<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Tuning Panorama HA Timers to Stop False HA1 Alerts over MPLS in Panorama Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/panorama-discussions/tuning-panorama-ha-timers-to-stop-false-ha1-alerts-over-mpls/m-p/1248690#M3026</link>
    <description>&lt;P&gt;Hello Community,&lt;/P&gt;
&lt;P&gt;I’m looking for some advice on tweaking our Panorama HA timers. We are seeing "false" failover alerts and want to ensure our plan to fix them is balanced correctly.&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Setup:&lt;BR /&gt;Two Panoramas in an Active/Passive HA pair located in different Data Centers.&lt;BR /&gt;Communication is over a WAN MPLS link.&lt;BR /&gt;These manage two sets of firewalls (one set at each site); both Panoramas can push policies to all firewalls.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;Issue&lt;BR /&gt;Every 15 to 20 days, we get a sequence of HA alerts, though a full failover hasn't occurred yet. Support confirmed we are missing about 4 heartbeats due to transient jitter on our MPLS.&lt;/P&gt;
&lt;P&gt;The Alerts we receive (in order):&lt;BR /&gt;Primary Panorama: HA1 connection down.&lt;BR /&gt;Secondary Panorama: HA1 connection down.&lt;BR /&gt;Secondary Panorama: "HA peer determined to be Active through managed devices; staying in Passive state."&lt;/P&gt;
&lt;P&gt;Even though it stays Passive, these alerts generate concern internally. We are currently using the standard "Recommended" timer settings, which seem a bit aggressive for our WAN. We want to move to Advanced settings to tweak the timers and stop these false alarms while maintaining a safe response time for a real failure.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;Planned Changes:&lt;BR /&gt;Under Setup:&lt;BR /&gt;Monitor Hold Time: Increase from 3000ms to 8000ms or 10000ms.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;Under HA Advanced Settings:&lt;BR /&gt;Heartbeat Interval: Increase from 2000ms to 4000ms.&lt;BR /&gt;Hello Interval: Increase from 8000ms to 12000ms.&lt;BR /&gt;Additional Master Hold Up Time: Increase from 7000ms to 10000ms.&amp;nbsp;&lt;BR /&gt;Preemption Hold Time: Increase from 1 min to 2 min (or leave at 1 min?).&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Under Path Monitoring:&lt;BR /&gt;Path Monitoring: Currently enabled with Failure Condition: Any. Should we Disable this entirely since we do not have any Path Groups or IPs defined or is it fine to leave it enabled?&lt;/P&gt;</description>
    <pubDate>Fri, 20 Feb 2026 11:15:54 GMT</pubDate>
    <dc:creator>kunaltupe05</dc:creator>
    <dc:date>2026-02-20T11:15:54Z</dc:date>
    <item>
      <title>Tuning Panorama HA Timers to Stop False HA1 Alerts over MPLS</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/tuning-panorama-ha-timers-to-stop-false-ha1-alerts-over-mpls/m-p/1248690#M3026</link>
      <description>&lt;P&gt;Hello Community,&lt;/P&gt;
&lt;P&gt;I’m looking for some advice on tweaking our Panorama HA timers. We are seeing "false" failover alerts and want to ensure our plan to fix them is balanced correctly.&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Setup:&lt;BR /&gt;Two Panoramas in an Active/Passive HA pair located in different Data Centers.&lt;BR /&gt;Communication is over a WAN MPLS link.&lt;BR /&gt;These manage two sets of firewalls (one set at each site); both Panoramas can push policies to all firewalls.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;Issue&lt;BR /&gt;Every 15 to 20 days, we get a sequence of HA alerts, though a full failover hasn't occurred yet. Support confirmed we are missing about 4 heartbeats due to transient jitter on our MPLS.&lt;/P&gt;
&lt;P&gt;The Alerts we receive (in order):&lt;BR /&gt;Primary Panorama: HA1 connection down.&lt;BR /&gt;Secondary Panorama: HA1 connection down.&lt;BR /&gt;Secondary Panorama: "HA peer determined to be Active through managed devices; staying in Passive state."&lt;/P&gt;
&lt;P&gt;Even though it stays Passive, these alerts generate concern internally. We are currently using the standard "Recommended" timer settings, which seem a bit aggressive for our WAN. We want to move to Advanced settings to tweak the timers and stop these false alarms while maintaining a safe response time for a real failure.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;Planned Changes:&lt;BR /&gt;Under Setup:&lt;BR /&gt;Monitor Hold Time: Increase from 3000ms to 8000ms or 10000ms.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;Under HA Advanced Settings:&lt;BR /&gt;Heartbeat Interval: Increase from 2000ms to 4000ms.&lt;BR /&gt;Hello Interval: Increase from 8000ms to 12000ms.&lt;BR /&gt;Additional Master Hold Up Time: Increase from 7000ms to 10000ms.&amp;nbsp;&lt;BR /&gt;Preemption Hold Time: Increase from 1 min to 2 min (or leave at 1 min?).&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Under Path Monitoring:&lt;BR /&gt;Path Monitoring: Currently enabled with Failure Condition: Any. Should we Disable this entirely since we do not have any Path Groups or IPs defined or is it fine to leave it enabled?&lt;/P&gt;</description>
      <pubDate>Fri, 20 Feb 2026 11:15:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/tuning-panorama-ha-timers-to-stop-false-ha1-alerts-over-mpls/m-p/1248690#M3026</guid>
      <dc:creator>kunaltupe05</dc:creator>
      <dc:date>2026-02-20T11:15:54Z</dc:date>
    </item>
  </channel>
</rss>

