After you replace a firewall in an HA cluster, reset the ID manager on the active
peer to prevent stale factory entries from causing traffic drops.
| Where Can I Use This? | What Do I Need? |
- NGFW (Managed by PAN-OS or Panorama)
|
|
When a replacement firewall joins an HA cluster as the passive peer, PAN-OS merges the
replacement unit's factory ID manager database with the active peer's operational
database. This merge can inject stale entries — application or policy IDs scoped to
virtual systems that don't exist in the running configuration. If the replacement unit
then becomes active while these stale entries are present, traffic can be
misidentified and dropped.
Resetting the ID manager on the active peer clears the merged database on both
peers. A subsequent commit force repopulates both peers from
the running configuration, removing any stale entries. Run the reset on the active
peer — running it on the passive peer doesn't resolve the issue because the next HA
sync cycle re-injects stale entries from the active peer's intact database.