<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Paloalto HA probem in Next-Generation Firewall Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/paloalto-ha-probem/m-p/516414#M434</link>
    <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/221866"&gt;@GabrielePiccini&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;Are both firewalls currently managed by Panorama?&lt;/P&gt;
&lt;P&gt;Are both firewalls receiving configuration from Panorama - are both assigned to same templates/device-group?&lt;/P&gt;
&lt;P&gt;Are you using management interface for HA1? Are there any other PAN firewalls in the same network?&lt;/P&gt;
&lt;P&gt;Are you able to login to the firewall while it is "down"?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;One of the possible think I am imagine is that when enabling the HA, firewalls are trying to sync the config - if "Enable Config Sync" is enabled. This option will sync firewalls local config, Panorama pushed config is not synced between HA members - Panorama always push config to each member in the HA separately. So it is possible that syncing local config to actually telling the firewall to remove everything (since the local config is empty and everything is pushed from Panorama). &lt;/P&gt;
&lt;P&gt;This could explain why FW loose connectivity with Panorama - assuming it is reaching it over OOB network, not passing over dataplane.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Another option would be that firewall is detecting another PAN HA cluster - if HA Group ID is the same. For that reason firewall is going to either non-functional or passive state and stop processing traffic.&lt;/P&gt;</description>
    <pubDate>Thu, 29 Sep 2022 22:03:33 GMT</pubDate>
    <dc:creator>aleksandar.astardzhiev</dc:creator>
    <dc:date>2022-09-29T22:03:33Z</dc:date>
    <item>
      <title>Paloalto HA probem</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/paloalto-ha-probem/m-p/516340#M431</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;we have a few PA440 clusters where we are unable to activate HA. Software version is 10.1.6-h6.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As soon as we enable HA on first node, everything goes down (including internet access) and then the config gets rolled back (due to lost connectivity to panorama).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I cannot seem to find any hint in the system logs.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Has this happened to anyone?&lt;/P&gt;</description>
      <pubDate>Thu, 29 Sep 2022 08:53:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/paloalto-ha-probem/m-p/516340#M431</guid>
      <dc:creator>GabrielePiccini</dc:creator>
      <dc:date>2022-09-29T08:53:32Z</dc:date>
    </item>
    <item>
      <title>Re: Paloalto HA probem</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/paloalto-ha-probem/m-p/516414#M434</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/221866"&gt;@GabrielePiccini&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;Are both firewalls currently managed by Panorama?&lt;/P&gt;
&lt;P&gt;Are both firewalls receiving configuration from Panorama - are both assigned to same templates/device-group?&lt;/P&gt;
&lt;P&gt;Are you using management interface for HA1? Are there any other PAN firewalls in the same network?&lt;/P&gt;
&lt;P&gt;Are you able to login to the firewall while it is "down"?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;One of the possible think I am imagine is that when enabling the HA, firewalls are trying to sync the config - if "Enable Config Sync" is enabled. This option will sync firewalls local config, Panorama pushed config is not synced between HA members - Panorama always push config to each member in the HA separately. So it is possible that syncing local config to actually telling the firewall to remove everything (since the local config is empty and everything is pushed from Panorama). &lt;/P&gt;
&lt;P&gt;This could explain why FW loose connectivity with Panorama - assuming it is reaching it over OOB network, not passing over dataplane.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Another option would be that firewall is detecting another PAN HA cluster - if HA Group ID is the same. For that reason firewall is going to either non-functional or passive state and stop processing traffic.&lt;/P&gt;</description>
      <pubDate>Thu, 29 Sep 2022 22:03:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/paloalto-ha-probem/m-p/516414#M434</guid>
      <dc:creator>aleksandar.astardzhiev</dc:creator>
      <dc:date>2022-09-29T22:03:33Z</dc:date>
    </item>
    <item>
      <title>Re: Paloalto HA probem</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/paloalto-ha-probem/m-p/516445#M438</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Are both firewalls currently managed by Panorama? YES&lt;/P&gt;
&lt;P&gt;Are both firewalls receiving configuration from Panorama - are both assigned to same templates/device-group? YES&lt;/P&gt;
&lt;P&gt;Are you using management interface for HA1? Are there any other PAN firewalls in the same network? NO, DEDICATED ONE. NO OTHER DEVICES ON NETWORK&lt;/P&gt;
&lt;P&gt;Are you able to login to the firewall while it is "down"? YES, VIA PUBLIC IP ADDRESS&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I also tried with "sync config" off. No matter what, even if firewall 2 has HA disabled, enabling HA on firewall 1 brings everything down.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Also , this occured on another installation (so it's not hardware related).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks for reply&lt;/P&gt;</description>
      <pubDate>Fri, 30 Sep 2022 06:46:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/paloalto-ha-probem/m-p/516445#M438</guid>
      <dc:creator>GabrielePiccini</dc:creator>
      <dc:date>2022-09-30T06:46:05Z</dc:date>
    </item>
    <item>
      <title>Re: Paloalto HA probem</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/paloalto-ha-probem/m-p/516723#M447</link>
      <description>&lt;P&gt;We finally managed to enable HA by starting from the secondiary node. Really strage.&lt;/P&gt;</description>
      <pubDate>Tue, 04 Oct 2022 08:36:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/paloalto-ha-probem/m-p/516723#M447</guid>
      <dc:creator>GabrielePiccini</dc:creator>
      <dc:date>2022-10-04T08:36:53Z</dc:date>
    </item>
  </channel>
</rss>

