<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: HA Failover moniring Management port in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/ha-failover-moniring-management-port/m-p/37307#M27358</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi &lt;A href="https://live.paloaltonetworks.com/u1/9569"&gt;djr&lt;/A&gt;,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yes, one of the option you can do is enable path monitoring for the management ranges. Also note that the communication would still go through one of the data ports (probably trust interface). You can point to one of the IP in management range and ask firewall to failover if that is unreachable. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is by design that management port is not an option under path monitoring. But your requirement can be a good feature request. You can contact your local sales / system engineer for feature request. Hope this helps. Thank you.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 05 Nov 2014 12:44:51 GMT</pubDate>
    <dc:creator>ssharma</dc:creator>
    <dc:date>2014-11-05T12:44:51Z</dc:date>
    <item>
      <title>HA Failover moniring Management port</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ha-failover-moniring-management-port/m-p/37306#M27357</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&amp;nbsp; I have an active/passive HA setup and have link state monitoring enabled on my data interfaces, but I notice I can't select the management port for this.&amp;nbsp; To my thinking, if I lose the management port I would want the cluster to fail over because it would no longer be able to log to Panorama, or to look up user IDs.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;How would you recommend doing this?&amp;nbsp; Is link path monitoring (using the management IP as the source) the only way?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 05 Nov 2014 12:36:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ha-failover-moniring-management-port/m-p/37306#M27357</guid>
      <dc:creator>djr</dc:creator>
      <dc:date>2014-11-05T12:36:04Z</dc:date>
    </item>
    <item>
      <title>Re: HA Failover moniring Management port</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ha-failover-moniring-management-port/m-p/37307#M27358</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi &lt;A href="https://live.paloaltonetworks.com/u1/9569"&gt;djr&lt;/A&gt;,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yes, one of the option you can do is enable path monitoring for the management ranges. Also note that the communication would still go through one of the data ports (probably trust interface). You can point to one of the IP in management range and ask firewall to failover if that is unreachable. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is by design that management port is not an option under path monitoring. But your requirement can be a good feature request. You can contact your local sales / system engineer for feature request. Hope this helps. Thank you.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 05 Nov 2014 12:44:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ha-failover-moniring-management-port/m-p/37307#M27358</guid>
      <dc:creator>ssharma</dc:creator>
      <dc:date>2014-11-05T12:44:51Z</dc:date>
    </item>
    <item>
      <title>Re: HA Failover moniring Management port</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ha-failover-moniring-management-port/m-p/37308#M27359</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks, I have done that.&amp;nbsp; Just to be clear though, if the management port fails, the firewall will route the AD lookups and logs to panorama etc via the trust interface?&amp;nbsp; It is L3 but I don't have any of the management services enabled and I don't presently have the trust address enabled on my panorama server as a valid source.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 05 Nov 2014 13:53:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ha-failover-moniring-management-port/m-p/37308#M27359</guid>
      <dc:creator>djr</dc:creator>
      <dc:date>2014-11-05T13:53:42Z</dc:date>
    </item>
    <item>
      <title>Re: HA Failover moniring Management port</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ha-failover-moniring-management-port/m-p/37309#M27360</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Djr,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Your situation is a special instance, since your PAN FW connected to AD through MGMT interface. But, most of the time data-ports are used for transit traffic and management is for &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;manage&lt;/SPAN&gt; the device. That's the reason only data-ports are available for monitoring at this point of time, just to ensure the transit traffic is passing through the FW. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But, your point is 100% valid and &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;i&lt;/SPAN&gt; would request you to contact with your PAN SE to submit a Feature Request for the same.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 05 Nov 2014 14:01:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ha-failover-moniring-management-port/m-p/37309#M27360</guid>
      <dc:creator>HULK</dc:creator>
      <dc:date>2014-11-05T14:01:28Z</dc:date>
    </item>
    <item>
      <title>Re: HA Failover moniring Management port</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ha-failover-moniring-management-port/m-p/37310#M27361</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi djr,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;No it will not failover user id or panorama functionality to trust interface once management port is down. From path monitoring you achieve failover if management ip ranges are unavailable (I haven't seen user using this approach though). Then the peer device's management will process those request normally. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can use either data port (trust port) or management port from Panorama and user id functionality. If you use data port for user id and panorama, and if that data port interface goes down, a failover will trigger from link monitoring itself. It will depend on your requirement. I will still suggest management interface for this purpose as this will lower number of packets device has to process at dataplane side, thus reducing dp cpu. Hope this helps. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 05 Nov 2014 14:05:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ha-failover-moniring-management-port/m-p/37310#M27361</guid>
      <dc:creator>ssharma</dc:creator>
      <dc:date>2014-11-05T14:05:25Z</dc:date>
    </item>
    <item>
      <title>Re: HA Failover moniring Management port</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ha-failover-moniring-management-port/m-p/37311#M27362</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;How can you choose which interface to use anyway?&amp;nbsp; I don't think I have set anything up to tell it which interface to use, it just does it.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 05 Nov 2014 14:08:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ha-failover-moniring-management-port/m-p/37311#M27362</guid>
      <dc:creator>djr</dc:creator>
      <dc:date>2014-11-05T14:08:15Z</dc:date>
    </item>
    <item>
      <title>Re: HA Failover moniring Management port</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ha-failover-moniring-management-port/m-p/37312#M27363</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You can configure it at following location :&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="service_route.JPG" class="image-0 jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/16743_service_route.JPG" style="height: 366px; width: 620px;" /&gt;&lt;/P&gt;&lt;P&gt;In above example I have requested firewall to user E1/5 which is my trust interface to use it for Panorama and User ID. Rest everything will still use management interface for other service.&lt;/P&gt;&lt;P&gt;You can configure it under Device -&amp;gt; Setup -&amp;gt; Services -&amp;gt; Service Route Configuration&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps. Thank you.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 05 Nov 2014 14:14:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ha-failover-moniring-management-port/m-p/37312#M27363</guid>
      <dc:creator>ssharma</dc:creator>
      <dc:date>2014-11-05T14:14:21Z</dc:date>
    </item>
    <item>
      <title>Re: HA Failover moniring Management port</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ha-failover-moniring-management-port/m-p/37313#M27364</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;FYI.&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/docs/DOC-6167"&gt;Setting a Service Route for Services to Use a Dataplane Interface from the Web UI and CLI&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 05 Nov 2014 14:16:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ha-failover-moniring-management-port/m-p/37313#M27364</guid>
      <dc:creator>HULK</dc:creator>
      <dc:date>2014-11-05T14:16:16Z</dc:date>
    </item>
    <item>
      <title>Re: HA Failover moniring Management port</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ha-failover-moniring-management-port/m-p/37314#M27365</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ah right, well my one is a lot simpler than yours, it just shows "use management interface for all" which for me is probably the best choice anyway.&amp;nbsp; As you say it keeps the data plane free for the data.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks very much, this has been very helpful and I have emailed my SE with the request.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best regards&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 05 Nov 2014 14:18:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ha-failover-moniring-management-port/m-p/37314#M27365</guid>
      <dc:creator>djr</dc:creator>
      <dc:date>2014-11-05T14:18:09Z</dc:date>
    </item>
    <item>
      <title>Re: HA Failover moniring Management port</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ha-failover-moniring-management-port/m-p/37315#M27366</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;By the way I tested this and it does not work!&amp;nbsp; I set the path monitoring to ping the gateway of the management interface's network and failed my management interface.&amp;nbsp; The device did not fail over but it did crash!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So I logged a support ticket and the answer came back that it would have used any available path for the path monitoring.&amp;nbsp; Unfortunately because it stayed active, my AD lookups stacked up and the useridd process crashed, the firewall wouldn't respond on the console and the only way out was to power it off.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So if you set the box up using the DEFAULT, to use the management port for service routes and your management port goes down...&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;It can't be made to fail over&lt;/LI&gt;&lt;LI&gt;It can no longer resolve any users&lt;/LI&gt;&lt;LI&gt;It can't update&lt;/LI&gt;&lt;LI&gt;It can't be managed&lt;/LI&gt;&lt;LI&gt;You can't get on via the console&lt;/LI&gt;&lt;LI&gt;and it crashes key processes&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Why has no-one else realised that a failure of the management port is the achilles heel of the HA?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 17 Nov 2014 14:07:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ha-failover-moniring-management-port/m-p/37315#M27366</guid>
      <dc:creator>djr</dc:creator>
      <dc:date>2014-11-17T14:07:41Z</dc:date>
    </item>
  </channel>
</rss>

