Replace a failed secondary Cloud-Delivered Firewall Management Center (successful backup)

This task enables you to replace a failed secondary Cloud-Delivered Firewall Management Center when a successful backup exists, ensuring continued high availability and minimal disruption.

Two Cloud-Delivered Firewall Management Centers—FMC1 (primary) and FMC2 (secondary)—form a high availability pair. If the secondary fails but its backup is successful, you can restore high availability by replacing it and restoring the backup.

Before you begin

Verify that the data backup from the failed secondary Cloud-Delivered Firewall Management Center is successful.

Procedure


Step 1

Contact Support to request a replacement for a failed Cloud-Delivered Firewall Management Center - FMC2.

Step 2

Continue to use the primary Cloud-Delivered Firewall Management Center - FMC1 as the active Cloud-Delivered Firewall Management Center.

Step 3

Reimage the replacement Cloud-Delivered Firewall Management Center with the same software version as FMC2.

Step 4

Restore the data backup from FMC2 to the new Cloud-Delivered Firewall Management Center.

Step 5

Install the required Cloud-Delivered Firewall Management Center patches, geolocation database (GeoDB) updates, vulnerability database (VDB) updates, and system software updates to match FMC1.

Step 6

Resume data synchronization (if paused) from the web interface of the new Cloud-Delivered Firewall Management Center - FMC2, to synchronize the latest configuration from the primary Cloud-Delivered Firewall Management Center - FMC1. For more information, refer to Restart communication between paired Cloud-Delivered Firewall Management Centers.

Classic and Smart Licenses work seamlessly.

What to do next

High availability has now been re-established and the primary and the secondary Cloud-Delivered Firewall Management Centers will now work as expected.