Establish high availability for Cloud-Delivered Firewall Management Center

Establishing high availability for Cloud-Delivered Firewall Management Center enables redundancy and ensures continuous management operations in case one management center fails.

High availability setup can take several hours, depending on bandwidth between peers, the number of policies, and the number of devices registered to the active Cloud-Delivered Firewall Management Center that must be synchronized to the standby Cloud-Delivered Firewall Management Center. You can view the High Availability page to check the status of the high availability peers.

Before you begin

Procedure


Step 1

Log into the Cloud-Delivered Firewall Management Center that you want to designate as the secondary.

Step 2

Choose Integration > Other Integrations, and then choose High Availability.

Step 3

Under Role for this Cloud-Delivered Firewall Management Center, choose Secondary, and complete these steps:

  1. Enter the hostname or IP address of the primary Cloud-Delivered Firewall Management Center in the Primary Firewall Management Center Host text box.

    You can leave this empty if the primary Cloud-Delivered Firewall Management Center does not have an IP address reachable from the peer Cloud-Delivered Firewall Management Center (the address can be public or private). In this case, use both the Registration Key and the Unique NAT ID fields. You need to specify the IP address of at least one Cloud-Delivered Firewall Management Center to enable HA connection.

  2. Enter a one-time-use registration key in the Registration Key text box.

    The registration key is a user-defined alphanumeric value up to 37 characters in length. Use this key to register both the secondary and the primary Cloud-Delivered Firewall Management Centers.

  3. If you did not specify the primary IP address, or if you do not plan to specify the secondary IP address on the primary Cloud-Delivered Firewall Management Center, then in the Unique NAT ID field, enter a unique alphanumeric ID. Refer to NAT Environments for more information.

Step 4

Click Register.

Step 5

Using an account with Admin access, log into the Cloud-Delivered Firewall Management Center that you want to designate as the primary, and then choose Integration > Other Integrations, and then choose High Availability.

Step 6

Under Role for this Cloud-Delivered Firewall Management Center, choose Primary, and complete these steps:

  1. Enter the hostname or IP address of the secondary Cloud-Delivered Firewall Management Center in the Secondary Firewall Management Center Host text box.

    You can leave this empty if the secondary Cloud-Delivered Firewall Management Center does not have an IP address reachable from the peer Cloud-Delivered Firewall Management Center (which can be a public or private IP address). In this case, use both the Registration Key and the Unique NAT ID fields. You must specify the IP address of at least one Cloud-Delivered Firewall Management Center to enable HA connection.

  2. Enter the same one-time-use registration key in the Registration Key text box you used in step 6.

  3. If required, enter the same NAT ID that you used in step 7 in the Unique NAT ID text box.

Step 7

Click Register.


After you complete these steps, the two Cloud-Delivered Firewall Management Centers operate with high availability, providing redundancy and seamless failover for device management.

What to do next

After establishing the Cloud-Delivered Firewall Management Center high availability pair, devices registered to the active Cloud-Delivered Firewall Management Center are automatically registered to the standby Cloud-Delivered Firewall Management Center.

Note

When a registered device has a NAT IP address, automatic device registration fails and the secondary Cloud-Delivered Firewall Management Center High Availability page lists the device as local, pending. You can then assign a different NAT IP address to the device on the standby Cloud-Delivered Firewall Management Center High Availability page. If automatic registration otherwise fails on the standby Cloud-Delivered Firewall Management Center, but the device appears to be registered to the active Secure Firewall Management Center, see Resolve device registration using CLI in Cloud-Delivered Firewall Management Center high availability.