<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: HA Passive interfaces not coming up. in Next-Generation Firewall Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/ha-passive-interfaces-not-coming-up/m-p/596585#M3677</link>
    <description>&lt;P&gt;Hi - thanks for the response!&lt;BR /&gt;&lt;BR /&gt;The links are monitored and the failover is being initiated as you have suggested above. We have changed the passive link state to auto from shutdown however the ports on passive Palo-Alto 2 connected to the core switch virtual chassis (switch 2) are in a 'notconnect' state. When these connections are moved from&amp;nbsp;core switch virtual chassis (switch 2) to (switch 1), the ports transition into a connected state. Does this suggest a loop in either the core switch or the Palo cluster? No logs are available on the core switch.&lt;/P&gt;</description>
    <pubDate>Tue, 03 Sep 2024 08:55:09 GMT</pubDate>
    <dc:creator>fw1972</dc:creator>
    <dc:date>2024-09-03T08:55:09Z</dc:date>
    <item>
      <title>HA Passive interfaces not coming up.</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/ha-passive-interfaces-not-coming-up/m-p/596530#M3674</link>
      <description>&lt;P&gt;Hi All, I have searched the community before posting however I cannot find a solution for the issue I am experiencing.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We have a very straightforward physical topology. A cisco 9500 sw switch stack operating as a stackwise-virtual chassis. On Switch 1 we have a single layer 2 copper connection to Palo-1 for inside traffic (inside to outside), on switch 2 we have a single layer 2 copper connection to Palo-2 for inside traffic&amp;nbsp;(inside to outside). Palo-1 is the active FW, Palo-2 is the Passive FW. HA is configured and directly connected, passive link state is 'shutdown'. The 9500 interfaces are configured as 'access' mode interfaces with spanning-tree portfast edge applied.&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;The issue we are seeing is during a manual failover from Palo-1 to Palo-2, the interfaces on Palo-2 do not become active, they remain down. I am not sure if changing the passive link state to 'auto' will help at all, other than speed up convergence time.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Can anyone please suggest what could be the issue?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Mon, 02 Sep 2024 09:28:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/ha-passive-interfaces-not-coming-up/m-p/596530#M3674</guid>
      <dc:creator>fw1972</dc:creator>
      <dc:date>2024-09-02T09:28:52Z</dc:date>
    </item>
    <item>
      <title>Re: HA Passive interfaces not coming up.</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/ha-passive-interfaces-not-coming-up/m-p/596534#M3676</link>
      <description>&lt;P&gt;how are you failing the cluster over?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;- manually setting the active member to suspended state ( device &amp;gt; high availability &amp;gt; operational commands &amp;gt; suspend local device)&lt;/P&gt;
&lt;P&gt;- unplugging/shutting an interface&lt;/P&gt;
&lt;P&gt;the last option also requires you to monitor your interfaces via&amp;nbsp;device &amp;gt; high availability &amp;gt; link and path monitoring&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="reaper_0-1725275312130.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/61883i278A97755B566370/image-size/large?v=v2&amp;amp;px=999" role="button" title="reaper_0-1725275312130.png" alt="reaper_0-1725275312130.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;else, your cluster will not fail over&lt;/P&gt;</description>
      <pubDate>Mon, 02 Sep 2024 11:09:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/ha-passive-interfaces-not-coming-up/m-p/596534#M3676</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2024-09-02T11:09:12Z</dc:date>
    </item>
    <item>
      <title>Re: HA Passive interfaces not coming up.</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/ha-passive-interfaces-not-coming-up/m-p/596585#M3677</link>
      <description>&lt;P&gt;Hi - thanks for the response!&lt;BR /&gt;&lt;BR /&gt;The links are monitored and the failover is being initiated as you have suggested above. We have changed the passive link state to auto from shutdown however the ports on passive Palo-Alto 2 connected to the core switch virtual chassis (switch 2) are in a 'notconnect' state. When these connections are moved from&amp;nbsp;core switch virtual chassis (switch 2) to (switch 1), the ports transition into a connected state. Does this suggest a loop in either the core switch or the Palo cluster? No logs are available on the core switch.&lt;/P&gt;</description>
      <pubDate>Tue, 03 Sep 2024 08:55:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/ha-passive-interfaces-not-coming-up/m-p/596585#M3677</guid>
      <dc:creator>fw1972</dc:creator>
      <dc:date>2024-09-03T08:55:09Z</dc:date>
    </item>
    <item>
      <title>Re: HA Passive interfaces not coming up.</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/ha-passive-interfaces-not-coming-up/m-p/597289#M3712</link>
      <description>&lt;P&gt;hm... that's tricky.... i'd be inclined to 'blame' the switch2&lt;/P&gt;
&lt;P&gt;the firewall should not care about loops when bringing up it's interfaces. As soon as the firewall becomes 'active/primary' the interfaces should come online regardless. If there's a loop you'll see a lot of errors on the interface etc, but the interfaces will remain up&lt;/P&gt;</description>
      <pubDate>Mon, 09 Sep 2024 10:36:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/ha-passive-interfaces-not-coming-up/m-p/597289#M3712</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2024-09-09T10:36:15Z</dc:date>
    </item>
  </channel>
</rss>

