- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
11-10-2023 08:52 AM
Hello Experts,
can you please help me with the query below?
We have 2 Palo Alto NGFW in high availability and currently it is being managed via panorama. recently my organization has decided to decommission old ntp servers due to some issues. They have setup new NTP servers and provided us with the new IP addresses which need to be updated on the 2 firewalls. And I'm not sure and confident enough on the approach.
Do I have to update the new NTP server IPs via Panorama or via the local device itself. I just wanted to make sure I dont make any mistake and break the high availability.
Does updating from Panorama will be easier or via the local device. I think if I update it from panorama it would be pushed to both the devices in high availability. OR if I push it via local device then how do I sync that config with panorama.
Any help or suggestions on this is highly appreciable. These devices are bit critical and needs to be handled very carefully.
11-10-2023 10:06 AM
If I make changes via the local device then how do I sync it with panorama. or it recommended to make changes only via panorama and then push it to the devices
11-10-2023 04:27 PM
Hello @sambillings459
thanks for post!
Since your Firewalls are managed by Panorama you should perform this change by Panorama by going to Templates > Device > [Select Template from drop down list] > Setup > Services. Once you change NTP servers to new IP addresses/FQDNs, commit and push to manage Firewalls. Select both Firewalls in HA while pushing it. The change will be performed by Panorama on both Firewalls in HA.
I would avoid making this change locally by overriding Panorama pushed configuration. Local configuration will not be synced back with Panorama. Local change also defeats purpose of Panorama.
Kind Regards
Pavel
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!