Professional Documents
Culture Documents
Live Community - Information Synchronized in An HA Pair - Live Community
Live Community - Information Synchronized in An HA Pair - Live Community
(/)
Register (https://live.paloaltonetworks.com/t5/custom/page/page-id/Register?referer=https%3A%2F%2Flive.paloaltonetworks.com%2Ft5%2FLearning-
Articles%2FInformation-Synchronized-in-an-HA-Pair%2Fta-p%2F57292)
Sign In (https://live.paloaltonetworks.com/twzvq79624/plugins/common/feature/saml/doauth/post?referer=https%3A%2F%2Flive.paloaltonetworks.com%2Ft5%2FLearning-
Articles%2FInformation-Synchronized-in-an-HA-Pair%2Fta-p%2F57292)
FAQs (/t5/help/faqpage)
Tools
(https://live.paloaltonetworks.com/t5/Tools/ct-p/Tools)
(https://ignite.paloaltonetworks.c
Overview
This document explains the information synchronized between High Availability (HA) pair members and applies to Active-Passive and
Active-Active deployments.
Details
Control Plane Synchronization Over HA1 link
Con guration: Con guration changes to either active or passive unit are synchronized to peer device
Tabs Synchronized: Policy, Objects and Network
All certi cates sync except Web Certi cate
(/t5/custom/page/page-id/Regist
Dataplane Synchronization over HA2 Link
Session states
IPSec SAs Labels
MAC Tables
Neighbor Discovery Table App-ID
(https://live.paloaltonetworks.com/t
IPv(4/6) return MAC
Authentication
HA2 Monitor Message (https://live.paloaltonetworks.com/t
ARP tables
Certi cates
(https://live.paloaltonetworks.com/t
Verify what gets synchronized over HA2 link using the command below:
> show highavailability statesynchronization Cloud
(https://live.paloaltonetworks.com/t
Objects Not Synchronized
Con guration
Under Network, interface-speci c parameters (such as, link speed and link duplex) are not synchronized (https://live.paloaltonetworks.com/t
Application Command Center (ACC) and log data is not synchronized
Decryption
Web Certi cates (https://live.paloaltonetworks.com/t
Log Link con guration is not synchronized between HA. (See: How Does the Log Link Feature Work? (/docs/DOC-1350))
Endpoint
(https://live.paloaltonetworks.com/t
Note: Device > Objects under the Device Tab are synchronized selectively. Refer to High Availability Synchronization (/docs/DOC-
5086) for the complete list of objects that are synchronized. GlobalProtect
(https://live.paloaltonetworks.com/t
CLI commands to perform a commit sync manually
Hardware
Synchronize Running Con guration (https://live.paloaltonetworks.com/t
>request highavailability synctoremote runningconfig
High Availability
Force the system to synchronize objects that are not saved as part of the system con guration, for example custom block and (https://live.paloaltonetworks.com/t
logon pages. This process operates over the HA control link Integration
>request highavailability synctoremote diskstate (https://live.paloaltonetworks.com/t
Learning
(https://live.paloaltonetworks.com/t
https://live.paloaltonetworks.com/t5/Learning-Articles/Information-Synchronized-in-an-HA-Pair/ta-p/57292 1/3
13/06/2018 Live Community - Information Synchronized in an HA Pair - Live Community
Manually sync the runtime session state. This is normally automatically done, but if needed this command can be executed to
Logs
force the synchronization of the session table (https://live.paloaltonetworks.com/t
>request highavailability synctoremote runtimestate Management
(https://live.paloaltonetworks.com/t
See Also NAT
High Availability Synchronization (/docs/DOC-5086). (https://live.paloaltonetworks.com/t
owner: akawimandan Network
(https://live.paloaltonetworks.com/t
Next
Pair/ta-p/57292/page/2/show-c
Comments
Important information on
VPNFilter Attacks
(/t5/Threat-Vulnerability-
Articles/Important-information-
on-VPNFilter-Attacks/ta-
p/215123)
In an Active/Passive HA Pair
are Existing Session...
(/t5/Learning-Articles/In-an-
Active-Passive-HA-Pair-are-
https://live.paloaltonetworks.com/t5/Learning-Articles/Information-Synchronized-in-an-HA-Pair/ta-p/57292 2/3
13/06/2018 Live Community - Information Synchronized in an HA Pair - Live Community
Existing-Sessions-Sync-ed-
When/ta-p/58312)
p/217722)
The World Cup is upon us, and while it b... Ignite: What's in it for me? (https://www.linkedin.com/compan
(https://live.paloaltonetworks.com/t5/Ignite- alto-
New App-IDs for June are ready! Blog/Ignite-What-s-in-it-for-me/ba- networks) (https://www.facebook.
(https://live.paloaltonetworks.com/t5/Comm p/213292)
unity-Blog/New-App-IDs-for-June-are- Ignite. What's all the fuss? You've got ...
ready/ba-p/217639)
New App-IDs for June are ready. Click to... We get by with a little help from our friends
(https://live.paloaltonetworks.com/t5/Ignite-
Palo Alto Networks SuperFan Program Blog/We-get-by-with-a-little-help-from-our-
(https://live.paloaltonetworks.com/t5/Comm friends/ba-p/212142)
unity-Blog/Palo-Alto-Networks-SuperFan- Hey, other than you, who are the geniuse...
Program/ba-p/217621)
A membership with super-sized bene ts J...
Copyright 2007 - 2018 - Palo Alto Networks Privacy Policy (https://www.paloaltonetworks.com/legal/privacy.html) Terms of Use (/t5/user/UserTermsOfServicePage)
(https://www.lithium.com/powered-by-lithium
https://live.paloaltonetworks.com/t5/Learning-Articles/Information-Synchronized-in-an-HA-Pair/ta-p/57292 3/3