For whatever reason, I had a Palo Alto Networks cluster that was not able to sync. A manual sync was not working, nor did a reboot of both devices (sequentially) help. Finally, the PAN support told me to “Export device state” on the active unit, import it on the passive one, do some changes, and commit. Indeed, this fixed it. A little more details:
I was running a PA-820 cluster with PAN-OS 8.1.13. Screenshot from the dashboard:
Some system logs:
I wanted to do some OS upgrades but wanted to fix this error before, of course.
This finally made it:
- Export of the “device state” from the active device. Device -> Setup -> Operations -> “Export device state”.
- Now on the passive device: “Import device state”. DO NOT COMMIT YET!
- Change the following settings on the passive device:
- hostname & login banner (if specific)
- management IP settings
- HA settings
- Commit on the passive device.
Worked for me. Though I do not know why this happened at all…