<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: HA problem Pa 410, Pa 3250 in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/ha-problem-pa-410-pa-3250/m-p/542771#M111161</link>
    <description>&lt;P&gt;--- Are the ports connected to the passive NGFW up on both switches?&lt;BR /&gt;Yes all ports up&lt;/P&gt;
&lt;P&gt;----What STP state are they in?&lt;BR /&gt;default i'm not configure enable only spanning-tree mode rapid-pvst&lt;/P&gt;
&lt;P&gt;Perform a failover and watch the ports transition.&amp;nbsp; Also check how fast the MAC addresses switch to the new ports.&lt;BR /&gt;--- I can check how I will be directly connected to the switch, the firewalls are in a remote location&lt;/P&gt;
&lt;P&gt;Does your HA widget in the Dashboard show all HA links are green?&lt;BR /&gt;--- all links are green&lt;/P&gt;</description>
    <pubDate>Fri, 19 May 2023 18:19:44 GMT</pubDate>
    <dc:creator>krzysztof.kubiak</dc:creator>
    <dc:date>2023-05-19T18:19:44Z</dc:date>
    <item>
      <title>HA problem Pa 410, Pa 3250</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ha-problem-pa-410-pa-3250/m-p/542684#M111149</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Hi all.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;I created an HA group from device PA410 (the same problem on PA3250) mode active-standby ,&amp;nbsp;when i switch active device to passive, the passive device becomes active and i have a problem.&amp;nbsp;there is no access to the firewall for about a minute&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;the following occurs for Pan OS 10.1.8&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="PAN OS 10.1.8.PNG" style="width: 649px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/50247iEB634F1004FE9A87/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="PAN OS 10.1.8.PNG" alt="PAN OS 10.1.8.PNG" /&gt;&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;I did update pan os to version 10.1.9 h3&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;I see a slight improvement but still the unavailability time&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="PAN OS 10.1.9 h3.PNG" style="width: 515px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/50248i7B8F9577085922A7/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="PAN OS 10.1.9 h3.PNG" alt="PAN OS 10.1.9 h3.PNG" /&gt;&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;the configuration of the HA group has not changed, as far as I remember on PAN OS 9.1.x I did not have this problem and now it occurs for devices of the 3250 and 410, 440 series&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 19 May 2023 05:23:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ha-problem-pa-410-pa-3250/m-p/542684#M111149</guid>
      <dc:creator>krzysztof.kubiak</dc:creator>
      <dc:date>2023-05-19T05:23:42Z</dc:date>
    </item>
    <item>
      <title>Re: HA problem Pa 410, Pa 3250</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ha-problem-pa-410-pa-3250/m-p/542738#M111151</link>
      <description>&lt;P&gt;Sounds like underlying network issue where spanning tree takes time to enable ports.&lt;/P&gt;
&lt;P&gt;It is possible switch passive firewall ports from shut down to active all the time but before this can be suggested we need to know more about your environment.&lt;/P&gt;
&lt;P&gt;Current HA "Passive Link State" configuration.&lt;/P&gt;
&lt;P&gt;Any AE interfaces connecting to switch?&lt;/P&gt;
&lt;P&gt;If yes then do you have LACP and do you have port channel in switch by firewall or are all ports to both firewalls in single port channel (bad).&lt;/P&gt;</description>
      <pubDate>Fri, 19 May 2023 12:56:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ha-problem-pa-410-pa-3250/m-p/542738#M111151</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2023-05-19T12:56:38Z</dc:date>
    </item>
    <item>
      <title>Re: HA problem Pa 410, Pa 3250</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ha-problem-pa-410-pa-3250/m-p/542749#M111152</link>
      <description>&lt;P&gt;Bellow my branch diagram,&amp;nbsp;The connection between Palo and the switch is one access link&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;configuration ha Pasive link state :auto&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="network fiagram.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/50255i5EB0BFA0AA5EF536/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="network fiagram.png" alt="network fiagram.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;When I change to make activ devices standby and standby activ device i lost conection from lan to internet.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;All port on switch going down and up :&lt;/P&gt;
&lt;P&gt;May 19 16:29:30 CEST: %LINK-3-UPDOWN: Interface GigabitEthernet0/8, changed state to down&lt;BR /&gt;May 19 16:29:33 CEST: %LINK-3-UPDOWN: Interface GigabitEthernet0/8, changed state to up&lt;/P&gt;
&lt;P&gt;May 19 16:29:37 CEST: %LINK-3-UPDOWN: Interface GigabitEthernet0/10, changed state to down&lt;BR /&gt;May 19 16:29:41 CEST: %LINK-3-UPDOWN: Interface GigabitEthernet0/10, changed state to up&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;i'm try use on switch port configuration&amp;nbsp;spanning-tree portfast&amp;nbsp;But this does not bring improvement&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 19 May 2023 14:56:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ha-problem-pa-410-pa-3250/m-p/542749#M111152</guid>
      <dc:creator>krzysztof.kubiak</dc:creator>
      <dc:date>2023-05-19T14:56:16Z</dc:date>
    </item>
    <item>
      <title>Re: HA problem Pa 410, Pa 3250</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ha-problem-pa-410-pa-3250/m-p/542755#M111154</link>
      <description>&lt;P&gt;As next step I suggest to configure packet capture on passive firewall by configuring interface that connects to Cisco switch and include non-ip traffic.&lt;/P&gt;
&lt;P&gt;Check how long it takes for traffic to start flowing in after firewall becomes active.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Raido_Rattameister_0-1684510322555.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/50257i4445C8EAA8F31528/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Raido_Rattameister_0-1684510322555.png" alt="Raido_Rattameister_0-1684510322555.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Just a random suggestion that is not related to your issue.&lt;/P&gt;
&lt;P&gt;HA1 is related to mgmt plane.&lt;/P&gt;
&lt;P&gt;HA2 is related to dataplane.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I would flip those ports around.&lt;/P&gt;
&lt;P&gt;HA1 is used to replicate config and send heart beats.&lt;/P&gt;
&lt;P&gt;Dedicated mgmt port is connected to mgmt plane but&amp;nbsp;eth1/6 is connected to dataplane so this is not optimal setup.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Raido_Rattameister_1-1684510404988.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/50258iDC9050750E68858A/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Raido_Rattameister_1-1684510404988.png" alt="Raido_Rattameister_1-1684510404988.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 19 May 2023 15:36:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ha-problem-pa-410-pa-3250/m-p/542755#M111154</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2023-05-19T15:36:34Z</dc:date>
    </item>
    <item>
      <title>Re: HA problem Pa 410, Pa 3250</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ha-problem-pa-410-pa-3250/m-p/542759#M111155</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/147329"&gt;@krzysztof.kubiak&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have PA-450s on 10.1.9-h3, and I do not have this problem.&amp;nbsp; Failover is immediate.&amp;nbsp; For this issue, you need to look at the switches.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Are the ports connected to the passive NGFW up on both switches?&lt;/LI&gt;
&lt;LI&gt;What STP state are they in?&lt;/LI&gt;
&lt;LI&gt;Perform a failover and watch the ports transition.&amp;nbsp; Also check how fast the MAC addresses switch to the new ports.&lt;/LI&gt;
&lt;LI&gt;Does your HA widget in the Dashboard show all HA links are green?&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;A minute outage sounds like an STP convergence issue.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;</description>
      <pubDate>Fri, 19 May 2023 16:11:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ha-problem-pa-410-pa-3250/m-p/542759#M111155</guid>
      <dc:creator>TomYoung</dc:creator>
      <dc:date>2023-05-19T16:11:04Z</dc:date>
    </item>
    <item>
      <title>Re: HA problem Pa 410, Pa 3250</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ha-problem-pa-410-pa-3250/m-p/542771#M111161</link>
      <description>&lt;P&gt;--- Are the ports connected to the passive NGFW up on both switches?&lt;BR /&gt;Yes all ports up&lt;/P&gt;
&lt;P&gt;----What STP state are they in?&lt;BR /&gt;default i'm not configure enable only spanning-tree mode rapid-pvst&lt;/P&gt;
&lt;P&gt;Perform a failover and watch the ports transition.&amp;nbsp; Also check how fast the MAC addresses switch to the new ports.&lt;BR /&gt;--- I can check how I will be directly connected to the switch, the firewalls are in a remote location&lt;/P&gt;
&lt;P&gt;Does your HA widget in the Dashboard show all HA links are green?&lt;BR /&gt;--- all links are green&lt;/P&gt;</description>
      <pubDate>Fri, 19 May 2023 18:19:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ha-problem-pa-410-pa-3250/m-p/542771#M111161</guid>
      <dc:creator>krzysztof.kubiak</dc:creator>
      <dc:date>2023-05-19T18:19:44Z</dc:date>
    </item>
    <item>
      <title>Re: HA problem Pa 410, Pa 3250</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ha-problem-pa-410-pa-3250/m-p/542773#M111162</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/147329"&gt;@krzysztof.kubiak&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;RSTP ports still can be in a blocking state.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You may need to have someone on site to troubleshoot.&amp;nbsp; It is most likely a L2 problem.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;</description>
      <pubDate>Fri, 19 May 2023 18:24:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ha-problem-pa-410-pa-3250/m-p/542773#M111162</guid>
      <dc:creator>TomYoung</dc:creator>
      <dc:date>2023-05-19T18:24:54Z</dc:date>
    </item>
  </channel>
</rss>

