Command Center Configuration Templates enable you to replicate a configuration across multiple NG Firewall appliances. This is useful for example if you want to have a standby failover system, or if you manage multiple deployments that use an identical configuration. Configuration replication works in combination with Configuration Backup.
NG Firewall configuration replication can include a complete configuration or specific sections of the configuration. You can manage both options in the Policies area of Command Center.
- To push the complete configuration use Templates. Note that the network configuration is excluded from the template.
- To push specific types of the configuration such as Firewall rules or Captive Portal settings, use the options beneath templates in the Policies menu. See Managing Command Center Policies for more details.
- Appliances must meet the requirements for managing appliances in Command Center.
- Configuration templates are based on backups. Therefore you must install and enable Configuration Backup.
- Each appliance must be running version 13.2 and above.
Note: If you use Policy Manager to create custom policies, you must create the same policy names on each appliance. Otherwise only the default policy synchronizes to each appliance.
To create a template:
- Navigate to the Policies tab in Command Center.
- In the menu on the left, click Template Configuration.
- Click Create Template to open the template configuration wizard.
- Choose an appliance you want to use as the configuration master and click Next.
- Choose a recent backup and click Next.
- Choose appliances to sync from the master.
- If you want the appliances to synchronize when you make changes to the master, enable Keep in Sync and set a schedule.
- Click Next.
- On the final step, click Sync Now to apply the configuration template.
- Click Close.
Sorting and Filters
The Template Configuration grid displays your templates and relevant details in sortable and filterable columns. You can manage these options and show or hide columns by clicking the down arrow to the right of any column header to access the menu.
Sync Now - You can manually initiate a configuration sync by selecting one or more templates and clicking Sync Now. You can also configure appliances to synchronize automatically.
Keep in Sync - You can set a sync schedule as Immediate, Daily, or Weekly. You can configure the Keep in Sync option when creating a new configuration template, or afterwards by selecting the template and clicking Manage Template.
Notes regarding synchronization:
- When synchronizing a configuration, the appliance requires a reboot. Assign a schedule outside of peak usage hours to reduce service interruption.
- If a template is configured for immediate synchronization and the target appliance is offline, the target appliance retries every 12 hours for up to 7 days.
- You can check the status of synchronized appliances in the Audit History of the Event Log.
Target Appliances inherit the configuration of the Master Appliance based on the sync options. You configure target appliances when creating a new configuration template, or afterwards by selecting the template and clicking Manage Template.Target Appliances
Note: Each NG Firewall appliance must be on the same version. The configuration does not sync unless the version of the appliance matches the version of the master appliance.
To delete one or more templates, select the template and click Delete Templates.Follow