Just
remove the sync to IP at your carpsettings before changing things at node1 if
you are unsure and enable it again after you are sure your configuration of
node 1 is ok. This way you can just power down node 1 if you have badly
missconfigured/totally destroyed it and the node 2 will take over with the old
configuration. Syncing should be (and stay) automatic imo.
Holger
I've made an error while creating a rule that made
me lost web connection to the node 1 of the firewall. Then, because of the
automatic sync, I lost the connection to node 2. :)
So, I think that one could choose if the sync is
manual or automatic. Create some rules on one node, test them, and if they
work, sync to the other node. This could be done by a "Sync now"
event.
What do you think?
____________
Virus checked by G DATA AntiVirusKit