<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: HA Down Time in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/ha-down-time/m-p/6219#M4535</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;In my experience it is often the switches that cause the delay and not the PA devices. I have a 2020 HA pair running with pretty speedy failover, though it can always be better!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you look at the units when you try a failover you should see all the activity lights on the ports go off on one unit and light up on the other unit. When these light up, the PA unit will be ready to start passing data, so your switch needs to get going too!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You said you were testing this by unplugging a data interface - what sort of experience do you get when you do a controlled failover? Device / HA / Operational Commands / Suspend local device&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also, are you using striaght through or crossover cables between the units?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 31 Oct 2012 11:36:14 GMT</pubDate>
    <dc:creator>UKRB</dc:creator>
    <dc:date>2012-10-31T11:36:14Z</dc:date>
    <item>
      <title>HA Down Time</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ha-down-time/m-p/6217#M4533</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;BR /&gt;Dear Support:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I want to know how long will the Standby PA become active ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;According to the HA best practice , Running @ PA2020 &amp;amp; 4.1.8&lt;/P&gt;&lt;P&gt;the HA statue&amp;nbsp; is normal , all things are match&lt;/P&gt;&lt;P&gt;and the link monitor had setup , interface monitor set to shutdown&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I ping 8.8.8.8 -t at the internal network&lt;/P&gt;&lt;P&gt;I unplugin one of data interface , and the standby PA becomse Active&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;but can;t ping 8.8.8.8&amp;nbsp; ,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I had already set the swithport to portfast mode&lt;/P&gt;&lt;P&gt;and I can ping 8.8.8.8 after around 90 seconds&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is it normal ? and any advise ? thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 31 Oct 2012 04:52:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ha-down-time/m-p/6217#M4533</guid>
      <dc:creator>j.guo</dc:creator>
      <dc:date>2012-10-31T04:52:17Z</dc:date>
    </item>
    <item>
      <title>Re: HA Down Time</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ha-down-time/m-p/6218#M4534</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;According to &lt;A __default_attr="18644" __jive_macro_name="message" class="jive_macro jive_macro_message" href="https://live.paloaltonetworks.com/"&gt;&lt;/A&gt; the default settings for HA are:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"&lt;/P&gt;&lt;P&gt;pa- 2000 hello interval - 8 sec, heart beat interval - 2sec, promotion hold time- 2 sec and preemption hold time -1 sec&lt;/P&gt;&lt;P&gt;"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;which gives that if the current active device goes away it will take 6 seconds (3 * heartbeat) before the passive device takes over the traffic.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you manually restart the current active device then the passive should take over straight away because the device being rebooted will send a signal to the passive device to take over.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you have to wait 90 seconds and use default HA settings in your PA cluster I would think you have some other malfunction somewhere on the road.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would try to setup a packet capture on the devices before and after your PA to find out if your portfast is really working as expected or not.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 31 Oct 2012 07:21:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ha-down-time/m-p/6218#M4534</guid>
      <dc:creator>mikand</dc:creator>
      <dc:date>2012-10-31T07:21:41Z</dc:date>
    </item>
    <item>
      <title>Re: HA Down Time</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ha-down-time/m-p/6219#M4535</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;In my experience it is often the switches that cause the delay and not the PA devices. I have a 2020 HA pair running with pretty speedy failover, though it can always be better!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you look at the units when you try a failover you should see all the activity lights on the ports go off on one unit and light up on the other unit. When these light up, the PA unit will be ready to start passing data, so your switch needs to get going too!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You said you were testing this by unplugging a data interface - what sort of experience do you get when you do a controlled failover? Device / HA / Operational Commands / Suspend local device&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also, are you using striaght through or crossover cables between the units?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 31 Oct 2012 11:36:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ha-down-time/m-p/6219#M4535</guid>
      <dc:creator>UKRB</dc:creator>
      <dc:date>2012-10-31T11:36:14Z</dc:date>
    </item>
    <item>
      <title>Re: HA Down Time</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ha-down-time/m-p/6220#M4536</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;any differents with striaght through or crossover cables?&lt;/P&gt;&lt;P&gt;we now HA1 is crossover , HA2 is striaght through&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 31 Oct 2012 12:10:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ha-down-time/m-p/6220#M4536</guid>
      <dc:creator>j.guo</dc:creator>
      <dc:date>2012-10-31T12:10:21Z</dc:date>
    </item>
    <item>
      <title>Re: HA Down Time</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ha-down-time/m-p/6221#M4537</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I'd verify that the passive node takes up when you think it should.&amp;nbsp; Open cli sessions and verify that your trigger is working as expected. See &lt;A _jive_internal="true" href="https://live.paloaltonetworks.com/docs/DOC-3838"&gt;https://live.paloaltonetworks.com/docs/DOC-3838&lt;/A&gt; for a quick list of commands to use.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Second, I'd make sure that Device-&amp;gt;High Availability-&amp;gt;General-&amp;gt;Active/Passive Settings-&amp;gt;Passive Link State, is set to auto.&amp;nbsp; As already mentioned, make sure your upstream switch is configured correctly for the PANs ports (spanning-tree disabled).&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you have a visio to share, post it.&amp;nbsp; It's good to have everyone on the same page.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Good luck,&lt;/P&gt;&lt;P&gt;Mike&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 02 Nov 2012 22:18:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ha-down-time/m-p/6221#M4537</guid>
      <dc:creator>msullivan</dc:creator>
      <dc:date>2012-11-02T22:18:19Z</dc:date>
    </item>
  </channel>
</rss>

