Cannot Sync Running Config in HA active/passive

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Cannot Sync Running Config in HA active/passive

L4 Transporter

Hi All,

 

I have a PA3020 with 7.0.5-h2 PAN-os version.

I have tried different times to sync manually the running config on passive member without success.

 

I can clearly see from the Active Member's "ha_agent.log" these errors:

=========================

(active)> tail mp-log ha_agent.log
00000001
TLV[2]: type 11 (SYSD_PEER_DOWN); len 4; value:
00000000

2016-08-05 10:03:00.924 +0200 debug: ha_state_cfg_commit_fail(src/ha_state_cfg.c:682): Commit failure on peer device
2016-08-05 10:03:00.924 +0200 Error: ha_state_cfg_dosync_fail(src/ha_state_cfg.c:427): Group 1: Config sync start failed on local mgmt srvr
2016-08-05 10:03:00.924 +0200 debug: ha_sysd_dev_cfgsync_update(src/ha_sysd.c:1345): Set dev cfgsync to Out-of-Sync
2016-08-05 10:03:00.924 +0200 debug: ha_state_cfg_dosync_fail(src/ha_state_cfg.c:438): Group 1: setting reason to failure for config sync when we got a dosync failure
2016-08-05 10:03:00.924 +0200 debug: ha_state_cfg_sync_callback(src/ha_state_cfg.c:920): ha_state_cfg_sync_callback: retries: 4; insync: no
2016-08-05 10:03:00.924 +0200 Warning: ha_event_log(src/ha_event.c:47): HA Group 1: Running configuration not synchronized after retries

=========================

 

I have checked all settings for both cluster member and also App&threats etc.

Everything is matched.

 

I have already reboot the passive member, but unfortunately nothing is changed.

 

What should I do?

Suggestions?

 

Best Regards

Luca

7 REPLIES 7

Cyber Elite
Cyber Elite

Hi Luca

 

have you tried restarting the management process on the active peer:

> debug software restart process management-server 
Tom Piens
PANgurus - Strata specialist; config reviews, policy optimization

Hi Reaper,

 

Can this one cause an impact on a production enviroment?

 

BR

Luca

Hi,

 

Don't think so as it is just a management-server. Just tried in my lab, all good. no interruption 

Hi @TranceforLife,

 

Thanks both @TranceforLife @reaper for your suggestion.

Also last question?

 

Why this happen? Everything works fine until one week ago?

Maybe uptime can cause this issue (process that are up for long time period not working properly??).

 

BR

Luca

Hi Luca

 

it could be the process has become bogged down a little by it's uptime and memory consumption. Impact of restart should be minimal, only side effect that comes to mind that dynamic url lookups (non-cached) may not function for the duration of the process restart (few seconds)

 

 

regards

Tom

Tom Piens
PANgurus - Strata specialist; config reviews, policy optimization

Hi All,

 

Mp restarted but issue still the same.

 

😞

 

BR

Luca

seems for me restarting the MP server fixed the issue

MP

Help the community: Like helpful comments and mark solutions.
  • 5049 Views
  • 7 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!