<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: HA session sync too slow? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/ha-session-sync-too-slow/m-p/1228960#M124274</link>
    <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/167193"&gt;@dmgeurts&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;
&lt;P&gt;I've recently migrated to a pair of active/active HA firewalls and am seeing some DNS return traffic dropped. Checking the logs, I can see that traffic is returned via another firewall as the DNS request was received. No problem, as normally the HA session sync is fast enough for the other firewall to have the session.&lt;BR /&gt;&lt;BR /&gt;However, the DNS servers reply so quickly that the session state hasn't synced yet and the return traffic is dropped. Has anyone seen this, and any suggestions other than delaying DNS replies on the servers?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Forgot to mention that the pair of firewalls are PA-3410 with direct HCSI link in adjacent racks. So, latency should be as small as it gets.&lt;/P&gt;
&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;
&lt;P&gt;That really doesn't make much sense.&amp;nbsp; 2 networked (routed) endpoints shouldn't be talking faster than firewalls directly connected to each other.&amp;nbsp; I've never ran a A/A deployment so unfortunately I don't have much insight to share.&amp;nbsp; I'm assuming you have the HA1, HA2, and HA3 interfaces defined?&amp;nbsp; The HA3 link as I understand it is required for an A/A deployment.&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Are your management and data CPUs all running at normal percentages?&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 13 May 2025 13:34:23 GMT</pubDate>
    <dc:creator>Brandon_Wertz</dc:creator>
    <dc:date>2025-05-13T13:34:23Z</dc:date>
    <item>
      <title>HA session sync too slow?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ha-session-sync-too-slow/m-p/1228829#M124252</link>
      <description>&lt;P&gt;I've recently migrated to a pair of active/active HA firewalls and am seeing some DNS return traffic dropped. Checking the logs, I can see that traffic is returned via another firewall as the DNS request was received. No problem, as normally the HA session sync is fast enough for the other firewall to have the session.&lt;BR /&gt;&lt;BR /&gt;However, the DNS servers reply so quickly that the session state hasn't synced yet and the return traffic is dropped. Has anyone seen this, and any suggestions other than delaying DNS replies on the servers?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Forgot to mention that the pair of firewalls are PA-3410 with direct HCSI link in adjacent racks. So, latency should be as small as it gets.&lt;/P&gt;</description>
      <pubDate>Mon, 12 May 2025 13:48:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ha-session-sync-too-slow/m-p/1228829#M124252</guid>
      <dc:creator>dmgeurts</dc:creator>
      <dc:date>2025-05-12T13:48:09Z</dc:date>
    </item>
    <item>
      <title>Re: HA session sync too slow?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ha-session-sync-too-slow/m-p/1228960#M124274</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/167193"&gt;@dmgeurts&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;
&lt;P&gt;I've recently migrated to a pair of active/active HA firewalls and am seeing some DNS return traffic dropped. Checking the logs, I can see that traffic is returned via another firewall as the DNS request was received. No problem, as normally the HA session sync is fast enough for the other firewall to have the session.&lt;BR /&gt;&lt;BR /&gt;However, the DNS servers reply so quickly that the session state hasn't synced yet and the return traffic is dropped. Has anyone seen this, and any suggestions other than delaying DNS replies on the servers?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Forgot to mention that the pair of firewalls are PA-3410 with direct HCSI link in adjacent racks. So, latency should be as small as it gets.&lt;/P&gt;
&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;
&lt;P&gt;That really doesn't make much sense.&amp;nbsp; 2 networked (routed) endpoints shouldn't be talking faster than firewalls directly connected to each other.&amp;nbsp; I've never ran a A/A deployment so unfortunately I don't have much insight to share.&amp;nbsp; I'm assuming you have the HA1, HA2, and HA3 interfaces defined?&amp;nbsp; The HA3 link as I understand it is required for an A/A deployment.&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Are your management and data CPUs all running at normal percentages?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 13 May 2025 13:34:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ha-session-sync-too-slow/m-p/1228960#M124274</guid>
      <dc:creator>Brandon_Wertz</dc:creator>
      <dc:date>2025-05-13T13:34:23Z</dc:date>
    </item>
    <item>
      <title>Re: HA session sync too slow?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ha-session-sync-too-slow/m-p/1228964#M124275</link>
      <description>&lt;P&gt;Yes, all HA1/2/3 and their backups are connected. CPU on data and management planes is low. The DNS server caches entries and it's a very small percentage of traffic affected.&lt;/P&gt;
&lt;P&gt;Agree with you completely. I did not expect this, so apart from CPU load anything I should be checking?&lt;/P&gt;
&lt;P&gt;PanOS version is 11.1.6h something (off the top of my head)&lt;/P&gt;</description>
      <pubDate>Tue, 13 May 2025 14:03:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ha-session-sync-too-slow/m-p/1228964#M124275</guid>
      <dc:creator>dmgeurts</dc:creator>
      <dc:date>2025-05-13T14:03:42Z</dc:date>
    </item>
    <item>
      <title>Re: HA session sync too slow?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ha-session-sync-too-slow/m-p/1228967#M124276</link>
      <description>&lt;P&gt;Unfortunately I don't have any other ideas, other than opening a support case getting TAC to take a look.&lt;/P&gt;</description>
      <pubDate>Tue, 13 May 2025 15:08:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ha-session-sync-too-slow/m-p/1228967#M124276</guid>
      <dc:creator>Brandon_Wertz</dc:creator>
      <dc:date>2025-05-13T15:08:43Z</dc:date>
    </item>
  </channel>
</rss>

