- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
06-20-2017 03:19 AM
Hi
So if your managing a clustered set of PA's with panorama.
Do you have "synchronise config set" or unset and let panorama write configs to both ?
Is there any thing wrong with having it set and having both units managed by panorama ?
06-20-2017 03:54 AM
hi @Alex_Samad
during HA config sync only the device local config is synced over to the peer, panorama config is not synchronized and needs to be pushed to both firewalls from panorama.
it's perfectly fine th sync config between HA peers and also have paorama pushed config
here's a list of all the things that are NOT synchronized :Reference: HA Synchronization
06-21-2017 06:21 AM
Hi @Alex_Samad
panorama config is not synced so if you push panorama config to PA1 only, it will not be synced to PA2
on the device, local and panorama config are distinctly separate from eachother and only the local config (local policy, local objects, ... ) will be synched
06-20-2017 03:54 AM
hi @Alex_Samad
during HA config sync only the device local config is synced over to the peer, panorama config is not synchronized and needs to be pushed to both firewalls from panorama.
it's perfectly fine th sync config between HA peers and also have paorama pushed config
here's a list of all the things that are NOT synchronized :Reference: HA Synchronization
06-20-2017 05:04 PM
Hi
Yes I understand I have to push.
But I have both pas attached to panorama - as pa1 pa2. and they sync to each other.
so when I do a push from panorama is pushes the same (the shared bits ) to pa1 and pa2 and then pa1 pushes to pa2 and pa2 pushes to pa1.
Seems like if I am using panorama I shouldn't need to sync configs ...
But I loose out if I make a change locally on pa1 as it will not sync over to pa2 ..
06-21-2017 06:21 AM
Hi @Alex_Samad
panorama config is not synced so if you push panorama config to PA1 only, it will not be synced to PA2
on the device, local and panorama config are distinctly separate from eachother and only the local config (local policy, local objects, ... ) will be synched
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!