panorama and clustered PA's

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

panorama and clustered PA's

L4 Transporter

Hi

 

So if your managing a clustered set of PA's with panorama.

 

Do you have "synchronise config set" or unset and let panorama write configs to both ?

 

Is there any thing wrong with having it set and having both units managed by panorama ?

 

 

2 accepted solutions

Accepted Solutions

Cyber Elite
Cyber Elite

hi @Alex_Samad

 

during HA config sync only the device local config is synced over to the peer, panorama config is not synchronized and needs to be pushed to both firewalls from panorama.

it's perfectly fine th sync config between HA peers and also have paorama pushed config

 

here's a list of all the things that are NOT synchronized :Reference: HA Synchronization

Tom Piens
PANgurus - Strata specialist; config reviews, policy optimization

View solution in original post

Hi @Alex_Samad

 

panorama config is not synced so if you push panorama config to PA1 only, it will not be synced to PA2

 

on the device, local and panorama config are distinctly separate from eachother and only the local config (local policy, local objects, ... ) will be synched

Tom Piens
PANgurus - Strata specialist; config reviews, policy optimization

View solution in original post

3 REPLIES 3

Cyber Elite
Cyber Elite

hi @Alex_Samad

 

during HA config sync only the device local config is synced over to the peer, panorama config is not synchronized and needs to be pushed to both firewalls from panorama.

it's perfectly fine th sync config between HA peers and also have paorama pushed config

 

here's a list of all the things that are NOT synchronized :Reference: HA Synchronization

Tom Piens
PANgurus - Strata specialist; config reviews, policy optimization

Hi

 

Yes I understand I have to push. 

 

But I have both pas attached to panorama - as pa1 pa2. and they sync to each other.

 

so when I do a push from panorama is pushes the same (the shared bits ) to pa1 and pa2 and then pa1 pushes to pa2 and pa2 pushes to pa1.

 

Seems like if I am using panorama I shouldn't need to sync configs ...

 

 

 

But I loose out if I make a change locally on pa1 as it will not sync over to pa2 .. 

Hi @Alex_Samad

 

panorama config is not synced so if you push panorama config to PA1 only, it will not be synced to PA2

 

on the device, local and panorama config are distinctly separate from eachother and only the local config (local policy, local objects, ... ) will be synched

Tom Piens
PANgurus - Strata specialist; config reviews, policy optimization
  • 2 accepted solutions
  • 2320 Views
  • 3 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!