After deploying the VM-Series firewall and
it connects to the Panorama management server, you must commit to
Panorama () to ensure that Panorama recognizes
the firewall as a managed device. If you reboot Panorama without committing
the changes, the firewall does not reconnect with Panorama; although
the device group displays the list of firewalls, the firewall does
not display in . Furthermore, when Panorama
has an HA configuration, the VM-Series firewall is not added to
the passive Panorama peer until the active Panorama peer synchronizes
the configuration. During this time, the passive Panorama peer logs
a critical message: vm-cfg: failed to process registration from svm device.vm-state: active.
The passive peer logs this message until you commit the changes
on the active Panorama, which then initiates synchronization between
the Panorama HA peers and the VM-Series firewall is added to the
passive Panorama peer. Workaround: To reconnect to
the managed firewalls, commit your changes to Panorama. In an HA
deployment, the commit initiates the synchronization of the running
configuration between the Panorama HA peers. |