<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: LACP in HA issue in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/lacp-in-ha-issue/m-p/92197#M43701</link>
    <description>&lt;P&gt;1. &amp;nbsp; Any pattern/specific time frame when does this issue happen?&lt;/P&gt;&lt;P&gt;1. &amp;nbsp; Have you try to run&amp;nbsp;continue ping from a host behind the firewall to outside of the firewall?&lt;/P&gt;&lt;P&gt;2. &amp;nbsp; Have you try to turn off LACP on the firewall and 9K ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;-E&lt;/P&gt;</description>
    <pubDate>Sun, 26 Jun 2016 01:12:05 GMT</pubDate>
    <dc:creator>nextgenhappines</dc:creator>
    <dc:date>2016-06-26T01:12:05Z</dc:date>
    <item>
      <title>LACP in HA issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/lacp-in-ha-issue/m-p/92147#M43696</link>
      <description>&lt;P&gt;I have a pair of PAN 5060 (v.7.1.2) firewalls &amp;nbsp;in HA Passive/Active connected with LACP to pair of core Nexus 9000 switches. From time to time (every hour or few) connectivity to active firewall is faling (can't ping firewall&amp;nbsp;LACP L3 interface ip address from core) for a few sec. When it happens I noticed presence of&amp;nbsp;MAC adddress of firewall&amp;nbsp;on the core switch where passive HA&amp;nbsp;cluster member&amp;nbsp;is connected but failover is not a case here&amp;nbsp;(there is neither no reason not trace of failover). &amp;nbsp;When connectivity is restored I can see MAC address of firewall back on core switch where active firewall is connected.&lt;/P&gt;</description>
      <pubDate>Sat, 25 Jun 2016 12:47:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/lacp-in-ha-issue/m-p/92147#M43696</guid>
      <dc:creator>niuk</dc:creator>
      <dc:date>2016-06-25T12:47:29Z</dc:date>
    </item>
    <item>
      <title>Re: LACP in HA issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/lacp-in-ha-issue/m-p/92197#M43701</link>
      <description>&lt;P&gt;1. &amp;nbsp; Any pattern/specific time frame when does this issue happen?&lt;/P&gt;&lt;P&gt;1. &amp;nbsp; Have you try to run&amp;nbsp;continue ping from a host behind the firewall to outside of the firewall?&lt;/P&gt;&lt;P&gt;2. &amp;nbsp; Have you try to turn off LACP on the firewall and 9K ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;-E&lt;/P&gt;</description>
      <pubDate>Sun, 26 Jun 2016 01:12:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/lacp-in-ha-issue/m-p/92197#M43701</guid>
      <dc:creator>nextgenhappines</dc:creator>
      <dc:date>2016-06-26T01:12:05Z</dc:date>
    </item>
    <item>
      <title>Re: LACP in HA issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/lacp-in-ha-issue/m-p/93575#M43889</link>
      <description>&lt;P&gt;No specific time frame, every hour or few. I've not try to turn off LACP neither ping from&amp;nbsp;&lt;SPAN&gt;host behind the firewall to outside of the firewall. I was advised to &lt;A href="https://live.paloaltonetworks.com/t5/Management-Articles/Trigger-a-Gratuitous-ARP-GARP-from-a-Palo-Alto-Networks-Device/ta-p/61962" target="_self"&gt;trigger a GARP&lt;/A&gt; and catpure it.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 03 Jul 2016 11:17:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/lacp-in-ha-issue/m-p/93575#M43889</guid>
      <dc:creator>niuk</dc:creator>
      <dc:date>2016-07-03T11:17:25Z</dc:date>
    </item>
    <item>
      <title>Re: LACP in HA issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/lacp-in-ha-issue/m-p/93578#M43892</link>
      <description>&lt;P&gt;Can you confirm that spanning tree is not enabled on the Nexus ports and potentially moving to blocking on the active link port.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If there is no spanning tree, then TAC&amp;nbsp;is correct no mac migration should occur outside of a bug in the PanOS causing the passive device to arp this address. &amp;nbsp;the packet captures should confirm the exact behavior.&lt;/P&gt;</description>
      <pubDate>Sun, 03 Jul 2016 11:39:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/lacp-in-ha-issue/m-p/93578#M43892</guid>
      <dc:creator>pulukas</dc:creator>
      <dc:date>2016-07-03T11:39:03Z</dc:date>
    </item>
    <item>
      <title>Re: LACP in HA issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/lacp-in-ha-issue/m-p/94638#M43937</link>
      <description>&lt;P&gt;Spanning tree is enabled on switch for that vlan where firewalls lives in. But there was no changes of active ports&amp;nbsp;when firewall MAC appeared (on switch where Passive is connected)&lt;/P&gt;</description>
      <pubDate>Wed, 06 Jul 2016 12:23:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/lacp-in-ha-issue/m-p/94638#M43937</guid>
      <dc:creator>niuk</dc:creator>
      <dc:date>2016-07-06T12:23:32Z</dc:date>
    </item>
    <item>
      <title>Re: LACP in HA issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/lacp-in-ha-issue/m-p/95985#M43994</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I agree with&amp;nbsp;pulukas, try disabling spanning tree on just those ports where the PAN's are connected and see if that resolves the issue.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Fri, 08 Jul 2016 21:23:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/lacp-in-ha-issue/m-p/95985#M43994</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2016-07-08T21:23:47Z</dc:date>
    </item>
    <item>
      <title>Re: LACP in HA issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/lacp-in-ha-issue/m-p/96143#M44001</link>
      <description>&lt;P&gt;If there is no spanning tree port status change, then this does have to be a bug. &amp;nbsp;The mac move should not occur in that scenario.&lt;/P&gt;</description>
      <pubDate>Sun, 10 Jul 2016 11:01:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/lacp-in-ha-issue/m-p/96143#M44001</guid>
      <dc:creator>pulukas</dc:creator>
      <dc:date>2016-07-10T11:01:37Z</dc:date>
    </item>
  </channel>
</rss>

