<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Issue with PA-445 Failover - Interface Reset in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/issue-with-pa-445-failover-interface-reset/m-p/1242901#M125622</link>
    <description>&lt;P&gt;We have passive link state set to auto in the "Active/Passive Settings" in the HA config.&amp;nbsp; We are also on 11.1.10-h1.&amp;nbsp; If it is in a newer release than that, we haven't taken it yet, as we usually only take preferred releases and haven't made the jump to 11.2 yet.&lt;/P&gt;</description>
    <pubDate>Mon, 01 Dec 2025 23:44:56 GMT</pubDate>
    <dc:creator>ControlAdmins</dc:creator>
    <dc:date>2025-12-01T23:44:56Z</dc:date>
    <item>
      <title>Issue with PA-445 Failover - Interface Reset</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/issue-with-pa-445-failover-interface-reset/m-p/1242895#M125620</link>
      <description>&lt;P&gt;We just replaced our active-passive PA-850s with PA-445s and have run into an issue when we failover the firewalls.&amp;nbsp; On failover, all the data-plane interfaces on the new active node go down for 20 seconds before coming back up.&amp;nbsp; This is dropping every active connection through the firewall.&amp;nbsp; We did not see this behavior on the PA-850s (failover was basically instantaneous) and we do not see it on PA-1410s we recently deployed either.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Support is claiming this is working as designed and this interface reset behavior was intentionally introduced to the PA-440 series in 11.1.&amp;nbsp; We did not get a straight answer if the issue is limited to just the PA-440 and PA-445, but we know at least the PA-1410 does not have it.&amp;nbsp; Anyone else experiencing this?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 01 Dec 2025 20:47:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/issue-with-pa-445-failover-interface-reset/m-p/1242895#M125620</guid>
      <dc:creator>ControlAdmins</dc:creator>
      <dc:date>2025-12-01T20:47:09Z</dc:date>
    </item>
    <item>
      <title>Re: Issue with PA-445 Failover - Interface Reset</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/issue-with-pa-445-failover-interface-reset/m-p/1242896#M125621</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/37666"&gt;@ControlAdmins&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-start="150" data-end="420"&gt;There was a known issue (PAN-181968) that affected the PA-4xx series where interfaces could take longer than expected to come up during HA failover. That behavior wasn’t intentional and it’s been corrected in later releases so you should already have the fix in 11.1.&lt;/P&gt;
&lt;P data-start="150" data-end="420"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-start="422" data-end="906"&gt;With that resolved, the most common factor I’ve seen influence longer failover times on the PA-400 series is the &lt;STRONG data-start="535" data-end="557"&gt;Passive Link State&lt;/STRONG&gt; setting. What do you currently have that configured as? If it’s set to &lt;STRONG data-start="629" data-end="641"&gt;shutdown&lt;/STRONG&gt;, the passive unit keeps its interfaces physically down. Switching Passive Link State to &lt;STRONG data-start="753" data-end="761"&gt;Auto&lt;/STRONG&gt; keeps the ports up on the passive firewall, which prevents link renegotiation during failover and improves failover times.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 01 Dec 2025 22:18:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/issue-with-pa-445-failover-interface-reset/m-p/1242896#M125621</guid>
      <dc:creator>JayGolf</dc:creator>
      <dc:date>2025-12-01T22:18:40Z</dc:date>
    </item>
    <item>
      <title>Re: Issue with PA-445 Failover - Interface Reset</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/issue-with-pa-445-failover-interface-reset/m-p/1242901#M125622</link>
      <description>&lt;P&gt;We have passive link state set to auto in the "Active/Passive Settings" in the HA config.&amp;nbsp; We are also on 11.1.10-h1.&amp;nbsp; If it is in a newer release than that, we haven't taken it yet, as we usually only take preferred releases and haven't made the jump to 11.2 yet.&lt;/P&gt;</description>
      <pubDate>Mon, 01 Dec 2025 23:44:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/issue-with-pa-445-failover-interface-reset/m-p/1242901#M125622</guid>
      <dc:creator>ControlAdmins</dc:creator>
      <dc:date>2025-12-01T23:44:56Z</dc:date>
    </item>
    <item>
      <title>Re: Issue with PA-445 Failover - Interface Reset</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/issue-with-pa-445-failover-interface-reset/m-p/1248803#M126035</link>
      <description>&lt;P&gt;Older post, but our PA-445 Ha pair do not experience this. Presently on 11.1.10-h12, but we also used 11.1.10-h10. We did not use 11.1.10-h1 as we came directly from 11.1.6-h17.&lt;/P&gt;
&lt;P&gt;In addition to having the physical ports having "Enable in HA Passive State" enabled, check to see if the switch is registering any type of change during HA failover. We do have our ports configured for "spanning-tree admin-edge-port" (HPE Aruba's version of Cisco portfast), but that should have no impact as the passive PAN's ports should already be enabled/up and in an STP forwarding state before, during, and after failover and should never "bounce" and not cause a STP topology change or event.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Presently we only have a pair of PA-445s in Test and one remote lower-speed field location. When doing a failover we do not experience any STP changes on the switches connected to the PA-445s' interfaces. Pinging through the PA-445 to a switch that is used for management access we drop 1-3 pings, but usually just 1 ping, and this is likely due to the IPSEC tunnel switching over between PANs and not the traffic itself. I don't have a way to test non-tunneled traffic on PA-445 at this time. However, none of our OT devices report any problems with two SCADA systems that are connected or even notice we're doing the HA failover at the remote site.&lt;/P&gt;</description>
      <pubDate>Mon, 23 Feb 2026 19:19:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/issue-with-pa-445-failover-interface-reset/m-p/1248803#M126035</guid>
      <dc:creator>jasonroy</dc:creator>
      <dc:date>2026-02-23T19:19:34Z</dc:date>
    </item>
  </channel>
</rss>

