<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: HA Interfaces failover triggers in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/ha-interfaces-failover-triggers/m-p/515718#M107111</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;Set the setting on the interface group to ALL. This way both interfaces have to be down to trigger a failover.&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;</description>
    <pubDate>Thu, 22 Sep 2022 17:41:08 GMT</pubDate>
    <dc:creator>OtakarKlier</dc:creator>
    <dc:date>2022-09-22T17:41:08Z</dc:date>
    <item>
      <title>HA Interfaces failover triggers</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ha-interfaces-failover-triggers/m-p/515611#M107084</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We currently have a pair of PA-5250 firewalls configured in active/passive. We have 4 port channel groups configured with the condition set to 'all'.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The question i have is we are using eth1/1 &amp;amp; eth1/2 as HA interfaces if one of these goes down will the firewalls failover?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Also is it possible to stop a interface from causing a failover? the global link monitoring configuration is set to 'any'&lt;/P&gt;&lt;BR /&gt;&lt;BR /&gt;Please note you are posting a public message where community members and experts can provide assistance. Sharing private information such as serial numbers or company information is not recommended.</description>
      <pubDate>Wed, 21 Sep 2022 15:11:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ha-interfaces-failover-triggers/m-p/515611#M107084</guid>
      <dc:creator>ElliotM</dc:creator>
      <dc:date>2022-09-21T15:11:02Z</dc:date>
    </item>
    <item>
      <title>Re: HA Interfaces failover triggers</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ha-interfaces-failover-triggers/m-p/515648#M107094</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/117258"&gt;@ElliotM&lt;/a&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If one of the interface that is configured for HA goes down, it will not cause failover event because these interfaces are not tracked, however as a best practice you should have a backup link for HA1 as well as for HA2 interfaces.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If HA1 interface goes down without HA1 backup to be configured, it might cause split brain when both Firewalls go into active state:&amp;nbsp;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u0000004OPJCA2&amp;amp;lang=en_US%E2%80%A9" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u0000004OPJCA2&amp;amp;lang=en_US%E2%80%A9&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If HA2 interface goes down without HA2 backup to be configured, the state information between Firewalls will not be in sync.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Here is HA Best Practice KB:&amp;nbsp;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000Cm5ZCAS" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000Cm5ZCAS&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you want to exempt an interface from failover tracking, I would remove it from link interface monitoring.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Kind Regards&lt;/P&gt;
&lt;P&gt;Pavel&lt;/P&gt;</description>
      <pubDate>Wed, 21 Sep 2022 21:21:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ha-interfaces-failover-triggers/m-p/515648#M107094</guid>
      <dc:creator>PavelK</dc:creator>
      <dc:date>2022-09-21T21:21:54Z</dc:date>
    </item>
    <item>
      <title>Re: HA Interfaces failover triggers</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ha-interfaces-failover-triggers/m-p/515718#M107111</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;Set the setting on the interface group to ALL. This way both interfaces have to be down to trigger a failover.&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Thu, 22 Sep 2022 17:41:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ha-interfaces-failover-triggers/m-p/515718#M107111</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2022-09-22T17:41:08Z</dc:date>
    </item>
    <item>
      <title>Re: HA Interfaces failover triggers</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ha-interfaces-failover-triggers/m-p/515792#M107125</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Just to be sure you are saying the HA interfaces are not tracked via the link monitoring even if they are not the dedicated HA ports.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Also thanks for the other info, we have backup HA1 &amp;amp; HA2.&lt;/P&gt;</description>
      <pubDate>Fri, 23 Sep 2022 08:20:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ha-interfaces-failover-triggers/m-p/515792#M107125</guid>
      <dc:creator>ElliotM</dc:creator>
      <dc:date>2022-09-23T08:20:06Z</dc:date>
    </item>
    <item>
      <title>Re: HA Interfaces failover triggers</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ha-interfaces-failover-triggers/m-p/515798#M107129</link>
      <description>&lt;P&gt;Thank you for reply&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/117258"&gt;@ElliotM&lt;/a&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Yes, this is my understanding. It is possible to set regular data plane interfaces to HA type and add it to HA Link Monitoring, however based on my tests shutting this interface down does not trigger a failover. I was testing it with PA-220 where I used interfaces 1/7 and 1/8 for HA.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Kind Regards&lt;/P&gt;
&lt;P&gt;Pavel&lt;/P&gt;</description>
      <pubDate>Fri, 23 Sep 2022 09:58:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ha-interfaces-failover-triggers/m-p/515798#M107129</guid>
      <dc:creator>PavelK</dc:creator>
      <dc:date>2022-09-23T09:58:44Z</dc:date>
    </item>
  </channel>
</rss>

