<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Regarding the Operational Specifications for HA Mode in Next-Generation Firewall Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/regarding-the-operational-specifications-for-ha-mode/m-p/1244079#M6534</link>
    <description>&lt;P data-start="2111" data-end="2317"&gt;You mentioned “ports link up sequentially, starting from port 1” — there is &lt;STRONG data-start="2225" data-end="2245"&gt;no documentation&lt;/STRONG&gt; that PAN-OS enforces a specific sequential order (Port1 → Port2 → …).&lt;/P&gt;
&lt;P data-start="2319" data-end="2341"&gt;&lt;STRONG data-start="2319" data-end="2339"&gt;Actual behavior:&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL data-start="2342" data-end="2701"&gt;
&lt;LI data-start="2342" data-end="2561"&gt;
&lt;P data-start="2344" data-end="2561"&gt;In &lt;STRONG data-start="2347" data-end="2359"&gt;Shutdown&lt;/STRONG&gt;, all passive data interfaces are &lt;EM data-start="2393" data-end="2416"&gt;administratively down&lt;/EM&gt; and only brought up when active; link up happens as normal OS initialization when the device takes over. &lt;SPAN class="" data-state="closed"&gt;&lt;SPAN class="ms-1 inline-flex max-w-full items-center relative top-[-0.094rem] animate-[show_150ms_ease-in]" data-testid="webpage-citation-pill"&gt;&lt;A class="flex h-4.5 overflow-hidden rounded-xl px-2 text-[9px] font-medium transition-colors duration-150 ease-in-out text-token-text-secondary! bg-[#F4F4F4]! dark:bg-[#303030]!" href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClcACAS&amp;amp;utm_source=chatgpt.com" target="_blank" rel="noopener"&gt;&lt;SPAN class="relative start-0 bottom-0 flex h-full w-full items-center"&gt;&lt;SPAN class="flex h-4 w-full items-center justify-between overflow-hidden"&gt;&lt;SPAN class="max-w-[15ch] grow truncate overflow-hidden text-center"&gt;knowledgebase.paloaltonetworks.com&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;LI data-start="2562" data-end="2701"&gt;
&lt;P data-start="2564" data-end="2701"&gt;In &lt;STRONG data-start="2567" data-end="2575"&gt;Auto&lt;/STRONG&gt;, physical interfaces stay up on passive and so sequence is not a factor for failover. &lt;SPAN class="" data-state="closed"&gt;&lt;SPAN class="ms-1 inline-flex max-w-full items-center relative top-[-0.094rem] animate-[show_150ms_ease-in]" data-testid="webpage-citation-pill"&gt;&lt;A class="flex h-4.5 overflow-hidden rounded-xl px-2 text-[9px] font-medium transition-colors duration-150 ease-in-out text-token-text-secondary! bg-[#F4F4F4]! dark:bg-[#303030]!" href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClcACAS&amp;amp;utm_source=chatgpt.com" target="_blank" rel="noopener"&gt;&lt;SPAN class="relative start-0 bottom-0 flex h-full w-full items-center"&gt;&lt;SPAN class="flex h-4 w-full items-center justify-between overflow-hidden"&gt;&lt;SPAN class="max-w-[15ch] grow truncate overflow-hidden text-center"&gt;knowledgebase.paloaltonetworks.com&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P data-start="2703" data-end="2726"&gt;&amp;nbsp;&lt;/P&gt;
&lt;BLOCKQUOTE data-start="2727" data-end="2949"&gt;
&lt;P data-start="2729" data-end="2949"&gt;“PAN-OS does not document a strict port ordering sequence. In shutdown mode the interfaces are down, so their subsequent ‘up’ event happens during transition; in auto mode they are already up, so no sequence dependency.”&lt;BR /&gt;&lt;BR /&gt;Any delay seen during a transition is due to the interface link negotiation (PHY coming up) rather than an explicit documented difference in SFP diagnostics between modes.”&lt;BR /&gt;&lt;BR /&gt;Switchover speeds are influenced by whether links are already up (Auto) versus needing to be brought up (Shutdown). There is no separate switchover timer inherent to Auto mode beyond this behavior.&lt;BR /&gt;&lt;BR /&gt;Palo Alto Networks recommends &lt;STRONG data-start="4542" data-end="4554"&gt;Shutdown&lt;/STRONG&gt; as the default, especially if the firewall interfaces reside in Layer-2 networks. &lt;STRONG data-start="4637" data-end="4645"&gt;Auto&lt;/STRONG&gt; is recommended only when interfaces do &lt;EM data-start="4685" data-end="4690"&gt;not&lt;/EM&gt; participate in Layer-2 forwarding to avoid unexpected behavior&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;H3 data-start="4816" data-end="4926"&gt;&lt;STRONG data-start="4820" data-end="4926"&gt;s it correct that in Shutdown mode delays are OS specification and only way to speed up is Auto mode?&lt;/STRONG&gt;&lt;/H3&gt;
&lt;P data-start="4927" data-end="4949"&gt;&lt;STRONG data-start="4927" data-end="4947"&gt;Accurate answer:&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL data-start="4950" data-end="5250"&gt;
&lt;LI data-start="4950" data-end="5250"&gt;
&lt;P data-start="4952" data-end="5250"&gt;Yes — shutdown behavior keeps passive interfaces down, requiring them to come up only when active. That adds link negotiation delay that cannot be avoided in Shutdown mode. Auto mode eliminates the need for PHY link up during failover by keeping interfaces up. &lt;SPAN class="" data-state="closed"&gt;&lt;SPAN class="ms-1 inline-flex max-w-full items-center relative top-[-0.094rem] animate-[show_150ms_ease-in]" data-testid="webpage-citation-pill"&gt;&lt;A class="flex h-4.5 overflow-hidden rounded-xl px-2 text-[9px] font-medium transition-colors duration-150 ease-in-out text-token-text-secondary! bg-[#F4F4F4]! dark:bg-[#303030]!" href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClcACAS&amp;amp;utm_source=chatgpt.com" target="_blank" rel="noopener"&gt;&lt;SPAN class="relative start-0 bottom-0 flex h-full w-full items-center"&gt;&lt;SPAN class="flex h-4 w-full items-center justify-between overflow-hidden"&gt;&lt;SPAN class="max-w-[15ch] grow truncate overflow-hidden text-center"&gt;knowledgebase.paloaltonetworks.com&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;H3 data-start="5252" data-end="5292"&gt;&lt;STRONG data-start="5256" data-end="5292"&gt;Is there loop risk in Auto mode?&lt;/STRONG&gt;&lt;/H3&gt;
&lt;P data-start="5293" data-end="5315"&gt;&amp;nbsp;&lt;/P&gt;
&lt;UL data-start="5316" data-end="5631"&gt;
&lt;LI data-start="5316" data-end="5631"&gt;
&lt;P data-start="5318" data-end="5631"&gt;Yes — because in Auto mode, passive interfaces are reported as up and neighbors (switches) may send traffic or cause MAC/ARP learning issues if not carefully designed. That’s why documentation explicitly warns &lt;STRONG data-start="5528" data-end="5592"&gt;not to select Auto if you have Layer-2 interfaces configured&lt;/STRONG&gt;.&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;/BLOCKQUOTE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 17 Dec 2025 20:10:10 GMT</pubDate>
    <dc:creator>S.Cantwell</dc:creator>
    <dc:date>2025-12-17T20:10:10Z</dc:date>
    <item>
      <title>Regarding the Operational Specifications for HA Mode</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/regarding-the-operational-specifications-for-ha-mode/m-p/1242625#M6486</link>
      <description>&lt;P&gt;I am reviewing the operational specifications for HA mode. Could you please clarify the following points?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;lt;Device Information&amp;gt;&lt;BR /&gt;Model: PA-3420 (2-unit HA configuration)&lt;BR /&gt;OS Version: 11.1.6-h10&lt;BR /&gt;Interface Information: Onboard (2 ports), Optical SFP10G (3 ports)&lt;BR /&gt;HA Ports: HA1-A,B&lt;BR /&gt;　　　　 HA2 Eth1/21,1/22 (Optical SFP10G)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please confirm whether my understanding of the operational specifications for Shutdown mode and Auto mode in HA mode is correct.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;- Behavior During Failover&lt;BR /&gt;Shutdown mode: All ports link up from scratch&lt;BR /&gt;Auto mode: Port states are preserved, resulting in faster failover&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;- Link-up Sequence&lt;BR /&gt;Shutdown mode: Ports link up sequentially, starting from port 1&lt;BR /&gt;Auto mode: Existing links are retained, so sequence has no effect&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;- SFP Diagnostics&lt;BR /&gt;Shutdown Mode: Always performed at startup → Causes delay&lt;BR /&gt;Auto Mode: Diagnostics unnecessary → High speed&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;- Definition of Switchover Time&lt;BR /&gt;Shutdown Mode: None (slower is by design)&lt;BR /&gt;Auto Mode: Switchover possible in short time&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;- Manufacturer Recommended Settings&lt;BR /&gt;Shutdown Mode: Recommended (prioritizes safety)&lt;BR /&gt;Auto Mode: Not recommended (can be selected for speed optimization)&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Is it correct to understand that in Shutdown mode, link-up delays during switching are an OS specification, and the only way to speed it up is to change to Auto mode? However, in Auto mode, ports are always open, so depending on the configuration, there are concerns such as loops?&lt;/P&gt;</description>
      <pubDate>Wed, 26 Nov 2025 05:13:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/regarding-the-operational-specifications-for-ha-mode/m-p/1242625#M6486</guid>
      <dc:creator>n-tomo</dc:creator>
      <dc:date>2025-11-26T05:13:08Z</dc:date>
    </item>
    <item>
      <title>Re: Regarding the Operational Specifications for HA Mode</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/regarding-the-operational-specifications-for-ha-mode/m-p/1243288#M6502</link>
      <description>&lt;P&gt;Is my understanding of this matter incorrect?&lt;BR /&gt;I would appreciate it if someone could kindly respond.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Best regerds&lt;/P&gt;</description>
      <pubDate>Mon, 08 Dec 2025 01:48:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/regarding-the-operational-specifications-for-ha-mode/m-p/1243288#M6502</guid>
      <dc:creator>n-tomo</dc:creator>
      <dc:date>2025-12-08T01:48:49Z</dc:date>
    </item>
    <item>
      <title>Re: Regarding the Operational Specifications for HA Mode</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/regarding-the-operational-specifications-for-ha-mode/m-p/1243877#M6518</link>
      <description>&lt;P&gt;Please take a moment to review this.&lt;/P&gt;
&lt;P&gt;Thank you for your cooperation.&lt;/P&gt;</description>
      <pubDate>Mon, 15 Dec 2025 05:34:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/regarding-the-operational-specifications-for-ha-mode/m-p/1243877#M6518</guid>
      <dc:creator>n-tomo</dc:creator>
      <dc:date>2025-12-15T05:34:48Z</dc:date>
    </item>
    <item>
      <title>Re: Regarding the Operational Specifications for HA Mode</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/regarding-the-operational-specifications-for-ha-mode/m-p/1244079#M6534</link>
      <description>&lt;P data-start="2111" data-end="2317"&gt;You mentioned “ports link up sequentially, starting from port 1” — there is &lt;STRONG data-start="2225" data-end="2245"&gt;no documentation&lt;/STRONG&gt; that PAN-OS enforces a specific sequential order (Port1 → Port2 → …).&lt;/P&gt;
&lt;P data-start="2319" data-end="2341"&gt;&lt;STRONG data-start="2319" data-end="2339"&gt;Actual behavior:&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL data-start="2342" data-end="2701"&gt;
&lt;LI data-start="2342" data-end="2561"&gt;
&lt;P data-start="2344" data-end="2561"&gt;In &lt;STRONG data-start="2347" data-end="2359"&gt;Shutdown&lt;/STRONG&gt;, all passive data interfaces are &lt;EM data-start="2393" data-end="2416"&gt;administratively down&lt;/EM&gt; and only brought up when active; link up happens as normal OS initialization when the device takes over. &lt;SPAN class="" data-state="closed"&gt;&lt;SPAN class="ms-1 inline-flex max-w-full items-center relative top-[-0.094rem] animate-[show_150ms_ease-in]" data-testid="webpage-citation-pill"&gt;&lt;A class="flex h-4.5 overflow-hidden rounded-xl px-2 text-[9px] font-medium transition-colors duration-150 ease-in-out text-token-text-secondary! bg-[#F4F4F4]! dark:bg-[#303030]!" href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClcACAS&amp;amp;utm_source=chatgpt.com" target="_blank" rel="noopener"&gt;&lt;SPAN class="relative start-0 bottom-0 flex h-full w-full items-center"&gt;&lt;SPAN class="flex h-4 w-full items-center justify-between overflow-hidden"&gt;&lt;SPAN class="max-w-[15ch] grow truncate overflow-hidden text-center"&gt;knowledgebase.paloaltonetworks.com&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;LI data-start="2562" data-end="2701"&gt;
&lt;P data-start="2564" data-end="2701"&gt;In &lt;STRONG data-start="2567" data-end="2575"&gt;Auto&lt;/STRONG&gt;, physical interfaces stay up on passive and so sequence is not a factor for failover. &lt;SPAN class="" data-state="closed"&gt;&lt;SPAN class="ms-1 inline-flex max-w-full items-center relative top-[-0.094rem] animate-[show_150ms_ease-in]" data-testid="webpage-citation-pill"&gt;&lt;A class="flex h-4.5 overflow-hidden rounded-xl px-2 text-[9px] font-medium transition-colors duration-150 ease-in-out text-token-text-secondary! bg-[#F4F4F4]! dark:bg-[#303030]!" href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClcACAS&amp;amp;utm_source=chatgpt.com" target="_blank" rel="noopener"&gt;&lt;SPAN class="relative start-0 bottom-0 flex h-full w-full items-center"&gt;&lt;SPAN class="flex h-4 w-full items-center justify-between overflow-hidden"&gt;&lt;SPAN class="max-w-[15ch] grow truncate overflow-hidden text-center"&gt;knowledgebase.paloaltonetworks.com&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P data-start="2703" data-end="2726"&gt;&amp;nbsp;&lt;/P&gt;
&lt;BLOCKQUOTE data-start="2727" data-end="2949"&gt;
&lt;P data-start="2729" data-end="2949"&gt;“PAN-OS does not document a strict port ordering sequence. In shutdown mode the interfaces are down, so their subsequent ‘up’ event happens during transition; in auto mode they are already up, so no sequence dependency.”&lt;BR /&gt;&lt;BR /&gt;Any delay seen during a transition is due to the interface link negotiation (PHY coming up) rather than an explicit documented difference in SFP diagnostics between modes.”&lt;BR /&gt;&lt;BR /&gt;Switchover speeds are influenced by whether links are already up (Auto) versus needing to be brought up (Shutdown). There is no separate switchover timer inherent to Auto mode beyond this behavior.&lt;BR /&gt;&lt;BR /&gt;Palo Alto Networks recommends &lt;STRONG data-start="4542" data-end="4554"&gt;Shutdown&lt;/STRONG&gt; as the default, especially if the firewall interfaces reside in Layer-2 networks. &lt;STRONG data-start="4637" data-end="4645"&gt;Auto&lt;/STRONG&gt; is recommended only when interfaces do &lt;EM data-start="4685" data-end="4690"&gt;not&lt;/EM&gt; participate in Layer-2 forwarding to avoid unexpected behavior&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;H3 data-start="4816" data-end="4926"&gt;&lt;STRONG data-start="4820" data-end="4926"&gt;s it correct that in Shutdown mode delays are OS specification and only way to speed up is Auto mode?&lt;/STRONG&gt;&lt;/H3&gt;
&lt;P data-start="4927" data-end="4949"&gt;&lt;STRONG data-start="4927" data-end="4947"&gt;Accurate answer:&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL data-start="4950" data-end="5250"&gt;
&lt;LI data-start="4950" data-end="5250"&gt;
&lt;P data-start="4952" data-end="5250"&gt;Yes — shutdown behavior keeps passive interfaces down, requiring them to come up only when active. That adds link negotiation delay that cannot be avoided in Shutdown mode. Auto mode eliminates the need for PHY link up during failover by keeping interfaces up. &lt;SPAN class="" data-state="closed"&gt;&lt;SPAN class="ms-1 inline-flex max-w-full items-center relative top-[-0.094rem] animate-[show_150ms_ease-in]" data-testid="webpage-citation-pill"&gt;&lt;A class="flex h-4.5 overflow-hidden rounded-xl px-2 text-[9px] font-medium transition-colors duration-150 ease-in-out text-token-text-secondary! bg-[#F4F4F4]! dark:bg-[#303030]!" href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClcACAS&amp;amp;utm_source=chatgpt.com" target="_blank" rel="noopener"&gt;&lt;SPAN class="relative start-0 bottom-0 flex h-full w-full items-center"&gt;&lt;SPAN class="flex h-4 w-full items-center justify-between overflow-hidden"&gt;&lt;SPAN class="max-w-[15ch] grow truncate overflow-hidden text-center"&gt;knowledgebase.paloaltonetworks.com&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;H3 data-start="5252" data-end="5292"&gt;&lt;STRONG data-start="5256" data-end="5292"&gt;Is there loop risk in Auto mode?&lt;/STRONG&gt;&lt;/H3&gt;
&lt;P data-start="5293" data-end="5315"&gt;&amp;nbsp;&lt;/P&gt;
&lt;UL data-start="5316" data-end="5631"&gt;
&lt;LI data-start="5316" data-end="5631"&gt;
&lt;P data-start="5318" data-end="5631"&gt;Yes — because in Auto mode, passive interfaces are reported as up and neighbors (switches) may send traffic or cause MAC/ARP learning issues if not carefully designed. That’s why documentation explicitly warns &lt;STRONG data-start="5528" data-end="5592"&gt;not to select Auto if you have Layer-2 interfaces configured&lt;/STRONG&gt;.&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;/BLOCKQUOTE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 17 Dec 2025 20:10:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/regarding-the-operational-specifications-for-ha-mode/m-p/1244079#M6534</guid>
      <dc:creator>S.Cantwell</dc:creator>
      <dc:date>2025-12-17T20:10:10Z</dc:date>
    </item>
  </channel>
</rss>

