Difference in Session Synchronization configuration output in PAN-OS 11.2 Active/Passive HA

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Difference in Session Synchronization configuration output in PAN-OS 11.2 Active/Passive HA

L0 Member

Hello experts,

 

I would like to confirm the HA configuration behavior in PAN-OS 11.2.

We have two firewalls configured in an Active/Passive HA pair. In the GUI, Enable Session Synchronization is enabled on both devices.

However, when checking the configuration from the CLI, the following line is displayed on one device:

 


”set deviceconfig high-availability group state-synchronization enabled yes”

On the other device, the same configuration line is not displayed.

 

In this case, is it correct to understand that enabled yes is the default value, and therefore it may not be exported to the XML / set-format configuration unless it was explicitly configured?

In other words, could this difference simply mean that one device has yes explicitly saved due to a past operation, while the other device is using the default value?

 

If both devices show Session Synchronization as enabled in the GUI and CLI, can this XML / set-format difference be safely ignored?

 

I would like to confirm whether this should be treated as an actual configuration difference, or simply as a display difference caused by explicit vs. implicit default values.

 

If anyone is familiar with the PAN-OS 11.2 behavior or has observed a similar case, I would appreciate your advice.

 

1 REPLY 1

Cyber Elite

Just checked my recently set up HA pair.

11.2.10-h5

 

Both firewalls show following output (so only keep-alive checkbox setting).

 

show | match state-synchronization
set deviceconfig high-availability group state-synchronization ha2-keep-alive enabled yes

Principal Architect @ Cloud Carib Ltd
Palo Alto Networks certified from 2011
  • 127 Views
  • 1 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!