Enhanced Security Measures in Place:   To ensure a safer experience, we’ve implemented additional, temporary security measures for all users.

updating ntp server from old to new IP Addresses

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

updating ntp server from old to new IP Addresses

L0 Member

Hello Experts,

 

can you please help me with the query below?

 

We have 2 Palo Alto NGFW in high availability and currently it is being managed via panorama. recently my organization has decided to decommission old ntp servers due to some issues. They have setup new NTP servers and provided us with the new IP addresses  which need to be updated on the 2 firewalls. And I'm not sure and confident enough  on the approach. 

Do I have to update the new NTP server IPs via Panorama or via the local device itself. I just wanted to make sure I dont make any mistake and break the high availability.

Does updating from Panorama will be easier or via the local device. I think if I update it from panorama it would be pushed to both the devices in high availability. OR if I push it via local device then how do I sync that config with panorama.

 

Any help or suggestions on this is highly appreciable. These devices are bit critical and needs to be handled very carefully.

2 REPLIES 2

L0 Member

If I make changes via the local device then how do I sync it with panorama. or it recommended to make changes only via panorama and then push it to the devices

Cyber Elite
Cyber Elite

Hello @sambillings459

 

thanks for post!

 

Since your Firewalls are managed by Panorama you should perform this change by Panorama by going to Templates > Device > [Select Template from drop down list] > Setup > Services. Once you change NTP servers to new IP addresses/FQDNs, commit and push to manage Firewalls. Select both Firewalls in HA while pushing it. The change will be performed by Panorama on both Firewalls in HA.

 

I would avoid making this change locally by overriding Panorama pushed configuration. Local configuration will not be synced back with Panorama. Local change also defeats purpose of Panorama.

 

Kind Regards

Pavel

Help the community: Like helpful comments and mark solutions.
  • 1547 Views
  • 2 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!