Remove a Device from an NGFW Cluster
Focus
Focus
Next-Generation Firewall

Remove a Device from an NGFW Cluster

Table of Contents

Remove a Device from an NGFW Cluster

Remove a single firewall node from an NGFW cluster using Strata Cloud Manager without disrupting the remaining active node.
Where Can I Use This?What Do I Need?
  • NGFW
  • Strata Cloud Manager Pro
  • An existing NGFW cluster with two member firewalls
Use this procedure to remove a single firewall from an active NGFW cluster — for planned maintenance, debugging, or hardware replacement — while the remaining node continues passing traffic. The recommended practice is to remove Node 2 and leave Node 1 active.
The Select Devices screen used in this procedure doesn't warn you before a device selection change reassigns a Node ID. Changing a firewall's assigned Node ID — even unintentionally — clears that firewall's configuration and immediately triggers a mandatory reboot.
What happens when a Node ID changes: Reassigning a firewall's Node ID is a platform identity change, not a simple configuration edit. When Strata Cloud Manager pushes the change, the firewall clears its previously pushed configuration, migrates local settings to the new identity, and immediately initiates a system reboot — by design, whether the change was intentional or accidental.
Verify serial numbers carefully before you save any change on this screen.
  1. Confirm both cluster nodes are currently ONLINE and that session synchronization across the HSCI links is healthy (see Node States Determine the Cluster State).
  2. If a multichassis link aggregation group (MC-LAG) or upstream routing depends on the node you're removing, drain traffic from it at the switch layer first, and confirm active sessions shift to the remaining node without drops.
  3. Select ConfigurationNGFW and Prisma Access.
  4. For the Configuration Scope, select the folder that contains the cluster.
  5. Select Overview, and in the Cluster Setup pane, click the cluster name to open the cluster workflow.
  6. On the Select Devices tab, clear the Node 2 Device selection.
    If clearing the Node 2 selection doesn't take effect immediately, toggle the Node 1 Device selection first to release the Node 2 highlight, then clear Node 2. Before you continue, verify that the serial number shown for Node 1 hasn't changed. If it has, stop and re-select the correct device before saving.
  7. Click Save.
    Strata Cloud Manager closes the workflow and removes the device from the cluster folder. Strata Cloud Manager sends the operational command that sets the removed device's Node ID to 0 (unclustered).
  8. The device reboots automatically to apply the change. If it doesn't reboot on its own, a manual reboot is required.
    Confirm the operation succeeded by checking that the device's Node ID shows 0 in its local management interface.
  9. After the reboot, connect directly to the device (not through the cluster) and confirm it's fully standalone.
    1. On the local Dashboard's Firewall Cluster widget, confirm it reads Clustering not enabled.
    2. From the CLI, confirm the chassis is healthy:
      show chassis status
      Confirm the output shows Chassis autocommit ready: True.
  10. Restore the device to standalone configuration.
    1. In Folder Management, move the device out of the cluster folder into its standalone device folder.
    2. Associate the device with its non-cluster configuration snippet, replacing cluster Ethernet interface references (such as node2:ethernet1/1) with the equivalent standard interface name (ethernet1/1).
    3. Push the configuration to the device and validate that the commit succeeds.
  11. View NGFW Cluster Summary and Monitoring to confirm the remaining node continues to report the expected cluster state.
    The cluster state will be OK once both nodes are healthy again, or IMPACTED while the removed node is offline.