3.1 Ensure a fully-synchronized High Availability peer is configured

Information

Ensure a High Availability peer is fully synchronized and in a passive or active state.
Rationale:
To ensure availability of both the firewall and the resources it protects, a High Availability peer is required. In the event a single firewall fails, or when maintenance such as a software update is required, the HA peer can be used to automatically fail over session states and maintain overall availability

Solution

Navigate to Device > High Availability > General.
Click General.
Click Data Link (HA2).
Select the correct interface .
Select the protocol (IPv4 or IPv6).
Select the correct Transport.
Set the Enable Session Synchronization box to be checked.
Save Configuration.
Default Value:
Not Configured

See Also

https://workbench.cisecurity.org/files/1780

Item Details

Category: SYSTEM AND INFORMATION INTEGRITY

References: 800-53|SI-13(5)

Plugin: Palo_Alto

Control ID: ad883dbb728774f9f08b1dab3f0390396c46eaa94e625ce4f73b85cd98dd8179