What happens on a HA sync-to-peer?
21722
Created On 09/25/18 19:10 PM - Last Modified 06/07/23 17:25 PM
Resolution
The following is what occurs on a HA sync-to-peer (in PAN-OS 4.0 and 3.1):
- A transform is done on the running/candidate xml locally
- The transformed config is transferred over a socket from mgmtsrvr to ha_agent (start of timeout period)
- ha_agent transfers this config to the peer ha_agent (call it ha_peer)
- ha_peer sends the transformed config to mgmtsrvr (call it ms_peer)
- ms_peer will wait for items ahead of the ha request to be queue and then service the ha request
- ms_peer will run a transform on the received xml config to apply it to its own running/candidate config
- ms_peer will send a response to ha_peer
- ha_peer will send a response to ha_agent on the original side
- ha_agent on the original side will send the response to mgmtsrvr on the original side
- mgmtsrvr receives the response
owner: panagent