<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: URL Sync to Peer for Active-Passive Cluster in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/url-sync-to-peer-for-active-passive-cluster/m-p/42361#M31109</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Both appliances are licensed, but the management interfaces for both are on a locked down IT only network.&lt;/P&gt;&lt;P&gt;So the updates are occuring by another active interface, which isn't active on the passive appliance.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As there is no available peer sync, can I do this manually? And if not, what is the overall effect on URL checking performance&lt;/P&gt;&lt;P&gt;when the backup pair comes online and is so out of date on its local database that it has to use Dynamic lookup?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 11 Oct 2011 01:36:50 GMT</pubDate>
    <dc:creator>KatanaNZ</dc:creator>
    <dc:date>2011-10-11T01:36:50Z</dc:date>
    <item>
      <title>URL Sync to Peer for Active-Passive Cluster</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/url-sync-to-peer-for-active-passive-cluster/m-p/42359#M31107</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So title says it all. I have a client with twin 4050's running in an active-passive cluster, that we have recently enabled&lt;/P&gt;&lt;P&gt;URL filtering on.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Annoyingly, there is no sync that we can see between the active and passive for the URL database, from initial activation,&lt;/P&gt;&lt;P&gt;through to the dynamic updates.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have to bounce the pair to bring the passive as active, so it would detect its license, and download the database,&lt;/P&gt;&lt;P&gt;and then revert back to what we want as the primary system.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;However it now appears that the active doesn't have a setting to sync its URL database with the passive to keep it current either.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any idea's on if this is the case, and/or how to get around it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We are not using Panorama for this client, but if we were in the future, would that resolve this issue?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 10 Oct 2011 22:08:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/url-sync-to-peer-for-active-passive-cluster/m-p/42359#M31107</guid>
      <dc:creator>KatanaNZ</dc:creator>
      <dc:date>2011-10-10T22:08:03Z</dc:date>
    </item>
    <item>
      <title>Re: URL Sync to Peer for Active-Passive Cluster</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/url-sync-to-peer-for-active-passive-cluster/m-p/42360#M31108</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;There's no sync-to-peer option for url filtering. I assume that both units licensed individually for url filtering? Does the Passive's mgmt interface not have access to the updates server directly?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 10 Oct 2011 23:53:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/url-sync-to-peer-for-active-passive-cluster/m-p/42360#M31108</guid>
      <dc:creator>gswcowboy</dc:creator>
      <dc:date>2011-10-10T23:53:03Z</dc:date>
    </item>
    <item>
      <title>Re: URL Sync to Peer for Active-Passive Cluster</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/url-sync-to-peer-for-active-passive-cluster/m-p/42361#M31109</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Both appliances are licensed, but the management interfaces for both are on a locked down IT only network.&lt;/P&gt;&lt;P&gt;So the updates are occuring by another active interface, which isn't active on the passive appliance.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As there is no available peer sync, can I do this manually? And if not, what is the overall effect on URL checking performance&lt;/P&gt;&lt;P&gt;when the backup pair comes online and is so out of date on its local database that it has to use Dynamic lookup?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 11 Oct 2011 01:36:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/url-sync-to-peer-for-active-passive-cluster/m-p/42361#M31109</guid>
      <dc:creator>KatanaNZ</dc:creator>
      <dc:date>2011-10-11T01:36:50Z</dc:date>
    </item>
    <item>
      <title>Re: URL Sync to Peer for Active-Passive Cluster</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/url-sync-to-peer-for-active-passive-cluster/m-p/42362#M31110</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;@KatanaNZ:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You cannot do a manual update of the Brightcloud DB.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you cannot change the security policy to allow the management interface of your PA Network devices to request software, AV, URL and app/threat updates, then my suggestion would be that a URL db update would be advisable if you have an HA failover. You can do this easily via the command line:&lt;/P&gt;&lt;P&gt;request url-filtering upgrade brightcloud&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Generally speaking I advise people to allow update traffic outbound from management interface to the Palo Alto Networks and Brightcloud update servers. The risk this represents to the network is typically lower than having to rely upon human intervention to update the device after an HA failover. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Benjamin&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 11 Oct 2011 02:21:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/url-sync-to-peer-for-active-passive-cluster/m-p/42362#M31110</guid>
      <dc:creator>bpappas</dc:creator>
      <dc:date>2011-10-11T02:21:25Z</dc:date>
    </item>
    <item>
      <title>Re: URL Sync to Peer for Active-Passive Cluster</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/url-sync-to-peer-for-active-passive-cluster/m-p/42363#M31111</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The IT Network, used for management of all critical systems, will not have any external access, neither inbound or outbound.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What I really need, is for the pairs to sync all data, not just parts of it.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 11 Oct 2011 02:59:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/url-sync-to-peer-for-active-passive-cluster/m-p/42363#M31111</guid>
      <dc:creator>KatanaNZ</dc:creator>
      <dc:date>2011-10-11T02:59:46Z</dc:date>
    </item>
    <item>
      <title>Re: URL Sync to Peer for Active-Passive Cluster</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/url-sync-to-peer-for-active-passive-cluster/m-p/42364#M31112</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;@KatanaNZ:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;in that case it would seem that you should file a feature request with your sales team. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And maybe a weekly failover and update URL database for the secondary unit would be something to add to your regularly scheduled change/maintenance window? Just an idea to keep things more in-sync than waiting for an outage to cause a failover.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Benjamin&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 11 Oct 2011 03:03:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/url-sync-to-peer-for-active-passive-cluster/m-p/42364#M31112</guid>
      <dc:creator>bpappas</dc:creator>
      <dc:date>2011-10-11T03:03:31Z</dc:date>
    </item>
  </channel>
</rss>

