panorama HA sync

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

panorama HA sync

L3 Networker

The physical firewalls was relocated and renamed from FWDAN-BYTWAN01/02 to FWSCO-BYTWAN01/02 with new mgmt. ips.Then we removed and added the firewalls back to one of the Panorama (vaemp-pan01) which was active that time. But the other panorama (vaalb-pan01) is still showing old names and discounted. Do we have to manually add the Firewalls again on the second Panorama vaalb-pan01, even its in HA?

 

We do understand reading the following document management settings don't sync when it comes to firewalls itself but is it the same case with panorama templates or device group? 

https://docs.paloaltonetworks.com/pan-os/8-1/pan-os-admin/high-availability/reference-ha-synchroniza...

 

This document does not mention that firewalls management ip and names won;t sync when using panorama.

 

https://docs.paloaltonetworks.com/panorama/7-1/panorama-admin/panorama-high-availability/synchroniza...

1 accepted solution

Accepted Solutions

@Jatin.Singh  no

 

pnorama receives the hostname once the firewall connects to it, so after you changed the hostname, the second panorama will only receive the new hostname when the firewall connects to it and reports its new hostname

Tom Piens
PANgurus - Strata specialist; config reviews, policy optimization

View solution in original post

4 REPLIES 4

Cyber Elite
Cyber Elite

Hi @Jatin.Singh  unfortunately those documents are not related to whay you are seeing

 

the second panorama will only get to see the updated infornation once the firewalls conenct to it and sync their host infornation, so disconnecting the primary would be a quick way to update this infornation

Tom Piens
PANgurus - Strata specialist; config reviews, policy optimization

@reaper Sorry,did you mean disconnect primary panorama from firewalls and update the host information on firewalls manually ? and then connect them back to both panoramas? 

@Jatin.Singh  no

 

pnorama receives the hostname once the firewall connects to it, so after you changed the hostname, the second panorama will only receive the new hostname when the firewall connects to it and reports its new hostname

Tom Piens
PANgurus - Strata specialist; config reviews, policy optimization

Hi Reaper,

 

I import the configurations from managed device to panorama then export to managed devices of our A/P firewalls. everything went well. but when I see the summary on panorama passive device template showing as in sync but active device template disappear. 

 

PFA below for your reference,

 

Sethupathi_0-1604515077233.png

 

Any suggestions? I didn't see any related article in the community.

 

 

  • 1 accepted solution
  • 3885 Views
  • 4 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!