<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: HA pair App and Threat sync to passive question. in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/ha-pair-app-and-threat-sync-to-peer-question/m-p/158872#M52025</link>
    <description>&lt;P&gt;well there's 2 strategies:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;- you can have the active member download, install and sync to peer, this will download and install, then copy the file over to passive and install there too (or you can download and sync, which will download and copy but not install)&lt;/P&gt;
&lt;P&gt;with this setting the secondary device does not really need a schedule ince the primary will perform that task&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="schedule updates and sync.png"&gt;&lt;img src="https://live.paloaltonetworks.com/skins/images/2F2A72B3BE70ACC5EBC3E1D7685F5297/responsive_peak/images/image_not_found.png" alt="schedule updates and sync.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;- or you can have each member do their own schedule and not use the sync option but that could lead to mismatch if one has install and the other has download only&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;There is a revert option available in the dynamic updates themselves which i would recommend to prevent running into the mismatch:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="revert.png"&gt;&lt;img src="https://live.paloaltonetworks.com/skins/images/2F2A72B3BE70ACC5EBC3E1D7685F5297/responsive_peak/images/image_not_found.png" alt="revert.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If your main concern is that a bad content package would be installed and you need a fallback, i would look into using the 'threshold' function first&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This will check for the release date/time of a content package and adds x time (as configured in the threshold) before checking the update server again. if the same file is still available it will go ahead and install, if a newer update is available (emergency content release or content package retracted) the instll will be aborted and the threshold is reset if a new package is available. after the second threshold a last check is done and if the package is still available, the emergency package is installed. if yet another version is see, the install will be abortted altogether and wait until the next scheduled event (watch out for AV updates as these can have several valid releases in a day where content is usually updated once to twice a week)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;on top of the above, there's still the manual revert&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;hope this helps!&lt;/P&gt;</description>
    <pubDate>Thu, 01 Jun 2017 11:11:20 GMT</pubDate>
    <dc:creator>reaper</dc:creator>
    <dc:date>2017-06-01T11:11:20Z</dc:date>
    <item>
      <title>HA pair App and Threat sync to peer question.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ha-pair-app-and-threat-sync-to-peer-question/m-p/158865#M52023</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Apps and threats on the currently active box are set to download and install, on the&amp;nbsp;passive to download only. &amp;nbsp;Active box received and installed new updates. Will that automatically be synced to the&amp;nbsp;passive? If we have a revert scenario where the Passive device has its a&lt;SPAN&gt;pps and threats configuration&amp;nbsp;to download and install, but the Active to download only. What will happen and what is the best practice to configure these setting on the both firewalls?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thx,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Myky&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 02 Jun 2017 14:59:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ha-pair-app-and-threat-sync-to-peer-question/m-p/158865#M52023</guid>
      <dc:creator>TranceforLife</dc:creator>
      <dc:date>2017-06-02T14:59:38Z</dc:date>
    </item>
    <item>
      <title>Re: HA pair App and Threat sync to passive question.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ha-pair-app-and-threat-sync-to-peer-question/m-p/158872#M52025</link>
      <description>&lt;P&gt;well there's 2 strategies:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;- you can have the active member download, install and sync to peer, this will download and install, then copy the file over to passive and install there too (or you can download and sync, which will download and copy but not install)&lt;/P&gt;
&lt;P&gt;with this setting the secondary device does not really need a schedule ince the primary will perform that task&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="schedule updates and sync.png"&gt;&lt;img src="https://live.paloaltonetworks.com/skins/images/2F2A72B3BE70ACC5EBC3E1D7685F5297/responsive_peak/images/image_not_found.png" alt="schedule updates and sync.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;- or you can have each member do their own schedule and not use the sync option but that could lead to mismatch if one has install and the other has download only&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;There is a revert option available in the dynamic updates themselves which i would recommend to prevent running into the mismatch:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="revert.png"&gt;&lt;img src="https://live.paloaltonetworks.com/skins/images/2F2A72B3BE70ACC5EBC3E1D7685F5297/responsive_peak/images/image_not_found.png" alt="revert.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If your main concern is that a bad content package would be installed and you need a fallback, i would look into using the 'threshold' function first&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This will check for the release date/time of a content package and adds x time (as configured in the threshold) before checking the update server again. if the same file is still available it will go ahead and install, if a newer update is available (emergency content release or content package retracted) the instll will be aborted and the threshold is reset if a new package is available. after the second threshold a last check is done and if the package is still available, the emergency package is installed. if yet another version is see, the install will be abortted altogether and wait until the next scheduled event (watch out for AV updates as these can have several valid releases in a day where content is usually updated once to twice a week)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;on top of the above, there's still the manual revert&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;hope this helps!&lt;/P&gt;</description>
      <pubDate>Thu, 01 Jun 2017 11:11:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ha-pair-app-and-threat-sync-to-peer-question/m-p/158872#M52025</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2017-06-01T11:11:20Z</dc:date>
    </item>
    <item>
      <title>Re: HA pair App and Threat sync to passive question.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ha-pair-app-and-threat-sync-to-peer-question/m-p/158873#M52026</link>
      <description>&lt;P&gt;Thank you for taking the time to reply and yes, it does help a lot. I don't have any further&amp;nbsp;questions yet &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 01 Jun 2017 11:43:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ha-pair-app-and-threat-sync-to-peer-question/m-p/158873#M52026</guid>
      <dc:creator>TranceforLife</dc:creator>
      <dc:date>2017-06-01T11:43:53Z</dc:date>
    </item>
  </channel>
</rss>

