<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Doubt configuration HA Paloalto-Aruba in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/doubt-configuration-ha-paloalto-aruba/m-p/597517#M118835</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/192693"&gt;@PavelK&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hi @PavelK&lt;/P&gt;
&lt;P&gt;Yes, I have enabled auto mode, but the problem persists, we only have HA1 enabled, I don't know if the problem is related to it.&lt;/P&gt;
&lt;P&gt;HA1 is connected to the aruba pair switch with LACP . any other idea?&lt;/P&gt;
&lt;P&gt;Thank you very much&lt;/P&gt;</description>
    <pubDate>Wed, 11 Sep 2024 08:42:50 GMT</pubDate>
    <dc:creator>Alpalo</dc:creator>
    <dc:date>2024-09-11T08:42:50Z</dc:date>
    <item>
      <title>Doubt configuration HA Paloalto-Aruba</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/doubt-configuration-ha-paloalto-aruba/m-p/597408#M118819</link>
      <description>&lt;P&gt;Hello to all&lt;/P&gt;
&lt;P&gt;I have a pair of FW PA-460 active-passive. When we perform Failover I lose 40 seconds the network to the internet. i have only HA1 connected on a pair of SW aruba. I suspect it may be an Aruba or Paloalto configuration issue. Any idea?&lt;/P&gt;
&lt;P&gt;Best regards.&lt;/P&gt;</description>
      <pubDate>Tue, 10 Sep 2024 14:21:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/doubt-configuration-ha-paloalto-aruba/m-p/597408#M118819</guid>
      <dc:creator>Alpalo</dc:creator>
      <dc:date>2024-09-10T14:21:59Z</dc:date>
    </item>
    <item>
      <title>Re: Doubt configuration HA Paloalto-Aruba</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/doubt-configuration-ha-paloalto-aruba/m-p/597422#M118820</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;I think these articles may be useful.&lt;/P&gt;
&lt;P&gt;Layer 3 High Availability with Optimal Failover Times Best Practices&lt;/P&gt;
&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClHnCAK" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClHnCAK&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Resource List: High Availability Configuring and Troubleshooting&lt;/P&gt;
&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClIbCAK" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClIbCAK&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Tue, 10 Sep 2024 18:24:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/doubt-configuration-ha-paloalto-aruba/m-p/597422#M118820</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2024-09-10T18:24:56Z</dc:date>
    </item>
    <item>
      <title>Re: Doubt configuration HA Paloalto-Aruba</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/doubt-configuration-ha-paloalto-aruba/m-p/597472#M118831</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/192671"&gt;@Alpalo&lt;/a&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;have you enabled&amp;nbsp;Passive Link State to Auto?&lt;/P&gt;
&lt;P&gt;Here are references:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000boFVCAY" target="_self"&gt;What is the corresponding link state when the passive link state is set to auto?&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-admin/high-availability/set-up-activepassive-ha/configure-activepassive-ha" target="_self"&gt;Configure Active/Passive HA&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Setting the link state to Auto allows for reducing the amount of time it takes for the passive firewall to take over when a failover occurs.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Kind Regards&lt;/P&gt;
&lt;P&gt;Pavel&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 11 Sep 2024 03:36:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/doubt-configuration-ha-paloalto-aruba/m-p/597472#M118831</guid>
      <dc:creator>PavelK</dc:creator>
      <dc:date>2024-09-11T03:36:22Z</dc:date>
    </item>
    <item>
      <title>Re: Doubt configuration HA Paloalto-Aruba</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/doubt-configuration-ha-paloalto-aruba/m-p/597517#M118835</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/192693"&gt;@PavelK&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hi @PavelK&lt;/P&gt;
&lt;P&gt;Yes, I have enabled auto mode, but the problem persists, we only have HA1 enabled, I don't know if the problem is related to it.&lt;/P&gt;
&lt;P&gt;HA1 is connected to the aruba pair switch with LACP . any other idea?&lt;/P&gt;
&lt;P&gt;Thank you very much&lt;/P&gt;</description>
      <pubDate>Wed, 11 Sep 2024 08:42:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/doubt-configuration-ha-paloalto-aruba/m-p/597517#M118835</guid>
      <dc:creator>Alpalo</dc:creator>
      <dc:date>2024-09-11T08:42:50Z</dc:date>
    </item>
    <item>
      <title>Re: Doubt configuration HA Paloalto-Aruba</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/doubt-configuration-ha-paloalto-aruba/m-p/598294#M119005</link>
      <description>&lt;P&gt;Any idea?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks so much&lt;/P&gt;</description>
      <pubDate>Thu, 19 Sep 2024 15:01:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/doubt-configuration-ha-paloalto-aruba/m-p/598294#M119005</guid>
      <dc:creator>Alpalo</dc:creator>
      <dc:date>2024-09-19T15:01:52Z</dc:date>
    </item>
    <item>
      <title>Re: Doubt configuration HA Paloalto-Aruba</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/doubt-configuration-ha-paloalto-aruba/m-p/598301#M119008</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;You have your HA connections between the two Palo Alto's via a switch?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Thu, 19 Sep 2024 15:27:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/doubt-configuration-ha-paloalto-aruba/m-p/598301#M119008</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2024-09-19T15:27:06Z</dc:date>
    </item>
    <item>
      <title>Re: Doubt configuration HA Paloalto-Aruba</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/doubt-configuration-ha-paloalto-aruba/m-p/598351#M119020</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/192671"&gt;@Alpalo&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;
&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/192693"&gt;@PavelK&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hi @PavelK&lt;/P&gt;
&lt;P&gt;Yes, I have enabled auto mode, but the problem persists, we only have HA1 enabled, I don't know if the problem is related to it.&lt;/P&gt;
&lt;P&gt;HA1 is connected to the aruba pair switch with LACP . any other idea?&lt;/P&gt;
&lt;P&gt;Thank you very much&lt;/P&gt;
&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;
&lt;P&gt;Twice now I only see mention of HA1 being used/turned on.&amp;nbsp; Do you not have a config for HA2?&amp;nbsp; Is there no HA2 connectivity (of some sort) between FW1/2?&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;HA1 links carry management sync/config sync.&amp;nbsp; HA2 links carry TCP session sync.&amp;nbsp; If you do not have HA2 connections between your active/passive firewalls the TCP state of existing sessions will NOT be known to your passive firewall and when a failover occurs all that session data will be lost and will need to be restarted for ALL traffic.&amp;nbsp; If this is how things are then I could potentially see a 40 second delay in your HA failovers.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'm not sure what your routing situation is but relevant IP/routing information/state wouldn't be known your to your passive firewall and would have to be learned.&amp;nbsp; Then once the network state is known to the firewall then all client TCP sessions could get re-established.&lt;/P&gt;</description>
      <pubDate>Thu, 19 Sep 2024 18:56:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/doubt-configuration-ha-paloalto-aruba/m-p/598351#M119020</guid>
      <dc:creator>Brandon_Wertz</dc:creator>
      <dc:date>2024-09-19T18:56:20Z</dc:date>
    </item>
  </channel>
</rss>

