Establish high availability for Cloud-Delivered Firewall Management Center
Establishing high availability for Cloud-Delivered Firewall Management Center enables redundancy and ensures continuous management operations in case one management center fails.
High availability setup can take several hours, depending on bandwidth between peers, the number of policies, and the number of devices registered to the active Cloud-Delivered Firewall Management Center that must be synchronized to the standby Cloud-Delivered Firewall Management Center. You can view the High Availability page to check the status of the high availability peers.
Before you begin
-
Confirm that both the Cloud-Delivered Firewall Management Centers adhere to the high availability system requirements. For more information, refer to Requirements for Cloud-Delivered Firewall Management Center high availability.
-
Confirm that you completed the prerequisites for establishing high availability. For more information, refer to Prerequisites for Cloud-Delivered Firewall Management Center high availability.
-
In a multidomain deployment, perform this task in the Global domain.
Procedure
Step 1 | Log into the Cloud-Delivered Firewall Management Center that you want to designate as the secondary. |
Step 2 | Choose , and then choose High Availability. |
Step 3 | Under Role for this Cloud-Delivered Firewall Management Center, choose Secondary, and complete these steps:
|
Step 4 | Click Register. |
Step 5 | Using an account with Admin access, log into the Cloud-Delivered Firewall Management Center that you want to designate as the primary, and then choose , and then choose High Availability. |
Step 6 | Under Role for this Cloud-Delivered Firewall Management Center, choose Primary, and complete these steps:
|
Step 7 | Click Register. |
After you complete these steps, the two Cloud-Delivered Firewall Management Centers operate with high availability, providing redundancy and seamless failover for device management.
What to do next
After establishing the Cloud-Delivered Firewall Management Center high availability pair, devices registered to the active Cloud-Delivered Firewall Management Center are automatically registered to the standby Cloud-Delivered Firewall Management Center.
Note | When a registered device has a NAT IP address, automatic device registration fails and the secondary Cloud-Delivered Firewall Management Center High Availability page lists the device as local, pending. You can then assign a different NAT IP address to the device on the standby Cloud-Delivered Firewall Management Center High Availability page. If automatic registration otherwise fails on the standby Cloud-Delivered Firewall Management Center, but the device appears to be registered to the active Secure Firewall Management Center, see Resolve device registration using CLI in Cloud-Delivered Firewall Management Center high availability. |