<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Virtual-wire active/passive HA issue in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/virtual-wire-active-passive-ha-issue/m-p/18774#M13678</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We are testing out a topology in the lab, with 2 PA-2020 in an active/passive HA cluster. They are between 2 pairs of Cisco switches and should play a role of redundant in-line firewalls. The connection to the switches is with FO modules on ports e1/13 and e1/14 (these ports are in a monitor group).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What we have noticed is some strange behaviour, and it is the same with PANOS 4.1.9. and 4.1.11.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If we pull out the cable on port e1/13 on the primary/active device, the firewalls failover, and the secondary/passive device becomes secondary/active. The now primary/passive will go to a non-functional state, and after a minute to passive, and will then again move to the active state. Of course, &lt;STRONG&gt;the cable is still unplugged&lt;/STRONG&gt;, so the failover happens again, and the secondary device becomes active once more. The process will continue until the primary device moves into a suspended state (3 times by default). The data traffic is highly effected with the failovering and spanning-tree recalculations on the Cisco switches.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When we disable the preemption, this does not happen, and failovering worked perfectly through different scenarios.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So, my question is - should the preemption be disabled in vwire active/passive HA? I have not found any reference or configuration best practice for this kind of topology in any document.&lt;/P&gt;&lt;P&gt;To me it seems logical that the firewall should check the state of the monitored interfaces (or path) before trying to resume its active role, even with preemption enabled.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 03 Apr 2013 14:37:31 GMT</pubDate>
    <dc:creator>bsimunko@recro-net.hr</dc:creator>
    <dc:date>2013-04-03T14:37:31Z</dc:date>
    <item>
      <title>Virtual-wire active/passive HA issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/virtual-wire-active-passive-ha-issue/m-p/18774#M13678</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We are testing out a topology in the lab, with 2 PA-2020 in an active/passive HA cluster. They are between 2 pairs of Cisco switches and should play a role of redundant in-line firewalls. The connection to the switches is with FO modules on ports e1/13 and e1/14 (these ports are in a monitor group).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What we have noticed is some strange behaviour, and it is the same with PANOS 4.1.9. and 4.1.11.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If we pull out the cable on port e1/13 on the primary/active device, the firewalls failover, and the secondary/passive device becomes secondary/active. The now primary/passive will go to a non-functional state, and after a minute to passive, and will then again move to the active state. Of course, &lt;STRONG&gt;the cable is still unplugged&lt;/STRONG&gt;, so the failover happens again, and the secondary device becomes active once more. The process will continue until the primary device moves into a suspended state (3 times by default). The data traffic is highly effected with the failovering and spanning-tree recalculations on the Cisco switches.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When we disable the preemption, this does not happen, and failovering worked perfectly through different scenarios.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So, my question is - should the preemption be disabled in vwire active/passive HA? I have not found any reference or configuration best practice for this kind of topology in any document.&lt;/P&gt;&lt;P&gt;To me it seems logical that the firewall should check the state of the monitored interfaces (or path) before trying to resume its active role, even with preemption enabled.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 03 Apr 2013 14:37:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/virtual-wire-active-passive-ha-issue/m-p/18774#M13678</guid>
      <dc:creator>bsimunko@recro-net.hr</dc:creator>
      <dc:date>2013-04-03T14:37:31Z</dc:date>
    </item>
    <item>
      <title>Re: Virtual-wire active/passive HA issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/virtual-wire-active-passive-ha-issue/m-p/18775#M13679</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Out of the blue that sounds like a bug.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also even if preemptive it shouldnt failover back to unit1 if unit1 isnt 100% available (that is couldnt ping whatever gateways you are monitoring against) - dunno on the other hand how PA handles this case.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you run vwire you could use these two boxes as two independent PA units and put the same security policy on them through shared config in panorama. This way no session sync is needed and no hazzle with failover who lives on its own.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As described in &lt;A class="active_link" href="http://www.aristanetworks.com/media/system/pdf/palo_alto_networks_arista.pdf" title="http://www.aristanetworks.com/media/system/pdf/palo_alto_networks_arista.pdf"&gt;http://www.aristanetworks.com/media/system/pdf/palo_alto_networks_arista.pdf&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The setup would be something like (example):&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cisco1: e1/13 (PA1_1), e1/14 (PA2_1)&lt;/P&gt;&lt;P&gt;||&lt;/P&gt;&lt;P&gt;PA1: VWIRE1: int1 (Cisco1_e1_13), int2 (Cisco2_e1_13)&lt;/P&gt;&lt;P&gt;PA2: VWIRE1: int1 (Cisco1_e1_14), int2 (Cisco2_e1_14)&lt;/P&gt;&lt;P&gt;||&lt;/P&gt;&lt;P&gt;Cisco2: e1/13 (PA1_2), e1/14 (PA2_2)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;and then make sure that loadbalancing for the etherchannel is L3 or lower (L2 etc). That is srcip+dstip on both ends is ok but its better if its dstip on the outer cisco and srcip on the inner cisco (to make life easier for the PA when it will identify bittorrent, skype etc heuristic based stuff). Also srcmac+dstmac would be ok.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Most modern cisco gear can use at least 8 paths for a single etherchannel in case you would like to scale things up.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Another note is if your cisco boxes can do virtual chassis then this etherchannel can be shared by multiple boxes (otherwise you would need some active/passive thingy on the cisco gear or spanningtree or such to disable the "looping" switch. That is if you have 2 ciscos as outer and 2 ciscos as inner switches (and no virtual chassis). This would also mean two VWIREs on each PA unit.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 03 Apr 2013 23:42:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/virtual-wire-active-passive-ha-issue/m-p/18775#M13679</guid>
      <dc:creator>mikand</dc:creator>
      <dc:date>2013-04-03T23:42:09Z</dc:date>
    </item>
    <item>
      <title>Re: Virtual-wire active/passive HA issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/virtual-wire-active-passive-ha-issue/m-p/18776#M13680</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Today I tested the same setup with a pair o PA-500 on PANOS 4.1.9, and the behaviour is the same.&lt;/P&gt;&lt;P&gt;Part of the log file from one of the devices:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2013/04/11 00:10:18info&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ha&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; state-c 0&amp;nbsp; HA Group 1: Moved from state Passive to state Active&lt;/P&gt;&lt;P&gt;2013/04/11 00:10:18info&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ras&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; rasmgr- 0&amp;nbsp; RASMGR daemon sync all user info to HA peer started.&lt;/P&gt;&lt;P&gt;2013/04/11 00:10:18info&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; vpn&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; keymgr- 0&amp;nbsp; KEYMGR sync all IPSec SA to HA peer started.&lt;/P&gt;&lt;P&gt;2013/04/11 00:10:19info&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; vpn&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; keymgr- 0&amp;nbsp; KEYMGR sync all IPSec SA to HA peer exit.&lt;/P&gt;&lt;P&gt;2013/04/11 00:10:19info&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; routing&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; routed- 0&amp;nbsp; FIB HA sync started when local device becomes master.&lt;/P&gt;&lt;P&gt;2013/04/11 00:10:19info&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; routing&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; routed- 0&amp;nbsp; FIB HA sync started when peer device becomes passive.&lt;/P&gt;&lt;P&gt;2013/04/11 00:10:20info&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; port&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; link-ch 0&amp;nbsp; Port&amp;nbsp; 2: Up&amp;nbsp;&amp;nbsp; 100Mb/s-full duplex&lt;/P&gt;&lt;P&gt;2013/04/11 00:10:22info&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; port&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; link-ch 0&amp;nbsp; Port&amp;nbsp; 1: Up&amp;nbsp;&amp;nbsp; 1Gb/s-full duplex&lt;/P&gt;&lt;P&gt;2013/04/11 00:11:04info&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; port&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; link-ch 0&amp;nbsp; Port&amp;nbsp; 1: Down 1Gb/s-full duplex&amp;nbsp; &lt;STRONG&gt;&amp;lt;---------------------------------------------------------- pulling out the cable&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;2013/04/11 00:11:18high&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ha&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; link-mo 0&amp;nbsp; HA Group 1: Link group '1' link 'ethernet1/1' is down&lt;/P&gt;&lt;P&gt;2013/04/11 00:11:18high&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ha&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; link-mo 0&amp;nbsp; HA Group 1: Link group '1' link 'ethernet1/2' is down&lt;/P&gt;&lt;P&gt;2013/04/11 00:11:18critical ha&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; link-mo 0&amp;nbsp; HA Group 1: Link group '1' failure; one or more links are down&lt;/P&gt;&lt;P&gt;2013/04/11 00:11:18critical ha&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; state-c 0&amp;nbsp; HA Group 1: Moved from state Active to state Non-Functional&lt;/P&gt;&lt;P&gt;2013/04/11 00:11:18info&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ras&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; rasmgr- 0&amp;nbsp; RASMGR daemon sync all user info to HA peer no longer needed.&lt;/P&gt;&lt;P&gt;2013/04/11 00:11:18info&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; vpn&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; keymgr- 0&amp;nbsp; KEYMGR sync all IPSec SA to HA peer no longer needed.&lt;/P&gt;&lt;P&gt;2013/04/11 00:11:18critical general&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; general 0&amp;nbsp; Chassis Master Alarm: HA-event&lt;/P&gt;&lt;P&gt;2013/04/11 00:11:19info&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; routing&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; routed- 0&amp;nbsp; FIB HA sync started when local device becomes master.&lt;/P&gt;&lt;P&gt;2013/04/11 00:12:18info&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ha&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; state-c 0&amp;nbsp; HA Group 1: Moved from state Non-Functional to state Passive&lt;/P&gt;&lt;P&gt;2013/04/11 00:12:18critical general&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; general 0&amp;nbsp; Chassis Master Alarm: Cleared&lt;/P&gt;&lt;P&gt;2013/04/11 00:12:42info&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; general&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; general 0&amp;nbsp; User admin accessed Monitor tab&lt;/P&gt;&lt;P&gt;2013/04/11 00:13:29info&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ha&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; state-c 0&amp;nbsp; HA Group 1: Moved from state Passive to state Active &lt;STRONG&gt;&amp;lt;---------------------------------------------------------- first transition to active state&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;2013/04/11 00:13:29info&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ras&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; rasmgr- 0&amp;nbsp; RASMGR daemon sync all user info to HA peer started.&lt;/P&gt;&lt;P&gt;2013/04/11 00:13:29info&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; vpn&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; keymgr- 0&amp;nbsp; KEYMGR sync all IPSec SA to HA peer started.&lt;/P&gt;&lt;P&gt;2013/04/11 00:13:29info&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; vpn&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; keymgr- 0&amp;nbsp; KEYMGR sync all IPSec SA to HA peer exit.&lt;/P&gt;&lt;P&gt;2013/04/11 00:13:30info&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; routing&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; routed- 0&amp;nbsp; FIB HA sync started when local device becomes master.&lt;/P&gt;&lt;P&gt;2013/04/11 00:13:30info&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; routing&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; routed- 0&amp;nbsp; FIB HA sync started when peer device becomes passive.&lt;/P&gt;&lt;P&gt;2013/04/11 00:13:30info&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; port&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; link-ch 0&amp;nbsp; Port&amp;nbsp; 2: Up&amp;nbsp;&amp;nbsp; 100Mb/s-full duplex&lt;/P&gt;&lt;P&gt;2013/04/11 00:14:29high&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ha&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; link-mo 0&amp;nbsp; HA Group 1: Link group '1' link 'ethernet1/1' is down&lt;/P&gt;&lt;P&gt;2013/04/11 00:14:29high&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ha&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; link-mo 0&amp;nbsp; HA Group 1: Link group '1' link 'ethernet1/2' is down&lt;/P&gt;&lt;P&gt;2013/04/11 00:14:29critical ha&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; link-mo 0&amp;nbsp; HA Group 1: Link group '1' failure; one or more links are down&lt;/P&gt;&lt;P&gt;2013/04/11 00:14:29critical ha&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; state-c 0&amp;nbsp; HA Group 1: Moved from state Active to state Non-Functional&lt;/P&gt;&lt;P&gt;2013/04/11 00:14:29info&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ras&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; rasmgr- 0&amp;nbsp; RASMGR daemon sync all user info to HA peer no longer needed.&lt;/P&gt;&lt;P&gt;2013/04/11 00:14:29info&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; vpn&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; keymgr- 0&amp;nbsp; KEYMGR sync all IPSec SA to HA peer no longer needed.&lt;/P&gt;&lt;P&gt;2013/04/11 00:14:29critical general&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; general 0&amp;nbsp; Chassis Master Alarm: HA-event&lt;/P&gt;&lt;P&gt;2013/04/11 00:14:30info&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; routing&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; routed- 0&amp;nbsp; FIB HA sync started when local device becomes master.&lt;/P&gt;&lt;P&gt;2013/04/11 00:15:29info&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ha&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; state-c 0&amp;nbsp; HA Group 1: Moved from state Non-Functional to state Passive&lt;/P&gt;&lt;P&gt;2013/04/11 00:15:29critical general&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; general 0&amp;nbsp; Chassis Master Alarm: Cleared&lt;/P&gt;&lt;P&gt;2013/04/11 00:15:38info&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; general&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; general 0&amp;nbsp; User admin accessed Monitor tab&lt;/P&gt;&lt;P&gt;2013/04/11 00:16:39info&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ha&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; state-c 0&amp;nbsp; HA Group 1: Moved from state Passive to state Active &lt;STRONG&gt;&amp;lt;---------------------------------------------------------- second transition to active state&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;2013/04/11 00:16:39info&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ras&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; rasmgr- 0&amp;nbsp; RASMGR daemon sync all user info to HA peer started.&lt;/P&gt;&lt;P&gt;2013/04/11 00:16:39info&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; vpn&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; keymgr- 0&amp;nbsp; KEYMGR sync all IPSec SA to HA peer started.&lt;/P&gt;&lt;P&gt;2013/04/11 00:16:40info&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; vpn&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; keymgr- 0&amp;nbsp; KEYMGR sync all IPSec SA to HA peer exit.&lt;/P&gt;&lt;P&gt;2013/04/11 00:16:40info&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; routing&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; routed- 0&amp;nbsp; FIB HA sync started when local device becomes master.&lt;/P&gt;&lt;P&gt;2013/04/11 00:16:40info&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; routing&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; routed- 0&amp;nbsp; FIB HA sync started when peer device becomes passive.&lt;/P&gt;&lt;P&gt;2013/04/11 00:16:41info&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; port&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; link-ch 0&amp;nbsp; Port&amp;nbsp; 2: Up&amp;nbsp;&amp;nbsp; 100Mb/s-full duplex&lt;/P&gt;&lt;P&gt;2013/04/11 00:17:39high&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ha&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; link-mo 0&amp;nbsp; HA Group 1: Link group '1' link 'ethernet1/1' is down&lt;/P&gt;&lt;P&gt;2013/04/11 00:17:39high&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ha&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; link-mo 0&amp;nbsp; HA Group 1: Link group '1' link 'ethernet1/2' is down&lt;/P&gt;&lt;P&gt;2013/04/11 00:17:39critical ha&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; link-mo 0&amp;nbsp; HA Group 1: Link group '1' failure; one or more links are down&lt;/P&gt;&lt;P&gt;2013/04/11 00:17:39critical ha&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; state-c 0&amp;nbsp; HA Group 1: Moved from state Active to state Non-Functional &lt;STRONG&gt;&amp;lt;---------------------------------------------------------- third transition to active state, but momentarily moves to "non-fuctional"&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;2013/04/11 00:17:39info&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ras&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; rasmgr- 0&amp;nbsp; RASMGR daemon sync all user info to HA peer no longer needed.&lt;/P&gt;&lt;P&gt;2013/04/11 00:17:39critical ha&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; preempt 0&amp;nbsp; HA Group 1: Going to Suspended state due to detection of a preemption loop after 3 loops&lt;/P&gt;&lt;P&gt;2013/04/11 00:17:39info&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; vpn&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; keymgr- 0&amp;nbsp; KEYMGR sync all IPSec SA to HA peer no longer needed.&lt;/P&gt;&lt;P&gt;2013/04/11 00:17:39critical ha&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; state-c 0&amp;nbsp; HA Group 1: Moved from state Non-Functional to state Suspended&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 05 Apr 2013 07:48:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/virtual-wire-active-passive-ha-issue/m-p/18776#M13680</guid>
      <dc:creator>bsimunko@recro-net.hr</dc:creator>
      <dc:date>2013-04-05T07:48:53Z</dc:date>
    </item>
  </channel>
</rss>

