Phase 2 SAs (Security Associations) are synchronized over HA2 links. This ensures that the IPsec tunnels are consistent between the primary and secondary firewalls, allowing for seamless failover in case the active firewall fails.
Phase 1 SAs are not specifically synchronized over HA links; instead, the Phase 1 configuration is usually re-established as part of the failover process.
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
krzyb
3 months, 2 weeks agoMoadil_001
4 months, 2 weeks agokaymorr
4 months, 3 weeks agokambata
4 months, 3 weeks ago