Active/Active HA
—If the firewalls are using the MGT
interface for content updates, then select
download-and-install
on
both firewalls but do not enable
Sync To Peer
.
However, if the firewalls are using a data port, then select
download-and-install
on
both firewalls and enable
Sync To Peer
so
that if one firewall goes into the active-secondary state, the active-primary
firewall will download and install the updates and push them to
the active-secondary firewall.