how firewall HA (A/P) synchronise when they are managed with panorama and with port data not out of band port

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

how firewall HA (A/P) synchronise when they are managed with panorama and with port data not out of band port

L1 Bithead
how firewall HA (A/P) synchronise when they are managed with panorama and with port data not out of band port ??
2 accepted solutions

Accepted Solutions

Cyber Elite
Cyber Elite

Hello @Bouthaina

 

thanks for post.

 

The Panorama pushed configuration is not synchronized in A/P Firewall HA pair. You have to push configuration to both active and passive Firewalls. Below are references:

 

Why Panorama pushed configuration is not synchronized between HA pair of firewalls?

DotW: HA Not Synchronized after Commit from Panorama

 

Kind Regards

Pavel  

Help the community: Like helpful comments and mark solutions.

View solution in original post

Cyber Elite
Cyber Elite

All the configuration pushed by panorama is applied to the firewalls in a cluster individually. This specific configuration is not synchronized and needs to be pushed to both systems at the same time from Panorama to ensure they are in sync.

The devices do still need an HA1 link to synchronize any local configuration you may have, and to build the cluster.

HA2 is used to synchronize sessions as per usual

Tom Piens
PANgurus - Strata specialist; config reviews, policy optimization

View solution in original post

2 REPLIES 2

Cyber Elite
Cyber Elite

Hello @Bouthaina

 

thanks for post.

 

The Panorama pushed configuration is not synchronized in A/P Firewall HA pair. You have to push configuration to both active and passive Firewalls. Below are references:

 

Why Panorama pushed configuration is not synchronized between HA pair of firewalls?

DotW: HA Not Synchronized after Commit from Panorama

 

Kind Regards

Pavel  

Help the community: Like helpful comments and mark solutions.

Cyber Elite
Cyber Elite

All the configuration pushed by panorama is applied to the firewalls in a cluster individually. This specific configuration is not synchronized and needs to be pushed to both systems at the same time from Panorama to ensure they are in sync.

The devices do still need an HA1 link to synchronize any local configuration you may have, and to build the cluster.

HA2 is used to synchronize sessions as per usual

Tom Piens
PANgurus - Strata specialist; config reviews, policy optimization
  • 2 accepted solutions
  • 1070 Views
  • 2 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!