HA Configuration Sync from PA-A to PA-B?

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

HA Configuration Sync from PA-A to PA-B?

L0 Member

Hello everyone,

Here is the scenario:

  • PA-A has the full configuration and a Device Priority of 50.
  • PA-B has no configuration and a Device Priority of 100.
  • Both firewalls are configured in Active-Passive mode and belong to the same Group ID.

Under High Availability → General → Setup, for the option “Enable Config Sync”, which firewall should have this setting enabled — PA-A or PA-B?

for both to have all the configure? 

1 accepted solution

Accepted Solutions

Community Team Member

Hi @Y.Acosta170952 ,

 

You would enable Config Sync on both firewalls in the HA pair. Once HA is established and config sync is enabled, PA-A with the lower device priority of 50 becomes the source of truth and will sync the running config to your PA-B with the priority of 100. 

 

Regarding your PA-B with no config, I would make sure that PA-B has the same PAN-OS version, content versions, and have the mgmt/data interfaces aligned before syncing.  

 

 

 

 

 

 

LIVEcommunity team member
Stay Secure,
Jay
Don't forget to Like items if a post is helpful to you!

Please help out other users and “Accept as Solution” if a post helps solve your problem !

Read more about how and why to accept solutions.

View solution in original post

3 REPLIES 3

Cyber Elite

Hello @Y.Acosta170952

 

best practice is to enabled the "Enable Config Sync" in both Firewalls in HA pair. Below are references from KBs:

How to Configure High Availability on PAN-OS

High-Availability - Out of Sync Peers - Configuration

 

Kind Regards

Pavel  

Help the community: Like helpful comments and mark solutions.

Community Team Member

Hi @Y.Acosta170952 ,

 

You would enable Config Sync on both firewalls in the HA pair. Once HA is established and config sync is enabled, PA-A with the lower device priority of 50 becomes the source of truth and will sync the running config to your PA-B with the priority of 100. 

 

Regarding your PA-B with no config, I would make sure that PA-B has the same PAN-OS version, content versions, and have the mgmt/data interfaces aligned before syncing.  

 

 

 

 

 

 

LIVEcommunity team member
Stay Secure,
Jay
Don't forget to Like items if a post is helpful to you!

Please help out other users and “Accept as Solution” if a post helps solve your problem !

Read more about how and why to accept solutions.

Cyber Elite

@Y.Acosta170952170952 Both firewalls need to have the config sync available .

 

Regards

MP

Help the community: Like helpful comments and mark solutions.
  • 1 accepted solution
  • 465 Views
  • 3 replies
  • 1 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!