<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic High Bandwidth on Broker VM: Cluster Mismatch (v29 vs v28) &amp;amp; P2P in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/high-bandwidth-on-broker-vm-cluster-mismatch-v29-vs-v28-amp-p2p/m-p/1246903#M9065</link>
    <description>&lt;P data-path-to-node="4"&gt;&lt;STRONG data-path-to-node="4" data-index-in-node="0"&gt;Hi everyone,&lt;/STRONG&gt;&lt;/P&gt;
&lt;P data-path-to-node="5"&gt;I'm facing high bandwidth usage on my Primary Broker VM. I need to validate if my diagnosis is correct:&lt;/P&gt;
&lt;P data-path-to-node="6"&gt;&lt;STRONG data-path-to-node="6" data-index-in-node="0"&gt;The Setup:&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL data-path-to-node="7"&gt;
&lt;LI&gt;
&lt;P data-path-to-node="7,0,0"&gt;&lt;STRONG data-path-to-node="7,0,0" data-index-in-node="0"&gt;Cluster:&lt;/STRONG&gt; HA Pair. Node 1 is &lt;STRONG data-path-to-node="7,0,0" data-index-in-node="28"&gt;v29.0.77&lt;/STRONG&gt; (Healthy). Node 2 is &lt;STRONG data-path-to-node="7,0,0" data-index-in-node="58"&gt;v28.0.99&lt;/STRONG&gt; (Service "Local Agent Settings" is &lt;STRONG data-path-to-node="7,0,0" data-index-in-node="102"&gt;Red/Down&lt;/STRONG&gt;).&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P data-path-to-node="7,1,0"&gt;&lt;STRONG data-path-to-node="7,1,0" data-index-in-node="0"&gt;Policy:&lt;/STRONG&gt; Download Source = Broker VM (P2P is currently disabled).&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P data-path-to-node="8"&gt;&lt;STRONG data-path-to-node="8" data-index-in-node="0"&gt;My Questions:&lt;/STRONG&gt;&lt;/P&gt;
&lt;OL start="1" data-path-to-node="9"&gt;
&lt;LI&gt;
&lt;P data-path-to-node="9,0,0"&gt;&lt;STRONG data-path-to-node="9,0,0" data-index-in-node="0"&gt;Cluster:&lt;/STRONG&gt; Does the version mismatch cause the load balancing to fail, forcing Node 1 to handle 100% of the traffic?&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P data-path-to-node="9,1,0"&gt;&lt;STRONG data-path-to-node="9,1,0" data-index-in-node="0"&gt;Agent Logic:&lt;/STRONG&gt; If "Broker VM" is selected in the policy, do agents &lt;STRONG data-path-to-node="9,1,0" data-index-in-node="65"&gt;always&lt;/STRONG&gt; prioritize the Broker over the Cloud (Internet), even if they have direct Internet access?&lt;/P&gt;
&lt;/LI&gt;
&lt;/OL&gt;
&lt;P data-path-to-node="10"&gt;I plan to enable P2P and upgrade Node 2 to match versions. Is this the right path?&lt;/P&gt;
&lt;P data-path-to-node="11"&gt;Thanks!&lt;/P&gt;</description>
    <pubDate>Wed, 28 Jan 2026 19:59:34 GMT</pubDate>
    <dc:creator>QuestionAb</dc:creator>
    <dc:date>2026-01-28T19:59:34Z</dc:date>
    <item>
      <title>High Bandwidth on Broker VM: Cluster Mismatch (v29 vs v28) &amp; P2P</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/high-bandwidth-on-broker-vm-cluster-mismatch-v29-vs-v28-amp-p2p/m-p/1246903#M9065</link>
      <description>&lt;P data-path-to-node="4"&gt;&lt;STRONG data-path-to-node="4" data-index-in-node="0"&gt;Hi everyone,&lt;/STRONG&gt;&lt;/P&gt;
&lt;P data-path-to-node="5"&gt;I'm facing high bandwidth usage on my Primary Broker VM. I need to validate if my diagnosis is correct:&lt;/P&gt;
&lt;P data-path-to-node="6"&gt;&lt;STRONG data-path-to-node="6" data-index-in-node="0"&gt;The Setup:&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL data-path-to-node="7"&gt;
&lt;LI&gt;
&lt;P data-path-to-node="7,0,0"&gt;&lt;STRONG data-path-to-node="7,0,0" data-index-in-node="0"&gt;Cluster:&lt;/STRONG&gt; HA Pair. Node 1 is &lt;STRONG data-path-to-node="7,0,0" data-index-in-node="28"&gt;v29.0.77&lt;/STRONG&gt; (Healthy). Node 2 is &lt;STRONG data-path-to-node="7,0,0" data-index-in-node="58"&gt;v28.0.99&lt;/STRONG&gt; (Service "Local Agent Settings" is &lt;STRONG data-path-to-node="7,0,0" data-index-in-node="102"&gt;Red/Down&lt;/STRONG&gt;).&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P data-path-to-node="7,1,0"&gt;&lt;STRONG data-path-to-node="7,1,0" data-index-in-node="0"&gt;Policy:&lt;/STRONG&gt; Download Source = Broker VM (P2P is currently disabled).&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P data-path-to-node="8"&gt;&lt;STRONG data-path-to-node="8" data-index-in-node="0"&gt;My Questions:&lt;/STRONG&gt;&lt;/P&gt;
&lt;OL start="1" data-path-to-node="9"&gt;
&lt;LI&gt;
&lt;P data-path-to-node="9,0,0"&gt;&lt;STRONG data-path-to-node="9,0,0" data-index-in-node="0"&gt;Cluster:&lt;/STRONG&gt; Does the version mismatch cause the load balancing to fail, forcing Node 1 to handle 100% of the traffic?&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P data-path-to-node="9,1,0"&gt;&lt;STRONG data-path-to-node="9,1,0" data-index-in-node="0"&gt;Agent Logic:&lt;/STRONG&gt; If "Broker VM" is selected in the policy, do agents &lt;STRONG data-path-to-node="9,1,0" data-index-in-node="65"&gt;always&lt;/STRONG&gt; prioritize the Broker over the Cloud (Internet), even if they have direct Internet access?&lt;/P&gt;
&lt;/LI&gt;
&lt;/OL&gt;
&lt;P data-path-to-node="10"&gt;I plan to enable P2P and upgrade Node 2 to match versions. Is this the right path?&lt;/P&gt;
&lt;P data-path-to-node="11"&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Wed, 28 Jan 2026 19:59:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/high-bandwidth-on-broker-vm-cluster-mismatch-v29-vs-v28-amp-p2p/m-p/1246903#M9065</guid>
      <dc:creator>QuestionAb</dc:creator>
      <dc:date>2026-01-28T19:59:34Z</dc:date>
    </item>
    <item>
      <title>Re: High Bandwidth on Broker VM: Cluster Mismatch (v29 vs v28) &amp; P2P</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/high-bandwidth-on-broker-vm-cluster-mismatch-v29-vs-v28-amp-p2p/m-p/1247027#M9072</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/804344437"&gt;@QuestionAb&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Greetings for the day.&lt;/P&gt;
&lt;HR /&gt;
&lt;H4&gt;1. Cluster Load Balancing and Node Failure&lt;/H4&gt;
&lt;P&gt;&lt;STRONG&gt;Does the version mismatch cause load balancing to fail, forcing Node 1 to handle 100% of the traffic?&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Native Load Balancing&lt;/STRONG&gt;&lt;BR /&gt;The Broker VM cluster feature is designed for high availability and failover redundancy, but it does &lt;STRONG&gt;not&lt;/STRONG&gt; provide native load balancing to actively distribute traffic across nodes. If active/active traffic distribution is required, it must be implemented using an external load balancer.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Failover Logic&lt;/STRONG&gt;&lt;BR /&gt;When a node in the cluster is marked as &lt;EM&gt;Red/Down&lt;/EM&gt;, the HA mechanism shifts all responsibilities to the healthy node. Since Node 2’s &lt;EM&gt;Local Agent Settings&lt;/EM&gt; service is down, it cannot serve agents, which effectively forces Node 1 to handle all agent traffic.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Version Mismatch&lt;/STRONG&gt;&lt;BR /&gt;Rolling upgrades are supported to minimize downtime, but running cluster nodes on different versions for an extended period can cause synchronization inconsistencies. Version &lt;STRONG&gt;v28.0.99&lt;/STRONG&gt; is associated with a known issue that causes repeated content downloads and excessive bandwidth usage. This behavior can further increase the load on the remaining healthy node.&lt;/P&gt;
&lt;HR /&gt;
&lt;H4&gt;2. Agent Logic and Download Priority&lt;/H4&gt;
&lt;P&gt;&lt;STRONG&gt;If “Broker VM” is selected in the policy, do agents always prioritize the Broker over the Cloud?&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Priority Order&lt;/STRONG&gt;&lt;BR /&gt;When &lt;EM&gt;Broker VM&lt;/EM&gt; is selected as a download source, the Cortex XDR agent follows this hierarchy:&lt;BR /&gt;&lt;STRONG&gt;P2P → Broker VM → Cortex Server (Cloud)&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Prioritization Behavior&lt;/STRONG&gt;&lt;BR /&gt;If P2P is disabled, agents will attempt to download content from the Broker VM first. They will fall back to the Cloud only if they cannot connect to the Broker VM or if the Broker returns an error (for example, authentication, authorization, or SSL-related failures).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Direct Server Access&lt;/STRONG&gt;&lt;BR /&gt;If &lt;EM&gt;Direct Server Access&lt;/EM&gt; is enabled in the agent settings profile, agents may bypass the Broker VM and connect directly to the Cortex cloud if they detect connectivity or caching issues with the Broker.&lt;/P&gt;
&lt;H4&gt;3. Recommended Path&lt;/H4&gt;
&lt;P&gt;&lt;STRONG&gt;Is enabling P2P and upgrading Node 2 the right path?&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Yes, this is the recommended approach.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Upgrade Node 2&lt;/STRONG&gt;&lt;BR /&gt;Upgrading Node 2 from &lt;STRONG&gt;v28.0.99&lt;/STRONG&gt; is critical due to the known content re-download issue that causes excessive bandwidth usage. Aligning Node 2 with Node 1 on &lt;STRONG&gt;v29.x&lt;/STRONG&gt; will also restore proper HA behavior and reduce synchronization risks.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Enable P2P&lt;/STRONG&gt;&lt;BR /&gt;Enabling Peer-to-Peer (P2P) significantly reduces the load on the Broker VM by allowing agents to share content packages within the same local network segment.&lt;/P&gt;
&lt;H4&gt;Recommended Troubleshooting Steps&lt;/H4&gt;
&lt;OL&gt;
&lt;LI&gt;
&lt;P&gt;&lt;STRONG&gt;Verify caching prerequisites&lt;/STRONG&gt;&lt;BR /&gt;Ensure Node 1 has a valid FQDN and properly configured SSL certificates, as these are required for Broker VM content caching.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;&lt;STRONG&gt;Check disk space&lt;/STRONG&gt;&lt;BR /&gt;Insufficient space on the &lt;CODE&gt;/data&lt;/CODE&gt; partition can cause content download failures and abnormal bandwidth usage.&lt;BR /&gt;Run:&lt;/P&gt;
&lt;PRE&gt;&lt;CODE&gt;df -h /data
&lt;/CODE&gt;&lt;/PRE&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;&lt;STRONG&gt;Monitor active connections&lt;/STRONG&gt;&lt;BR /&gt;Review active agent connections on Node 1. Note that the &lt;EM&gt;Local Agent Settings&lt;/EM&gt; applet only shows connections that are actively transferring data at that exact moment, not total registered agents.&lt;/P&gt;
&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;If you feel this has answered your query, please let us know by clicking like and on&amp;nbsp;&lt;STRONG&gt;"mark this as a Solution".&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Happy New year!!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks &amp;amp; Regards,&lt;BR /&gt;S. Subashkar Sekar&lt;/P&gt;</description>
      <pubDate>Thu, 29 Jan 2026 17:35:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/high-bandwidth-on-broker-vm-cluster-mismatch-v29-vs-v28-amp-p2p/m-p/1247027#M9072</guid>
      <dc:creator>susekar</dc:creator>
      <dc:date>2026-01-29T17:35:19Z</dc:date>
    </item>
    <item>
      <title>Re: High Bandwidth on Broker VM: Cluster Mismatch (v29 vs v28) &amp; P2P</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/high-bandwidth-on-broker-vm-cluster-mismatch-v29-vs-v28-amp-p2p/m-p/1248159#M9130</link>
      <description>&lt;P&gt;Thank you so much!!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 13 Feb 2026 22:07:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/high-bandwidth-on-broker-vm-cluster-mismatch-v29-vs-v28-amp-p2p/m-p/1248159#M9130</guid>
      <dc:creator>QuestionAb</dc:creator>
      <dc:date>2026-02-13T22:07:59Z</dc:date>
    </item>
  </channel>
</rss>

