quickfix would of course be to get a threat license for both boxes (or a regular + HA license if that exists).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Otherwise I would try to factory reset both boxes and then import the backup of the running-config (dont forget to change its name otherwise you end up with two "running-config" :smileysilly:) - downside with this method is that you would lose the current threat db in machine A.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Does anyone know if one can import a threat db without license?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If so then perhaps your Sales Engineer could provide you with a copy of the db used in machine A.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 15 May 2012 10:30:04 GMT</pubDate>
    <dc:creator>mikand</dc:creator>
    <dc:date>2012-05-15T10:30:04Z</dc:date>
    <item>
      <title>Cannot sync two machines in HA mode</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/cannot-sync-two-machines-in-ha-mode/m-p/169#M131</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;BR /&gt;Heres my case: Machine A and B was working in HA mode.Meanwhile their antivirus and threat licenses expired and we didnt renewed them. Both machines has valid and up-to-date URL filtering license.&lt;/P&gt;&lt;P&gt;Machine B went dead after some power problems and no longer worked anymore.&lt;/P&gt;&lt;P&gt;We replaced it with machine C. Registered Machine C on paloalto and installed the URL filtering license on it&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now we want to join again machine C to machine A, in HA mode.&lt;/P&gt;&lt;P&gt;The HA sync starts normally but is always aborted because the versions of the Threat and Antivirus on machine A is not the same on C!&lt;/P&gt;&lt;P&gt;the versions on the C machine are 0 (zero) (thats correct as I said we no longer renewed them and the updating of the software didnt installed them) while A machine has the expired licenses&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I cannot remove or update the expired threat and Virus versions from A, and I cannot install any Threat and Virus license on C machine so I am stucked and caanot do any HA sync!&lt;/P&gt;&lt;P&gt;Please any clue on how do I can solve this situation?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Luis&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 15 May 2012 09:29:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/cannot-sync-two-machines-in-ha-mode/m-p/169#M131</guid>
      <dc:creator>luisneves</dc:creator>
      <dc:date>2012-05-15T09:29:17Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot sync two machines in HA mode</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/cannot-sync-two-machines-in-ha-mode/m-p/170#M132</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Sounds like you should contact your Sales Engineer.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The quickfix would of course be to get a threat license for both boxes (or a regular + HA license if that exists).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Otherwise I would try to factory reset both boxes and then import the backup of the running-config (dont forget to change its name otherwise you end up with two "running-config" :smileysilly:) - downside with this method is that you would lose the current threat db in machine A.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Does anyone know if one can import a threat db without license?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If so then perhaps your Sales Engineer could provide you with a copy of the db used in machine A.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 15 May 2012 10:30:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/cannot-sync-two-machines-in-ha-mode/m-p/170#M132</guid>
      <dc:creator>mikand</dc:creator>
      <dc:date>2012-05-15T10:30:04Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot sync two machines in HA mode</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/cannot-sync-two-machines-in-ha-mode/m-p/171#M133</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Mikand, thanks for replying.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regarding asking for licenses:&lt;/P&gt;&lt;P&gt;Can I generate and use a Trial license for both machines? will this trial license OVERLAY the old expired license on the A machine? If positive, you think the trial license will not generate problems in a HA sync?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards, Luis&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 15 May 2012 10:39:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/cannot-sync-two-machines-in-ha-mode/m-p/171#M133</guid>
      <dc:creator>luisneves</dc:creator>
      <dc:date>2012-05-15T10:39:00Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot sync two machines in HA mode</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/cannot-sync-two-machines-in-ha-mode/m-p/172#M134</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Again, contact your Sales Engineer (and dont forget to reply to this thread once you have regarding which answers your SE gave you).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;According to the admin guide the recommended way regarding HA (specially when you run into problems) is to do factory reset on both boxes and configure them from scratch (again dont forget to take backup of running-config before you reset them).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The tricky part in your case is that no matter which method you use you will end up with downtime.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If downtime is no problem I would try the trial license method to get both boxes to the same PANOS aswell as same URL db and Threat db and then try to connect them using HA again. The question then is what will happen when the trial license expires (unless you load the boxes with proper licenses, mainly thinking of the threat db stuff which you dont seem to want to buy any longer?)...&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 15 May 2012 10:54:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/cannot-sync-two-machines-in-ha-mode/m-p/172#M134</guid>
      <dc:creator>mikand</dc:creator>
      <dc:date>2012-05-15T10:54:59Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot sync two machines in HA mode</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/cannot-sync-two-machines-in-ha-mode/m-p/173#M135</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Mikland, thankyou for all the tips, Ive used the factory reset method and it worked out ok, everything is in HA now&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Luis&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 28 May 2012 10:24:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/cannot-sync-two-machines-in-ha-mode/m-p/173#M135</guid>
      <dc:creator>luisneves</dc:creator>
      <dc:date>2012-05-28T10:24:14Z</dc:date>
    </item>
  </channel>
</rss>

