Enhanced Security Measures in Place:   To ensure a safer experience, we’ve implemented additional, temporary security measures for all users.

ACTICE/PASSIVE CONFIG SYNC PROBLEM( Running cofiguration not synchronize)

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

ACTICE/PASSIVE CONFIG SYNC PROBLEM( Running cofiguration not synchronize)

L4 Transporter

Hello All,

 

The firewalls are configured in high availability (A/P) but the running configuration is not synchronized.

run-confi.PNG

 

I have already tried to restarting management server of both firewall as well I tried to sync manually but getting below error:-

 

run-confi.2.png

 

 

After that, I have tried to sync from CLI mode by this command:- request high-availability sync-to-remote running-config

 

is showing failed to synchronize running-config.

 

Can anyone help me?

 

 

 

 

 

 

7 REPLIES 7

Cyber Elite
Cyber Elite

On the Active PA click on syn to peer 

Also before that install all the dynamic updates on both active and passive firewall

MP

Help the community: Like helpful comments and mark solutions.

@MP18  I have tried already but same issue persist.

Try this on PAssive PA

 

 request high-availability sync-to-remote running-config

MP

Help the community: Like helpful comments and mark solutions.

@MP18  I have tried this command to both firewall but same issue was happening.

On active PA any change done?

if you revert back to previous config on active PA does it work?

 

Paste the output of 

less mp-log ha_agent.log

MP

Help the community: Like helpful comments and mark solutions.

Also For successful HA configuration, the below must match between the two firewalls.

 

Version Compatibility:
Software Version: Match
Application Content Compatibility: Match
Anti-Virus Compatibility: Match
Threat Content Compatibility: Match
VPN Client Software Compatibility: Match
Global Protect Client Software Compatibility: Match
MP

Help the community: Like helpful comments and mark solutions.

@ It is necessary to import all certificates from active firewall to passive firewall?

  • 6665 Views
  • 7 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!