<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Panorama HA1 connection daily flips because of buffer space in Panorama Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/panorama-discussions/panorama-ha1-connection-daily-flips-because-of-buffer-space/m-p/594495#M2432</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have a case with TAC regarding this issue for 4 months now so I figured I would try my luck here.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;My issue is a HA split-brain problem between Panorama Active and Passive appliances in 2 different physical locations.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The issue is that HA1 breaks for 1 second briefly because: health-check fails -&amp;gt; ICMP packets are not sent from primary devices -&amp;gt; buffer memory for ICMP packets is unavailable.&lt;BR /&gt;&lt;BR /&gt;The failover is &lt;STRONG&gt;NOT&lt;/STRONG&gt; happening because it buffer unavailability is very brief but still enough to generate Critical Alerts and mess up our monitoring systems (but no production impact).&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;less mp-log ha_agent.log&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;2024-06-03 08:19:41.162 +0200 Error: ha_ping_peer_miss(src/ha_ping.c:764): Missed 1 ping timeouts out of 3 (ha1)&lt;BR /&gt;2024-06-03 08:19:43.163 +0200 Error: ha_ping_send(src/ha_ping.c:604): Unable to send icmp packet:(errno: 105) No buffer space available&lt;BR /&gt;2024-06-03 08:19:43.163 +0200 Error: ha_ping_peer_miss(src/ha_ping.c:764): Missed 2 ping timeouts out of 3 (ha1)&lt;BR /&gt;2024-06-03 08:19:43.599 +0200 Received HA1 MAC address: 00:50:56:a4:22:b9&lt;BR /&gt;2024-06-03 08:19:43.630 +0200 Received HA1 MAC address: 00:50:56:a4:22:b9&lt;BR /&gt;2024-06-03 08:19:44.251 +0200 debug: ha_peer_recv_error(src/ha_peer.c:5781): Group 0 (HA1-MAIN): Receiving error message&lt;/P&gt;
&lt;P&gt;Msg Hdr&lt;BR /&gt;-------&lt;BR /&gt;version : 1&lt;BR /&gt;groupID : 0&lt;BR /&gt;type : Error (5)&lt;BR /&gt;token : 0x702a&lt;BR /&gt;flags : 0x1 (req:)&lt;BR /&gt;length : 59&lt;/P&gt;
&lt;P&gt;Error Msg&lt;BR /&gt;---------&lt;BR /&gt;flags : 0x2 (close:)&lt;BR /&gt;err code : Heartbeat ping failure (16)&lt;BR /&gt;num tlvs : 1&lt;BR /&gt;Printing out 1 tlvs&lt;BR /&gt;TLV[1]: type 5 (ERR_STRING); len 23; value:&lt;BR /&gt;48656172 74626561 74207069 6e672066 61696c75 726500&lt;/P&gt;
&lt;P&gt;2024-06-03 08:19:44.251 +0200 Warning: ha_event_log(src/ha_event.c:59): HA1 connection down&lt;BR /&gt;2024-06-03 08:19:44.253 +0200 Error: ha_peer_primary_link_switchover(src/ha_peer.c:2531): Group 0: Unable to find a primary interface to switch&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Palo Alto has documentation for split-brain but all documentation is for &lt;STRONG&gt;NGFW&lt;/STRONG&gt; Physical appliances and &lt;STRONG&gt;not&lt;/STRONG&gt; Panorama.&lt;BR /&gt;&lt;BR /&gt;Does anybody have any suggestions how to fix this issue? Thanks for any help!&lt;/P&gt;</description>
    <pubDate>Fri, 09 Aug 2024 12:43:15 GMT</pubDate>
    <dc:creator>LukasOsipovic</dc:creator>
    <dc:date>2024-08-09T12:43:15Z</dc:date>
    <item>
      <title>Panorama HA1 connection daily flips because of buffer space</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/panorama-ha1-connection-daily-flips-because-of-buffer-space/m-p/594495#M2432</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have a case with TAC regarding this issue for 4 months now so I figured I would try my luck here.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;My issue is a HA split-brain problem between Panorama Active and Passive appliances in 2 different physical locations.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The issue is that HA1 breaks for 1 second briefly because: health-check fails -&amp;gt; ICMP packets are not sent from primary devices -&amp;gt; buffer memory for ICMP packets is unavailable.&lt;BR /&gt;&lt;BR /&gt;The failover is &lt;STRONG&gt;NOT&lt;/STRONG&gt; happening because it buffer unavailability is very brief but still enough to generate Critical Alerts and mess up our monitoring systems (but no production impact).&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;less mp-log ha_agent.log&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;2024-06-03 08:19:41.162 +0200 Error: ha_ping_peer_miss(src/ha_ping.c:764): Missed 1 ping timeouts out of 3 (ha1)&lt;BR /&gt;2024-06-03 08:19:43.163 +0200 Error: ha_ping_send(src/ha_ping.c:604): Unable to send icmp packet:(errno: 105) No buffer space available&lt;BR /&gt;2024-06-03 08:19:43.163 +0200 Error: ha_ping_peer_miss(src/ha_ping.c:764): Missed 2 ping timeouts out of 3 (ha1)&lt;BR /&gt;2024-06-03 08:19:43.599 +0200 Received HA1 MAC address: 00:50:56:a4:22:b9&lt;BR /&gt;2024-06-03 08:19:43.630 +0200 Received HA1 MAC address: 00:50:56:a4:22:b9&lt;BR /&gt;2024-06-03 08:19:44.251 +0200 debug: ha_peer_recv_error(src/ha_peer.c:5781): Group 0 (HA1-MAIN): Receiving error message&lt;/P&gt;
&lt;P&gt;Msg Hdr&lt;BR /&gt;-------&lt;BR /&gt;version : 1&lt;BR /&gt;groupID : 0&lt;BR /&gt;type : Error (5)&lt;BR /&gt;token : 0x702a&lt;BR /&gt;flags : 0x1 (req:)&lt;BR /&gt;length : 59&lt;/P&gt;
&lt;P&gt;Error Msg&lt;BR /&gt;---------&lt;BR /&gt;flags : 0x2 (close:)&lt;BR /&gt;err code : Heartbeat ping failure (16)&lt;BR /&gt;num tlvs : 1&lt;BR /&gt;Printing out 1 tlvs&lt;BR /&gt;TLV[1]: type 5 (ERR_STRING); len 23; value:&lt;BR /&gt;48656172 74626561 74207069 6e672066 61696c75 726500&lt;/P&gt;
&lt;P&gt;2024-06-03 08:19:44.251 +0200 Warning: ha_event_log(src/ha_event.c:59): HA1 connection down&lt;BR /&gt;2024-06-03 08:19:44.253 +0200 Error: ha_peer_primary_link_switchover(src/ha_peer.c:2531): Group 0: Unable to find a primary interface to switch&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Palo Alto has documentation for split-brain but all documentation is for &lt;STRONG&gt;NGFW&lt;/STRONG&gt; Physical appliances and &lt;STRONG&gt;not&lt;/STRONG&gt; Panorama.&lt;BR /&gt;&lt;BR /&gt;Does anybody have any suggestions how to fix this issue? Thanks for any help!&lt;/P&gt;</description>
      <pubDate>Fri, 09 Aug 2024 12:43:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/panorama-ha1-connection-daily-flips-because-of-buffer-space/m-p/594495#M2432</guid>
      <dc:creator>LukasOsipovic</dc:creator>
      <dc:date>2024-08-09T12:43:15Z</dc:date>
    </item>
  </channel>
</rss>

