10-27-2021 07:22 AM
Hi folks,
We have PA 7050 firewall chassis and after upgrade to version 9.1.11, we got a sync HA issue, the TAC told us that it's mandatory to configure the log card interface.
So we created a log interface to resolve the issue, the sync HA issue was resolved but the log traffic is no more sent to the syslog server.
TAC told us that the log traffic is using the log card IP and no more the management IP as before.
We have multiple vsys created on the FW, so my question is, is it possible to create a single log card IP to forward log traffic for all vsys or it's mandatory to create a specific sub-interface per vsys ? (that means we need to create multiple sub-interface under the log card physical interface)
Thanks in advance for your feedback.
Best Regards,
10-27-2021 05:55 PM
Correct, you'll need to create a sub-interface per VSYS enabled on your firewall. You can't use a single logical interface if you're using a multi-vsys system.
10-27-2021 05:55 PM
Correct, you'll need to create a sub-interface per VSYS enabled on your firewall. You can't use a single logical interface if you're using a multi-vsys system.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!