<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Dynamic Updates only on Active HA Member. in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/dynamic-updates-only-on-active-ha-member/m-p/213930#M62195</link>
    <description>&lt;P&gt;Our active HA member failed last week, and that highlighted that the passive had a couple of minor issues with the Dynamic update configurationa and email configuration which we fixed.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Howevr it's also highlighted another issue.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Our "Content Updates" are set to update directly out of the firewall external interfaces, yet on the now "Passive" unit these are shut down, so the unit can't update and sends out alerts.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The New "active" unit is updating and Syncing the&amp;nbsp;updates across.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is there a way ( other than manual disabling Dynamic Updates Manual)&amp;nbsp; to specify that only the "Active" unit checkes and updates content????&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Cheers&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Rob&lt;/P&gt;</description>
    <pubDate>Thu, 10 May 2018 15:37:51 GMT</pubDate>
    <dc:creator>RobinClayton</dc:creator>
    <dc:date>2018-05-10T15:37:51Z</dc:date>
    <item>
      <title>Dynamic Updates only on Active HA Member.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dynamic-updates-only-on-active-ha-member/m-p/213930#M62195</link>
      <description>&lt;P&gt;Our active HA member failed last week, and that highlighted that the passive had a couple of minor issues with the Dynamic update configurationa and email configuration which we fixed.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Howevr it's also highlighted another issue.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Our "Content Updates" are set to update directly out of the firewall external interfaces, yet on the now "Passive" unit these are shut down, so the unit can't update and sends out alerts.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The New "active" unit is updating and Syncing the&amp;nbsp;updates across.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is there a way ( other than manual disabling Dynamic Updates Manual)&amp;nbsp; to specify that only the "Active" unit checkes and updates content????&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Cheers&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Rob&lt;/P&gt;</description>
      <pubDate>Thu, 10 May 2018 15:37:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dynamic-updates-only-on-active-ha-member/m-p/213930#M62195</guid>
      <dc:creator>RobinClayton</dc:creator>
      <dc:date>2018-05-10T15:37:51Z</dc:date>
    </item>
    <item>
      <title>Re: Dynamic Updates only on Active HA Member.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dynamic-updates-only-on-active-ha-member/m-p/213941#M62197</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Not really. What I have done with good success is to have both perform updates with the options to sync to peer. They are set at different time intervals so they dont step on each other. Also I use the management interface as the source so it can always go out.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 10 May 2018 16:32:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dynamic-updates-only-on-active-ha-member/m-p/213941#M62197</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2018-05-10T16:32:53Z</dc:date>
    </item>
    <item>
      <title>Re: Dynamic Updates only on Active HA Member.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dynamic-updates-only-on-active-ha-member/m-p/213948#M62202</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/71756"&gt;@RobinClayton&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;As&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/27580"&gt;@OtakarKlier&lt;/a&gt;&amp;nbsp;mentioned the fix to this would really be setting the service route for dynamic updates to use the management interface if you are able to do so. If for some reason you can't use the management interface for some reason, the current best practice is to utilize the "Sync-to-peer" option with 30 minutes gap between update schedules on both units. This is to prevent the firewalls 'syncing' to the peer firewall at the same time, causing both syncs to fail.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 10 May 2018 17:46:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dynamic-updates-only-on-active-ha-member/m-p/213948#M62202</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2018-05-10T17:46:38Z</dc:date>
    </item>
    <item>
      <title>Re: Dynamic Updates only on Active HA Member.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dynamic-updates-only-on-active-ha-member/m-p/214011#M62216</link>
      <description>&lt;P&gt;I do have them both set Sync-To-Peer , at different intervals. But The alert is still generated on the passive device.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I could use the management interface but then I need to add a new rules to the firewall to allow it to get to the content. I guess App-id "paloalto-updates" should be all I need.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Cheers&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Rob&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 11 May 2018 08:08:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dynamic-updates-only-on-active-ha-member/m-p/214011#M62216</guid>
      <dc:creator>RobinClayton</dc:creator>
      <dc:date>2018-05-11T08:08:05Z</dc:date>
    </item>
    <item>
      <title>Re: Dynamic Updates only on Active HA Member.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dynamic-updates-only-on-active-ha-member/m-p/214020#M62218</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/71756"&gt;@RobinClayton&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Ya if you could use the management interface I would personally just recommend doing that. The applications that should be identified are [ paloalto-wildfire-cloud paloalto-updates pan-db-cloud ] and possibly ssl&lt;/P&gt;</description>
      <pubDate>Fri, 11 May 2018 12:52:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dynamic-updates-only-on-active-ha-member/m-p/214020#M62218</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2018-05-11T12:52:42Z</dc:date>
    </item>
  </channel>
</rss>

