Replace a failed secondary Cloud-Delivered Firewall Management Center (unsuccessful backup)

This task enables you to restore high availability by replacing a failed secondary Cloud-Delivered Firewall Management Center when backup from the secondary is unsuccessful.

  • Ensures the primary management center remains active during the replacement process.

  • Synchronizes configuration and licensing between the primary and replacement secondary management centers.

Two Cloud-Delivered Firewall Management Centers, FMC1 (primary) and FMC2 (secondary), form a high availability pair. If the secondary fails and backup is unsuccessful, you must replace it to restore high availability.

This procedure is relevant when the secondary management center cannot be recovered from backup and must be replaced to maintain system redundancy and continuity.

Applicable in high availability deployments of Secure Firewall Management Centers.

Before you begin

Ensure you have access to the primary Cloud-Delivered Firewall Management Center and the replacement device for the secondary.

  • Verify the replacement device is available and ready for reimaging.

  • Obtain the required software version and updates for the replacement device.

Procedure


Step 1

Contact Support to request a replacement for a failed Cloud-Delivered Firewall Management Center - FMC2.

Step 2

Continue to use the primary Cloud-Delivered Firewall Management Center - FMC1 as the active Cloud-Delivered Firewall Management Center.

Step 3

Reimage the replacement Cloud-Delivered Firewall Management Center with the same software version as FMC2.

Step 4

Install the required Cloud-Delivered Firewall Management Center patches, geolocation database (GeoDB) updates, vulnerability database (VDB) updates and system software updates to match FMC1.

Step 5

Access the web interface of the primary Cloud-Delivered Firewall Management Center - FMC1 and break Cloud-Delivered Firewall Management Center high availability. For more information, refer to Disable Cloud-Delivered Firewall Management Center high availability. When prompted to select an option for handling managed devices, choose Manage registered devices from this console.

Step 6

Re-establish Cloud-Delivered Firewall Management Center high availability, by setting up the Cloud-Delivered Firewall Management Center - FMC1 as the primary and Cloud-Delivered Firewall Management Center - FMC2 as the secondary. For more information, refer to Establish high availability for Cloud-Delivered Firewall Management Center.

  • When high availability is successfully established, the latest configuration from the primary Cloud-Delivered Firewall Management Center - FMC1 is synchronized to the secondary Cloud-Delivered Firewall Management Center - FMC2.

  • Both Classic and Smart licenses function without issues.


What to do next

High availability has been re-established. The primary and secondary Cloud-Delivered Firewall Management Centers now operate as expected.