<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: IP confilicting error in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/ip-confilicting-error/m-p/67207#M39462</link>
    <description>&lt;P&gt;Are you running as active-passive or active-active&lt;/P&gt;</description>
    <pubDate>Fri, 23 Oct 2015 13:34:14 GMT</pubDate>
    <dc:creator>OtakarKlier</dc:creator>
    <dc:date>2015-10-23T13:34:14Z</dc:date>
    <item>
      <title>IP confilicting error</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ip-confilicting-error/m-p/67194#M39455</link>
      <description>Hi 
We have configured HA pair on our two PA-VM200  Palo alto firewall. Now IP address of my interfaces eth1/1 (inside 10.1.1.1) and eth1/2 ( out side 10.1.1.2) are showing same as primary 10.1.1.1 on both firewalls and I am getting IP confilicting  error.

Any idea ?


Regards,</description>
      <pubDate>Fri, 23 Oct 2015 11:30:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ip-confilicting-error/m-p/67194#M39455</guid>
      <dc:creator>MohammedRafiq</dc:creator>
      <dc:date>2015-10-23T11:30:03Z</dc:date>
    </item>
    <item>
      <title>Re: IP confilicting error</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ip-confilicting-error/m-p/67197#M39456</link>
      <description />
      <pubDate>Fri, 23 Oct 2015 19:01:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ip-confilicting-error/m-p/67197#M39456</guid>
      <dc:creator>pankaku</dc:creator>
      <dc:date>2015-10-23T19:01:23Z</dc:date>
    </item>
    <item>
      <title>Re: IP confilicting error</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ip-confilicting-error/m-p/67207#M39462</link>
      <description>&lt;P&gt;Are you running as active-passive or active-active&lt;/P&gt;</description>
      <pubDate>Fri, 23 Oct 2015 13:34:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ip-confilicting-error/m-p/67207#M39462</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2015-10-23T13:34:14Z</dc:date>
    </item>
    <item>
      <title>Re: IP confilicting error</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ip-confilicting-error/m-p/67212#M39466</link>
      <description>&lt;P&gt;Hi Mohammed&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This could be normal behavior until you complete the configuration&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In an ActivePassive configuration (the only option available to VM series) the IP addresses used on the interfaces are shared between the two HA peers, so upon config sync the ip's should be made identical on all interfaces.&lt;/P&gt;
&lt;P&gt;They calculate a virtual MAC address and depending on their stance (active or passive) will respond to arp requests and process traffic etc&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;to coordinate these actions, they need to be aware of eachother and how 'helathy' the other member is. if the HA configuration has not been completed, one member may not be able to see the other member yet. if the HA configuration was completed, but this issue still exists, they may not be able to 'see' eachother and coordinate HA operations&lt;/P&gt;
&lt;P&gt;in the case where they are not able to communicate, both sides may believe the other side is down and will assume an active role&amp;nbsp; (we call this a split brain)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;to resolve this you should try to figure out if the config has been committed properly and the config is identical on both sides:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;is the group ID identical&lt;/LI&gt;
&lt;LI&gt;is tha HA1 ip subnet configured properly&lt;/LI&gt;
&lt;LI&gt;is the peer ha1 IP correct on both sides&lt;/LI&gt;
&lt;LI&gt;are both sides running the same PAN-OS&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;on the dashboard you can open the HighAvailability widget that may help you see more clearly what could be the problem&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;IMG src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/937i75E33475E8C63897/image-size/original?v=mpbl-1&amp;amp;px=-1" alt="2015-10-23_16-46-42.png" title="2015-10-23_16-46-42.png" border="0" /&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 23 Oct 2015 14:49:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ip-confilicting-error/m-p/67212#M39466</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2015-10-23T14:49:30Z</dc:date>
    </item>
    <item>
      <title>Re: IP confilicting error</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ip-confilicting-error/m-p/67438#M39527</link>
      <description>Thanks,
The issue were resolved by enabling/disabling HA on Primary and secondary.

The firewall is V-200 and both HA1 and HA2 ( session sync) are configured,  I am not sure this will do stateful failover or not.

According to PA documentation, VM series does not support stateful failover, but when you configure HA , it will not let you complete until you configure HA2 ( session Sync ) as well.


Regards,</description>
      <pubDate>Thu, 29 Oct 2015 12:16:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ip-confilicting-error/m-p/67438#M39527</guid>
      <dc:creator>MohammedRafiq</dc:creator>
      <dc:date>2015-10-29T12:16:50Z</dc:date>
    </item>
  </channel>
</rss>

