<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Firewall HA - Confirmation  Behavioral - Link Monitor - HA Vwire - Active Passive - Link state Shutdown in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/firewall-ha-confirmation-behavioral-link-monitor-ha-vwire-active/m-p/552562#M112409</link>
    <description>&lt;P class="_1qeIAgB0cPwnLhDF9XSiJM"&gt;Hello Live Community , good evening, how are you, I hope you are very well.&lt;/P&gt;
&lt;P class="_1qeIAgB0cPwnLhDF9XSiJM"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="_1qeIAgB0cPwnLhDF9XSiJM"&gt;I have a question that I would like you to confirm and comment on please. Thank you for your collaboration and for your good vibes.&lt;/P&gt;
&lt;P class="_1qeIAgB0cPwnLhDF9XSiJM"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="_1qeIAgB0cPwnLhDF9XSiJM"&gt;In a VWire Active-Passive HA environment, where this topology exists.&lt;/P&gt;
&lt;P class="_1qeIAgB0cPwnLhDF9XSiJM"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="_1qeIAgB0cPwnLhDF9XSiJM"&gt;Firewall-01 on VWire Active ----- Firewall-02 on VWire Passive&lt;/P&gt;
&lt;P class="_1qeIAgB0cPwnLhDF9XSiJM"&gt;Interfaces 1/1 and 1/2 Vwire-01&lt;/P&gt;
&lt;P class="_1qeIAgB0cPwnLhDF9XSiJM"&gt;Firewall-01 Priority 50&lt;/P&gt;
&lt;P class="_1qeIAgB0cPwnLhDF9XSiJM"&gt;Firewall-02 Priority 100&lt;/P&gt;
&lt;P class="_1qeIAgB0cPwnLhDF9XSiJM"&gt;Preemtive enabled on both computers.&lt;/P&gt;
&lt;P class="_1qeIAgB0cPwnLhDF9XSiJM"&gt;Preemtive Hold time: 1 Minute ( Default value ).&lt;/P&gt;
&lt;P class="_1qeIAgB0cPwnLhDF9XSiJM"&gt;Passive Link State: Shutdown&lt;/P&gt;
&lt;P class="_1qeIAgB0cPwnLhDF9XSiJM"&gt;Vwire: Link-State-Pass-Through enable ( Default ).&lt;/P&gt;
&lt;P class="_1qeIAgB0cPwnLhDF9XSiJM"&gt;Link monitor on both firewalls:&lt;/P&gt;
&lt;P class="_1qeIAgB0cPwnLhDF9XSiJM"&gt;Firewall-01: Ethernet 1/1 and 1/2 - ANY Interface&lt;/P&gt;
&lt;P class="_1qeIAgB0cPwnLhDF9XSiJM"&gt;Firewall-02: Ethernet 1/1 and 1/2 - ANY Interface&lt;/P&gt;
&lt;P class="_1qeIAgB0cPwnLhDF9XSiJM"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="_1qeIAgB0cPwnLhDF9XSiJM"&gt;Failure Scenario:&lt;/P&gt;
&lt;P class="_1qeIAgB0cPwnLhDF9XSiJM"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="_1qeIAgB0cPwnLhDF9XSiJM"&gt;In the event of a failure in the Firewall-01 Ethernet 1/1 and 1/2 interface. Firewall-02 will assume the role of Active.&lt;/P&gt;
&lt;P class="_1qeIAgB0cPwnLhDF9XSiJM"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="_1qeIAgB0cPwnLhDF9XSiJM"&gt;If Firewall-01 recovers from its failure in its Ethernet interfaces 1/1 and 1/2, Firewall-02 of the secondary block (with the Role of Active) will wait 1 minute (Preemtive Hold Time 1 minute) to redeliver the Active Role to Firewall-01 to the main block.&lt;/P&gt;
&lt;P class="_1qeIAgB0cPwnLhDF9XSiJM"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="_1qeIAgB0cPwnLhDF9XSiJM"&gt;Or for this to work, should the secondary be in Passive Link Auto so that it is negotiating and not in Passive Link Shutdown? This is because I have a doubt, since how is it going to detect the Palo Alto that recovered from its failure condition, from the link monitor, if it has its interfaces down, they should be on auto, right?&lt;/P&gt;
&lt;P class="_1qeIAgB0cPwnLhDF9XSiJM"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="_1qeIAgB0cPwnLhDF9XSiJM"&gt;In HA VWire environment I'm not entirely familiar versus L3 environments.&lt;/P&gt;
&lt;P class="_1qeIAgB0cPwnLhDF9XSiJM"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="_1qeIAgB0cPwnLhDF9XSiJM"&gt;Com VWire according to what I comment, especially in the scenario of failure and recovery of the Principal, is this expected behavior correct? or with VWire is it different? should assume or validate other additional details, regarding HA issues, such as Timers, settings, options, etc.&lt;/P&gt;
&lt;P class="_1qeIAgB0cPwnLhDF9XSiJM"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="_1qeIAgB0cPwnLhDF9XSiJM"&gt;Thank you in advance for your time, for your good vibes, for your collaboration, advice and comments.&lt;/P&gt;
&lt;P class="_1qeIAgB0cPwnLhDF9XSiJM"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="_1qeIAgB0cPwnLhDF9XSiJM"&gt;Greetings&lt;/P&gt;</description>
    <pubDate>Fri, 04 Aug 2023 09:14:46 GMT</pubDate>
    <dc:creator>Metgatz</dc:creator>
    <dc:date>2023-08-04T09:14:46Z</dc:date>
    <item>
      <title>Firewall HA - Confirmation  Behavioral - Link Monitor - HA Vwire - Active Passive - Link state Shutdown</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/firewall-ha-confirmation-behavioral-link-monitor-ha-vwire-active/m-p/552562#M112409</link>
      <description>&lt;P class="_1qeIAgB0cPwnLhDF9XSiJM"&gt;Hello Live Community , good evening, how are you, I hope you are very well.&lt;/P&gt;
&lt;P class="_1qeIAgB0cPwnLhDF9XSiJM"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="_1qeIAgB0cPwnLhDF9XSiJM"&gt;I have a question that I would like you to confirm and comment on please. Thank you for your collaboration and for your good vibes.&lt;/P&gt;
&lt;P class="_1qeIAgB0cPwnLhDF9XSiJM"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="_1qeIAgB0cPwnLhDF9XSiJM"&gt;In a VWire Active-Passive HA environment, where this topology exists.&lt;/P&gt;
&lt;P class="_1qeIAgB0cPwnLhDF9XSiJM"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="_1qeIAgB0cPwnLhDF9XSiJM"&gt;Firewall-01 on VWire Active ----- Firewall-02 on VWire Passive&lt;/P&gt;
&lt;P class="_1qeIAgB0cPwnLhDF9XSiJM"&gt;Interfaces 1/1 and 1/2 Vwire-01&lt;/P&gt;
&lt;P class="_1qeIAgB0cPwnLhDF9XSiJM"&gt;Firewall-01 Priority 50&lt;/P&gt;
&lt;P class="_1qeIAgB0cPwnLhDF9XSiJM"&gt;Firewall-02 Priority 100&lt;/P&gt;
&lt;P class="_1qeIAgB0cPwnLhDF9XSiJM"&gt;Preemtive enabled on both computers.&lt;/P&gt;
&lt;P class="_1qeIAgB0cPwnLhDF9XSiJM"&gt;Preemtive Hold time: 1 Minute ( Default value ).&lt;/P&gt;
&lt;P class="_1qeIAgB0cPwnLhDF9XSiJM"&gt;Passive Link State: Shutdown&lt;/P&gt;
&lt;P class="_1qeIAgB0cPwnLhDF9XSiJM"&gt;Vwire: Link-State-Pass-Through enable ( Default ).&lt;/P&gt;
&lt;P class="_1qeIAgB0cPwnLhDF9XSiJM"&gt;Link monitor on both firewalls:&lt;/P&gt;
&lt;P class="_1qeIAgB0cPwnLhDF9XSiJM"&gt;Firewall-01: Ethernet 1/1 and 1/2 - ANY Interface&lt;/P&gt;
&lt;P class="_1qeIAgB0cPwnLhDF9XSiJM"&gt;Firewall-02: Ethernet 1/1 and 1/2 - ANY Interface&lt;/P&gt;
&lt;P class="_1qeIAgB0cPwnLhDF9XSiJM"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="_1qeIAgB0cPwnLhDF9XSiJM"&gt;Failure Scenario:&lt;/P&gt;
&lt;P class="_1qeIAgB0cPwnLhDF9XSiJM"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="_1qeIAgB0cPwnLhDF9XSiJM"&gt;In the event of a failure in the Firewall-01 Ethernet 1/1 and 1/2 interface. Firewall-02 will assume the role of Active.&lt;/P&gt;
&lt;P class="_1qeIAgB0cPwnLhDF9XSiJM"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="_1qeIAgB0cPwnLhDF9XSiJM"&gt;If Firewall-01 recovers from its failure in its Ethernet interfaces 1/1 and 1/2, Firewall-02 of the secondary block (with the Role of Active) will wait 1 minute (Preemtive Hold Time 1 minute) to redeliver the Active Role to Firewall-01 to the main block.&lt;/P&gt;
&lt;P class="_1qeIAgB0cPwnLhDF9XSiJM"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="_1qeIAgB0cPwnLhDF9XSiJM"&gt;Or for this to work, should the secondary be in Passive Link Auto so that it is negotiating and not in Passive Link Shutdown? This is because I have a doubt, since how is it going to detect the Palo Alto that recovered from its failure condition, from the link monitor, if it has its interfaces down, they should be on auto, right?&lt;/P&gt;
&lt;P class="_1qeIAgB0cPwnLhDF9XSiJM"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="_1qeIAgB0cPwnLhDF9XSiJM"&gt;In HA VWire environment I'm not entirely familiar versus L3 environments.&lt;/P&gt;
&lt;P class="_1qeIAgB0cPwnLhDF9XSiJM"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="_1qeIAgB0cPwnLhDF9XSiJM"&gt;Com VWire according to what I comment, especially in the scenario of failure and recovery of the Principal, is this expected behavior correct? or with VWire is it different? should assume or validate other additional details, regarding HA issues, such as Timers, settings, options, etc.&lt;/P&gt;
&lt;P class="_1qeIAgB0cPwnLhDF9XSiJM"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="_1qeIAgB0cPwnLhDF9XSiJM"&gt;Thank you in advance for your time, for your good vibes, for your collaboration, advice and comments.&lt;/P&gt;
&lt;P class="_1qeIAgB0cPwnLhDF9XSiJM"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="_1qeIAgB0cPwnLhDF9XSiJM"&gt;Greetings&lt;/P&gt;</description>
      <pubDate>Fri, 04 Aug 2023 09:14:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/firewall-ha-confirmation-behavioral-link-monitor-ha-vwire-active/m-p/552562#M112409</guid>
      <dc:creator>Metgatz</dc:creator>
      <dc:date>2023-08-04T09:14:46Z</dc:date>
    </item>
    <item>
      <title>Re: Firewall HA - Confirmation  Behavioral - Link Monitor - HA Vwire - Active Passive - Link state Shutdown</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/firewall-ha-confirmation-behavioral-link-monitor-ha-vwire-active/m-p/552637#M112413</link>
      <description>&lt;P&gt;&lt;STRONG&gt;Scenario 1:&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;With passive link state set to shutdown, I would expect the firewalls to hit their flap limit. That scenario would result in failover to firewall 2, back to firewall 1 (due to preempt with higher priority value), then back to firewall 2. Assuming a flap limit of 3, firewall 1 would remain in a suspended state due to 'non-functional loop detected' until admin intervention, while firewall 2 continued to support traffic.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Scenario 2:&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;As you suggested, setting passive link state to auto would result in a cleaner failover. Firewall 1 would fail to firewall 2 and stay there. Firewall 1 would stay suspended due to monitored link down. Once the link is back up, firewall 1 would renegotiate HA, and should become the active unit since it's configured to preempt with a higher priority value.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Scenario 3:&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;If a monitored link on each firewall failed (e.g. e1/1 on both firewalls), one of them would become suspended due to non-func loop, regardless of passive link state being shutdown or auto. Recovery would require admin intervention, same as the first scenario.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If there's something I overlooked or didn't take into account, feel free to correct me.&lt;/P&gt;</description>
      <pubDate>Fri, 04 Aug 2023 17:54:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/firewall-ha-confirmation-behavioral-link-monitor-ha-vwire-active/m-p/552637#M112413</guid>
      <dc:creator>mplewis</dc:creator>
      <dc:date>2023-08-04T17:54:05Z</dc:date>
    </item>
    <item>
      <title>Re: Firewall HA - Confirmation  Behavioral - Link Monitor - HA Vwire - Active Passive - Link state Shutdown</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/firewall-ha-confirmation-behavioral-link-monitor-ha-vwire-active/m-p/552648#M112416</link>
      <description>&lt;P&gt;OK, thank you&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/66270"&gt;@mplewis&lt;/a&gt;&amp;nbsp; very much for your comments and cooperation.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;Regarding point 1, to scenario 1&lt;/EM&gt; that you mention, with the passive interfaces Link state shutdown. That means that the secondary firewall or with the passive role, has its interfaces turned off. In this scenario, if the link monitor is on both interfaces 1/1 and 1/2, and any of the interfaces of Firewall-01, active, of the Main block fail, it will assign the role to the Secondary as Active. But if we understand that the passive keeps its interfaces down, when it recovers from its failure condition, the Principal is Firewall-01, which has the role of passive, for example, the ethernet 1/1 interface recovers, if the Principal is in state passive, how will it detect if I lift its interface change, to recover its control after one minute, for the value of preemtive 1 minute, if its interfaces are shutdown those of the passive? What is associated with the recovery of the interfaces and that detection of the recovery of the interfaces condition, of the Main equipment in passive state, recovers from its interface problems, and after 1 minute assumes the role again, it would only be with Passive Link in "Auto" I understand right? With Passive Link Shutdown there is no way, right? This in VWire, L2 and L3 environments, the most common, right?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you for your time, your comments and your great collaboration.&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Greetings&lt;/P&gt;</description>
      <pubDate>Fri, 04 Aug 2023 19:50:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/firewall-ha-confirmation-behavioral-link-monitor-ha-vwire-active/m-p/552648#M112416</guid>
      <dc:creator>Metgatz</dc:creator>
      <dc:date>2023-08-04T19:50:19Z</dc:date>
    </item>
    <item>
      <title>Re: Firewall HA - Confirmation  Behavioral - Link Monitor - HA Vwire - Active Passive - Link state Shutdown</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/firewall-ha-confirmation-behavioral-link-monitor-ha-vwire-active/m-p/552654#M112418</link>
      <description>&lt;P&gt;Hello, sorry if I refer and tag you, I hope I'm not bothering you.&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/77347"&gt;@TomYoung&lt;/a&gt;&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/7608"&gt;@reaper&lt;/a&gt;&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/15603"&gt;@Raido_Rattameister&lt;/a&gt;&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/192693"&gt;@PavelK&lt;/a&gt;&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/70130"&gt;@aleksandar.astardzhiev&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please see my post and give me your comments, advice, clarifications, details, etc. regarding what I say about HA with Vwire ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you very much for your comments, for your time, for your collaboration.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I remain attentive&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Best regards.&lt;/P&gt;</description>
      <pubDate>Fri, 04 Aug 2023 23:25:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/firewall-ha-confirmation-behavioral-link-monitor-ha-vwire-active/m-p/552654#M112418</guid>
      <dc:creator>Metgatz</dc:creator>
      <dc:date>2023-08-04T23:25:14Z</dc:date>
    </item>
  </channel>
</rss>

