<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: datapalne issue in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/datapalne-issue/m-p/500945#M105212</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/155938"&gt;@dawoodJabbar&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;Hopefully you were able to resolve this over the weekend, however it seems like this is going to be harder to troubleshoot over a text based forum &amp;nbsp;and things may not have been in a good spot before your test. Hopefully if you haven't already done so, you've engaged TAC to look at this with you to rule out any configuration or device issues.&lt;/P&gt;
&lt;P&gt;A couple things that I have questions/observations on after a few of your comments:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Have you ever done a failover before and have it work, or is this a new Active/Passive configuration?&lt;/LI&gt;
&lt;LI&gt;Attempting to ping an interface isn't really that great of a test with PAN, as there's moving parts to having the traffic allowed. When you did the factory reset on the passive firewall, did you remember to active an interface-management profile that allowed ICMP and actually allow it on your rulebase assuming you weren't relying on intrazone-default?&amp;nbsp;&lt;/LI&gt;
&lt;LI&gt;On your passive firewall, what is the actual status of the device? When you go through and reset things and configure it, are you seeing the auto-commit and subsequent commits succeed?&amp;nbsp;&lt;/LI&gt;
&lt;LI&gt;Lastly if you're actively facing an issue with an HA test without making other prior changes, I'd really recommend NOT upgrading PAN-OS. You're really just introducing another set of variables to the issue, and you've now moved into a state where you had a known working HA-pair to start with to one that's in an unknown state. When trying to solve an issue, introducing changes just increases complexity.&amp;nbsp;&lt;/LI&gt;
&lt;/UL&gt;</description>
    <pubDate>Tue, 07 Jun 2022 02:08:51 GMT</pubDate>
    <dc:creator>BPry</dc:creator>
    <dc:date>2022-06-07T02:08:51Z</dc:date>
    <item>
      <title>datapalne issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/datapalne-issue/m-p/499646#M105189</link>
      <description>&lt;P&gt;I have 2 Paloalto firewalls working as ha active-passive, yesterday we had HA test so try to pass the traffic to the passive device buy suspend the active, the passive become active everything works fine till now my issue is the interface of the firewall 2 is not responding to anything ping or anything my network is down in Cisco switches showing interface up but not showing lldp Although lldp is enabled on Paloalto, now I’m rollback to firewall 1 Everything work fine, but the second firewall still its interfaces not working it’s up but not passing any traffic even when I try to connect PC directly to Interface There is no ping&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;even I tried to factory reset and still the same issue&amp;nbsp; and upgraded the device to the latest pan-os 2.0.1&lt;/P&gt;</description>
      <pubDate>Sun, 05 Jun 2022 05:32:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/datapalne-issue/m-p/499646#M105189</guid>
      <dc:creator>dawoodJabbar</dc:creator>
      <dc:date>2022-06-05T05:32:57Z</dc:date>
    </item>
    <item>
      <title>Re: datapalne issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/datapalne-issue/m-p/499649#M105190</link>
      <description>&lt;P&gt;The passive device does not respond to anything (besides on the mgn interface). That's due to moving the IP and MAC to the active node, the passive node has no IP on the "traffic" interfaces.&lt;/P&gt;&lt;P&gt;If you have LLDP enabled, please verify that "Enable in HA Passive State" is ticked (Interfaces --&amp;gt; Ethernet --&amp;gt; your Interface --&amp;gt; Advanced --&amp;gt; [x] Enable LLDP -- [x] Enable in HA Passive State)&lt;/P&gt;</description>
      <pubDate>Sun, 05 Jun 2022 06:02:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/datapalne-issue/m-p/499649#M105190</guid>
      <dc:creator>JoergSchuetter</dc:creator>
      <dc:date>2022-06-05T06:02:32Z</dc:date>
    </item>
    <item>
      <title>Re: datapalne issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/datapalne-issue/m-p/499654#M105191</link>
      <description>&lt;P&gt;the LLDP is enabled on the Passive firewall kindly check the attachment for that, I try to make the passive to be active but still have the same issue, I try to factory reset the firewall and try to do basic configuration just to check the issue is related to ha or we have a hardware issue in the data plane.&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="PA1.PNG" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/41590i67F7DEF72332B945/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="PA1.PNG" alt="PA1.PNG" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="PAN2.PNG" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/41591iFD310AD4B07F70FF/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="PAN2.PNG" alt="PAN2.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 05 Jun 2022 06:12:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/datapalne-issue/m-p/499654#M105191</guid>
      <dc:creator>dawoodJabbar</dc:creator>
      <dc:date>2022-06-05T06:12:33Z</dc:date>
    </item>
    <item>
      <title>Re: datapalne issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/datapalne-issue/m-p/499661#M105192</link>
      <description>&lt;P&gt;the LLDP Is enabled on the passive firewall, I try to suspend the local device for ha in the active firewall to move the traffic to the passive but the device does not forward any traffic, and it becomes active in ha, I also try to remove it from ha and upgraded the device to the latest pan-os 2.0.1 also factory reset the device but still same &lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="PA1.PNG" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/41592iA073896F23BF4588/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="PA1.PNG" alt="PA1.PNG" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="PAN2.PNG" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/41593iD32F3967FCF48E12/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="PAN2.PNG" alt="PAN2.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 05 Jun 2022 06:24:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/datapalne-issue/m-p/499661#M105192</guid>
      <dc:creator>dawoodJabbar</dc:creator>
      <dc:date>2022-06-05T06:24:52Z</dc:date>
    </item>
    <item>
      <title>Re: datapalne issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/datapalne-issue/m-p/499666#M105193</link>
      <description>&lt;P&gt;the LLDP is enabled on the passive firewall, I try to make the passive firewall become active but still faced the same issue also remove it from ha and check the interface but no luck, any idea&lt;/P&gt;</description>
      <pubDate>Sun, 05 Jun 2022 06:36:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/datapalne-issue/m-p/499666#M105193</guid>
      <dc:creator>dawoodJabbar</dc:creator>
      <dc:date>2022-06-05T06:36:13Z</dc:date>
    </item>
    <item>
      <title>Re: datapalne issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/datapalne-issue/m-p/499669#M105194</link>
      <description>&lt;P&gt;I try to upgrade the device to the latest pan-os 2.0.1 and still the same also factory reset the firewall and setup the basic configuration to check the interface but still same&lt;/P&gt;</description>
      <pubDate>Sun, 05 Jun 2022 06:38:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/datapalne-issue/m-p/499669#M105194</guid>
      <dc:creator>dawoodJabbar</dc:creator>
      <dc:date>2022-06-05T06:38:21Z</dc:date>
    </item>
    <item>
      <title>Re: datapalne issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/datapalne-issue/m-p/500696#M105206</link>
      <description>&lt;P&gt;Can you confirm the version you're using?&lt;/P&gt;</description>
      <pubDate>Mon, 06 Jun 2022 20:35:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/datapalne-issue/m-p/500696#M105206</guid>
      <dc:creator>rmfalconer</dc:creator>
      <dc:date>2022-06-06T20:35:47Z</dc:date>
    </item>
    <item>
      <title>Re: datapalne issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/datapalne-issue/m-p/500945#M105212</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/155938"&gt;@dawoodJabbar&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;Hopefully you were able to resolve this over the weekend, however it seems like this is going to be harder to troubleshoot over a text based forum &amp;nbsp;and things may not have been in a good spot before your test. Hopefully if you haven't already done so, you've engaged TAC to look at this with you to rule out any configuration or device issues.&lt;/P&gt;
&lt;P&gt;A couple things that I have questions/observations on after a few of your comments:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Have you ever done a failover before and have it work, or is this a new Active/Passive configuration?&lt;/LI&gt;
&lt;LI&gt;Attempting to ping an interface isn't really that great of a test with PAN, as there's moving parts to having the traffic allowed. When you did the factory reset on the passive firewall, did you remember to active an interface-management profile that allowed ICMP and actually allow it on your rulebase assuming you weren't relying on intrazone-default?&amp;nbsp;&lt;/LI&gt;
&lt;LI&gt;On your passive firewall, what is the actual status of the device? When you go through and reset things and configure it, are you seeing the auto-commit and subsequent commits succeed?&amp;nbsp;&lt;/LI&gt;
&lt;LI&gt;Lastly if you're actively facing an issue with an HA test without making other prior changes, I'd really recommend NOT upgrading PAN-OS. You're really just introducing another set of variables to the issue, and you've now moved into a state where you had a known working HA-pair to start with to one that's in an unknown state. When trying to solve an issue, introducing changes just increases complexity.&amp;nbsp;&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Tue, 07 Jun 2022 02:08:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/datapalne-issue/m-p/500945#M105212</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2022-06-07T02:08:51Z</dc:date>
    </item>
    <item>
      <title>Re: datapalne issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/datapalne-issue/m-p/500986#M105215</link>
      <description>&lt;P&gt;Have you ever done a failover before and have it work,&lt;/P&gt;&lt;P&gt;yes we have tested the ha failover about 6 Months ago.&lt;/P&gt;&lt;P&gt;is this a new Active/Passive configuration?&lt;/P&gt;&lt;P&gt;no.&lt;/P&gt;&lt;P&gt;On your passive firewall, what is the actual status of the device?&lt;/P&gt;&lt;P&gt;the management plane works fine but the data plane is not working the data plane session count is zero.&lt;/P&gt;&lt;P&gt;When you go through and reset things and configure it?&lt;/P&gt;&lt;P&gt;after upgrading the passive i thought its a configuration issue so i&amp;nbsp;factory rest the device to sure by using this command&lt;/P&gt;&lt;P&gt;request system private-data-reset and also do the factory rest by palo alto factory reset maintenance mode same thing no responses&lt;/P&gt;&lt;P&gt;on data plane&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp; are you seeing the auto-commit and subsequent commits succeed?&lt;/P&gt;&lt;P&gt;yes, and I do some change and the commits working fine&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Attempting to ping an interface isn't really that great of a test with PAN, as there's moving parts to having the traffic allowed. When you did the factory reset on the passive firewall, did you remember to active an interface-management profile that allowed ICMP and actually allow it on your rulebase assuming you weren't relying on intrazone-default?&lt;/P&gt;&lt;P&gt;yes i add icmp in the interface-management profile and apply this on the interface that was under test,and i creat new rule to allowed&lt;/P&gt;&lt;P&gt;the traffic to pass the firewall ,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;i also try do downgrade to 10.1.5h2 after factory rest and no luck&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 07 Jun 2022 05:17:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/datapalne-issue/m-p/500986#M105215</guid>
      <dc:creator>dawoodJabbar</dc:creator>
      <dc:date>2022-06-07T05:17:38Z</dc:date>
    </item>
    <item>
      <title>Re: datapalne issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/datapalne-issue/m-p/501249#M105233</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/155938"&gt;@dawoodJabbar&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;I am little confused by what is the acutal problem you are facing...&lt;/P&gt;
&lt;P&gt;Am I understand correctly that:&lt;/P&gt;
&lt;P&gt;- You have failovered to second member and no traffic was passing over the firewall&lt;/P&gt;
&lt;P&gt;- You have removed this member from HA, factory reset it and try to use it as standalone but still no traffic is passing the firewall?&lt;/P&gt;</description>
      <pubDate>Tue, 07 Jun 2022 14:41:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/datapalne-issue/m-p/501249#M105233</guid>
      <dc:creator>aleksandar.astardzhiev</dc:creator>
      <dc:date>2022-06-07T14:41:36Z</dc:date>
    </item>
    <item>
      <title>Re: datapalne issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/datapalne-issue/m-p/501261#M105234</link>
      <description>&lt;P&gt;Yes exactly today Palo Alto TAC team investigate this issue with me about six &amp;nbsp;hours they &amp;nbsp;collect log and try everything downgrade but no luck actually they say that its data plane issue and will investigate more in the log they took and if they nothing found it’s RMA&lt;/P&gt;</description>
      <pubDate>Tue, 07 Jun 2022 14:48:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/datapalne-issue/m-p/501261#M105234</guid>
      <dc:creator>dawoodJabbar</dc:creator>
      <dc:date>2022-06-07T14:48:09Z</dc:date>
    </item>
  </channel>
</rss>

