<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: HA pair issue PA-500 in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/ha-pair-issue-pa-500/m-p/124009#M46265</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Passive link state is probably configured as 'shutdown'. &amp;nbsp;This f&lt;SPAN&gt;orces the interface link to the down state on your passive device :&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Passive Link State" style="width: 616px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/6241iCB85C2E42D927253/image-size/large?v=v2&amp;amp;px=999" role="button" title="2016-11-04_11-01-44.png" alt="Passive Link State" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;Passive Link State&lt;/span&gt;&lt;/span&gt;﻿&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Looks like the management server might have an issue ... as long as your DP has no issues then traffic might&amp;nbsp;pass the device normally.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Restarting the mgmt-server usually fixes this issue but obviously you cannot do this currently in the operational mode. &amp;nbsp;You can of course reboot the device, alternatively you could reach out to support who could root your device and restart the mgmt-server process as root to try and fix it.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Cheers,&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;-Kim.&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 04 Nov 2016 10:03:32 GMT</pubDate>
    <dc:creator>kiwi</dc:creator>
    <dc:date>2016-11-04T10:03:32Z</dc:date>
    <item>
      <title>HA pair issue PA-500</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ha-pair-issue-pa-500/m-p/123429#M46225</link>
      <description>&lt;P&gt;Hi Guys,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Interesting one. Devices are in HA pair of the&amp;nbsp;PA-500. Suddenly we are no longer able to access the active device through the&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;GUl, but able to ping mgmt interface and SSH to it. When SSHing getting the screen below:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ssh error.PNG" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/6162i0517267F7E1B13B5/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="ssh error.PNG" alt="ssh error.PNG" /&gt;&lt;/span&gt;﻿&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;A firewall in not producing any command output and doesn't&amp;nbsp;see itself as in HA pair, no (active).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The passive device still accessible and seeing this box as active:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="error.PNG" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/6164i2DADDACCFC1919A4/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="error.PNG" alt="error.PNG" /&gt;&lt;/span&gt;﻿&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The clients currently connected to the box are not experiencing any system outage, so my guess active is working fine.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Another CLI&amp;nbsp;output&amp;nbsp;from the&amp;nbsp;passive box (uptime is quite cool 713 days):&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="state.PNG" style="width: 595px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/6170iEA2E431FD60AE3BC/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="state.PNG" alt="state.PNG" /&gt;&lt;/span&gt;﻿&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Anyone who had this before or any ideas? Thinking about to give a reboot to the box but not sure if the interfaces are in the correct&amp;nbsp;state on the&amp;nbsp;passive box. Why are they all down apart on the&amp;nbsp;HA links?:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="int-state.PNG" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/6172i95DDF57A989A829E/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="int-state.PNG" alt="int-state.PNG" /&gt;&lt;/span&gt;﻿&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thx,&lt;/P&gt;&lt;P&gt;Myky&lt;/P&gt;</description>
      <pubDate>Fri, 04 Nov 2016 09:31:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ha-pair-issue-pa-500/m-p/123429#M46225</guid>
      <dc:creator>TranceforLife</dc:creator>
      <dc:date>2016-11-04T09:31:03Z</dc:date>
    </item>
    <item>
      <title>Re: HA pair issue PA-500</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ha-pair-issue-pa-500/m-p/124009#M46265</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Passive link state is probably configured as 'shutdown'. &amp;nbsp;This f&lt;SPAN&gt;orces the interface link to the down state on your passive device :&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Passive Link State" style="width: 616px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/6241iCB85C2E42D927253/image-size/large?v=v2&amp;amp;px=999" role="button" title="2016-11-04_11-01-44.png" alt="Passive Link State" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;Passive Link State&lt;/span&gt;&lt;/span&gt;﻿&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Looks like the management server might have an issue ... as long as your DP has no issues then traffic might&amp;nbsp;pass the device normally.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Restarting the mgmt-server usually fixes this issue but obviously you cannot do this currently in the operational mode. &amp;nbsp;You can of course reboot the device, alternatively you could reach out to support who could root your device and restart the mgmt-server process as root to try and fix it.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Cheers,&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;-Kim.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 04 Nov 2016 10:03:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ha-pair-issue-pa-500/m-p/124009#M46265</guid>
      <dc:creator>kiwi</dc:creator>
      <dc:date>2016-11-04T10:03:32Z</dc:date>
    </item>
    <item>
      <title>Re: HA pair issue PA-500</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ha-pair-issue-pa-500/m-p/124026#M46266</link>
      <description>&lt;P&gt;Hi Wiki,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for your feed back. Didn't&amp;nbsp;know about passive link states. &amp;nbsp;But what is the purpose/difference of having "auto" or "shutdown" configured?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Management-Articles/What-is-the-Difference-Between-Auto-and-Shutdown-Mode-for/ta-p/58377" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Management-Articles/What-is-the-Difference-Between-Auto-and-Shutdown-Mode-for/ta-p/58377&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;That's an issue. I did try to use command:&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;gt; &lt;/SPAN&gt;&lt;SPAN&gt;debug software &lt;SPAN class="lia-search-match-lithium"&gt;restart&lt;/SPAN&gt; &lt;SPAN class="lia-search-match-lithium"&gt;management&lt;/SPAN&gt;-server but nothing is working at the&amp;nbsp;moment.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Do you think support still will be able to access box as root?&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thx,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Myky&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 04 Nov 2016 10:30:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ha-pair-issue-pa-500/m-p/124026#M46266</guid>
      <dc:creator>TranceforLife</dc:creator>
      <dc:date>2016-11-04T10:30:51Z</dc:date>
    </item>
    <item>
      <title>Re: HA pair issue PA-500</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ha-pair-issue-pa-500/m-p/124027#M46267</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/37163"&gt;@TranceforLife﻿&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;auto&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;— Causes the link status to reflect physical connectivity, but discards all packets received. This option allows the link state of the interface to stay up until a failover occurs, decreasing the amount of time it takes for the passive device to take over.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;This option is supported in Layer 2, Layer 3, and Virtual Wire mode. The auto option is desirable, if it is feasible for your network.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;SPAN&gt;shutdown&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;— Forces the interface link to the down state. This is the default option, which ensures that loops are not created in the network.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The CLI command you mention doesn't work because it relies on the management server process to be executed. &amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;SPAN&gt;Yes, if you still have SSH access to the device, then support can root into your device. &amp;nbsp;Once rooted into the device they can restart the management server as root.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;SPAN&gt;Cheers,&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;SPAN&gt;-Kim.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 04 Nov 2016 10:48:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ha-pair-issue-pa-500/m-p/124027#M46267</guid>
      <dc:creator>kiwi</dc:creator>
      <dc:date>2016-11-04T10:48:45Z</dc:date>
    </item>
    <item>
      <title>Re: HA pair issue PA-500</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ha-pair-issue-pa-500/m-p/124030#M46268</link>
      <description>&lt;P&gt;Much appreciated&lt;/P&gt;</description>
      <pubDate>Fri, 04 Nov 2016 11:15:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ha-pair-issue-pa-500/m-p/124030#M46268</guid>
      <dc:creator>TranceforLife</dc:creator>
      <dc:date>2016-11-04T11:15:13Z</dc:date>
    </item>
  </channel>
</rss>

