<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: HA2 problems in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/ha2-problems/m-p/17779#M12944</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;sorry for the huge delay &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;It's connected through a switch. In the meanwhile it's identified as a bug.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Michael&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 21 Sep 2012 08:13:43 GMT</pubDate>
    <dc:creator>muellerm</dc:creator>
    <dc:date>2012-09-21T08:13:43Z</dc:date>
    <item>
      <title>HA2 problems</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ha2-problems/m-p/17772#M12937</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello together,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have a A/A cluster with PA-5050 boxes running PAN-OS 4.1.5&lt;/P&gt;&lt;P&gt;At the moment one node is suspended due to another problem. We had the problem that we lost the HA2 connectivity (main/backup) between the cluster nodes and traffic through the active box where stopped.&lt;/P&gt;&lt;P&gt;From my point of view this should not happen as this link is for synchoronisation of state, session, routing,etc... But as only one box is active at the moment, so need for the sync?!? After reestablishing a connection for HA2 traffic was passing the firewall.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any clue?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thx&lt;/P&gt;&lt;P&gt;Michael&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 15 May 2012 14:35:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ha2-problems/m-p/17772#M12937</guid>
      <dc:creator>muellerm</dc:creator>
      <dc:date>2012-05-15T14:35:59Z</dc:date>
    </item>
    <item>
      <title>Re: HA2 problems</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ha2-problems/m-p/17773#M12938</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Sessionsync is so when failover occurs the already setup sessions can continue - otherwise they would be just dropped (or if lucky get fin/ack or rst depending on what kind of session it is).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As a workaround I think you can setup one of the dataplane interfaces to be used for HA.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 15 May 2012 22:07:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ha2-problems/m-p/17773#M12938</guid>
      <dc:creator>mikand</dc:creator>
      <dc:date>2012-05-15T22:07:35Z</dc:date>
    </item>
    <item>
      <title>Re: HA2 problems</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ha2-problems/m-p/17774#M12939</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi...Did all traffic or just some of the traffic stop?&amp;nbsp; It is most likely where one PA setups the session and can't sync the session to its peer.&amp;nbsp; As return traffic arrives at the peer, the traffic may be out of state and the peer drops the packets. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As suggested by mikand, you should configure backup for HA2 as well as HA1 and HA3 if possible.&amp;nbsp; For HA3 you can use AE (LAG) if our PA models support it. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 15 May 2012 23:50:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ha2-problems/m-p/17774#M12939</guid>
      <dc:creator>rmonvon</dc:creator>
      <dc:date>2012-05-15T23:50:35Z</dc:date>
    </item>
    <item>
      <title>Re: HA2 problems</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ha2-problems/m-p/17775#M12940</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks for the fast replies.&lt;/P&gt;&lt;P&gt;Maybe I was not clear enough. We have a HA2 main and backup. Due to another problem the main was not working and we lost the backup.&lt;/P&gt;&lt;P&gt;In the moment we lost the backup one of the firewalls were suspended, so we were running on one node. At this time we lost as well the HA2 backup and traffic seems not to be passing anymore.&lt;/P&gt;&lt;P&gt;Unfortunatly I wasn't onsite during this time. I just get it reported like this. So it hard to figure out what realy happens and as it's a production enviroment I'm not able to reproduce this issue.&lt;/P&gt;&lt;P&gt;The only thing which I'm sure that during the time traffic wasn't passing both HA2 link weren't present.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now, I just want to know if it's possible that the root cause of the stopped traffic can be that no HA2 link was present. Even when we were running on a single node at this time. So no need for the session sync.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Michael&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 16 May 2012 10:53:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ha2-problems/m-p/17775#M12940</guid>
      <dc:creator>muellerm</dc:creator>
      <dc:date>2012-05-16T10:53:37Z</dc:date>
    </item>
    <item>
      <title>Re: HA2 problems</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ha2-problems/m-p/17776#M12941</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I recommend that we review the system log around the time of the failure and check the HA events to figure the sequence of failures.&amp;nbsp; HA2 failure may impact new sessions/traffic as the session state cannot be sync'ed but it should not impact existing sessions.&amp;nbsp; You can have 1 node running while the other is down and HA2 can be disconnected.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also, how did the other node went into suspend state?&amp;nbsp; Maybe the failure included more than just HA2?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 16 May 2012 14:46:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ha2-problems/m-p/17776#M12941</guid>
      <dc:creator>rmonvon</dc:creator>
      <dc:date>2012-05-16T14:46:10Z</dc:date>
    </item>
    <item>
      <title>Re: HA2 problems</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ha2-problems/m-p/17777#M12942</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;the other node is suspended manually. There is an issue which impacted our service in the A/A deployment, we had to suspend on box.This is allready addressed and under investigations by PA.&lt;/P&gt;&lt;P&gt;I thougth as well that it should not impact any traffic when running on a single node without HA2.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I can try to gather logs around the time the problem occured&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'll check if I can test this during a night&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Michael&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 16 May 2012 15:16:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ha2-problems/m-p/17777#M12942</guid>
      <dc:creator>muellerm</dc:creator>
      <dc:date>2012-05-16T15:16:14Z</dc:date>
    </item>
    <item>
      <title>Re: HA2 problems</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ha2-problems/m-p/17778#M12943</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;As far as the links.. HA1 and HA2.. how are they connected?&lt;/P&gt;&lt;P&gt;Are we talking about a Straight thru cable, Cross over cable or connected through a switch.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you say Straight thru cable, it is not recommeneded. In fact it is not supported.&lt;/P&gt;&lt;P&gt;It is recommended that if you have to use a cable, that it is a Cross over cable.. or connect through a switch.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Lets see if that helps or not.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 24 May 2012 21:06:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ha2-problems/m-p/17778#M12943</guid>
      <dc:creator>jdelio</dc:creator>
      <dc:date>2012-05-24T21:06:50Z</dc:date>
    </item>
    <item>
      <title>Re: HA2 problems</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ha2-problems/m-p/17779#M12944</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;sorry for the huge delay &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;It's connected through a switch. In the meanwhile it's identified as a bug.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Michael&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 21 Sep 2012 08:13:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ha2-problems/m-p/17779#M12944</guid>
      <dc:creator>muellerm</dc:creator>
      <dc:date>2012-09-21T08:13:43Z</dc:date>
    </item>
  </channel>
</rss>

