<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PA HA concept quick question in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/pa-ha-concept-quick-question/m-p/130610#M46859</link>
    <description>&lt;P&gt;Will do a test and let you know. Thanks man!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;P.S Using different community forums for &amp;nbsp;dif vendors (Extreme, Aruba, Infoblox) but PA is the&amp;nbsp;best &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 02 Dec 2016 13:17:10 GMT</pubDate>
    <dc:creator>TranceforLife</dc:creator>
    <dc:date>2016-12-02T13:17:10Z</dc:date>
    <item>
      <title>PA HA concept quick question</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-ha-concept-quick-question/m-p/130571#M46850</link>
      <description>&lt;P&gt;Hi Guys,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Just to clarify that heartbeat ping &amp;nbsp;messages send by bi-direction (Active&amp;gt;Passive and Passive&amp;gt;Active) and these messages proceed by management plane. So if my MP CPU utilisation is always high (98% it is 2050) is it possible to lose ICMP (h&lt;SPAN&gt;eartbeat) messages?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Cheers,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Myky&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;gurus members&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/7608"&gt;@reaper﻿&lt;/a&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/11943"&gt;@kiwi﻿&lt;/a&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry﻿&lt;/a&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 02 Dec 2016 11:55:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-ha-concept-quick-question/m-p/130571#M46850</guid>
      <dc:creator>TranceforLife</dc:creator>
      <dc:date>2016-12-02T11:55:21Z</dc:date>
    </item>
    <item>
      <title>Re: PA HA concept quick question</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-ha-concept-quick-question/m-p/130602#M46853</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/37163"&gt;@TranceforLife﻿&lt;/a&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;HA1 has it's own intelligent hearbeat to check if both sides are 'aware' they are alive, this is controlled on the dataplane and flows through dataplane or dedicated interfaces&lt;/P&gt;
&lt;P&gt;the ha1 backup on mgmt interface is an additional ping between the management planes, just to ensure if dataplane is running so high the ha1 messages get timed out, the passive unit doesn't take over and create a split brain situation&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I wouldn't recommend setting your primary HA1 to management unless the dp is running hight to begin with&lt;/P&gt;</description>
      <pubDate>Fri, 02 Dec 2016 12:48:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-ha-concept-quick-question/m-p/130602#M46853</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2016-12-02T12:48:59Z</dc:date>
    </item>
    <item>
      <title>Re: PA HA concept quick question</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-ha-concept-quick-question/m-p/130603#M46854</link>
      <description>&lt;P&gt;Hi Reaper,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for your reply. So it is not processed by MP plane then. We do have a case where our PA2050 MP CPU always running high (98%) and see a lot of these HA alerts:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Apr 01 03:17:06 Error: ha_ping_peer_miss(src/ha_ping.c:751): Missed 1 ping timeouts out of 3 (ha1)&lt;/P&gt;&lt;P&gt;Apr 01 03:17:28 Error: ha_ping_peer_miss(src/ha_ping.c:751): Missed 1 ping timeouts out of 3 (ha1)&lt;/P&gt;&lt;P&gt;Apr 01 03:17:29 Error: ha_ping_peer_miss(src/ha_ping.c:751): Missed 2 ping timeouts out of 3 (ha1)&lt;/P&gt;&lt;P&gt;Apr 01 03:25:14 Error: ha_ping_peer_miss(src/ha_ping.c:751): Missed 1 ping timeouts out of 3 (ha1)&lt;/P&gt;&lt;P&gt;Apr 01 03:25:17 Error: ha_ping_peer_miss(src/ha_ping.c:751): Missed 1 ping timeouts out of 3 (ha1)&lt;/P&gt;&lt;P&gt;Apr 01 03:28:04 Error: ha_ping_peer_miss(src/ha_ping.c:751): Missed 1 ping timeouts out of 3 (ha1)&lt;/P&gt;&lt;P&gt;Apr 01 03:28:26 Error: ha_ping_peer_miss(src/ha_ping.c:751): Missed 1 ping timeouts out of 3 (ha1)&lt;/P&gt;&lt;P&gt;Apr 01 03:28:27 Error: ha_ping_peer_miss(src/ha_ping.c:751): Missed 2 ping timeouts out of 3 (ha1)&lt;/P&gt;&lt;P&gt;Apr 01 03:28:28 Error: ha_ping_peer_miss(src/ha_ping.c:751): Missed 3 ping timeouts out of 3 (ha1)&lt;/P&gt;&lt;P&gt;Apr 01 03:28:28 Error: ha_ping_peer_miss(src/ha_ping.c:758): We have missed 4 pings from the peer for group 1 (ha1), restarting connection&lt;/P&gt;&lt;P&gt;Apr 01 03:28:28 Warning: ha_event_log(src/ha_event.c:47): HA Group 1: HA1 connection down&lt;/P&gt;&lt;P&gt;Apr 01 03:28:28 Warning: ha_event_log(src/ha_event.c:47): HA Group 1: All HA1 connections down&lt;/P&gt;&lt;P&gt;Apr 01 03:28:28 ha_sysd_haX_link_change(src/ha_sysd.c:2223): Seeing HA1 peer link unknown, waiting hold&lt;/P&gt;&lt;P&gt;Apr 01 03:28:28 ha_sysd_haX_link_change(src/ha_sysd.c:2223): Seeing HA1-Backup peer link unknown, waiting hold&lt;/P&gt;&lt;P&gt;Apr 01 03:28:28 HA2 peer link unknown&lt;/P&gt;&lt;P&gt;Apr 01 03:28:28 HA2-Backup peer link unknown&lt;/P&gt;&lt;P&gt;Apr 01 03:28:28 HA3 peer link unknown&lt;/P&gt;&lt;P&gt;Apr 01 03:28:28 ha_peer_send_error(src/ha_peer.c:1452): Group 1 (HA1-MAIN): Sending errro message&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Error Msg&lt;/P&gt;&lt;P&gt;---------&lt;/P&gt;&lt;P&gt;flags&amp;nbsp;&amp;nbsp;&amp;nbsp; : 0x2 (close:)&lt;/P&gt;&lt;P&gt;err code : Heartbeat ping failure (16)&lt;/P&gt;&lt;P&gt;num tlvs : 1&lt;/P&gt;&lt;P&gt;&amp;nbsp; Printing out 1 tlvs&lt;/P&gt;&lt;P&gt;&amp;nbsp; TLV[1]: type 5 (ERR_STRING); len 23; value:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 48656172 74626561 74207069 6e672066 61696c75 726500&lt;/P&gt;&lt;P&gt;Apr 01 03:28:28 Error: ha_peer_disconnect(src/ha_peer.c:1593): Group 1 (HA1-MAIN): peer connection error msg set: Heartbeat ping failure&lt;/P&gt;&lt;P&gt;Apr 01 03:28:28 Group 1 (HA1-MGMT): new primary (error), going away from NONE&lt;/P&gt;&lt;P&gt;Apr 01 03:28:28 Warning: ha_event_log(src/ha_event.c:47): HA Group 1: HA heartbeat backup is being used to avoid split-brain; the HA functionality is in a degraded state pending the recovery of HA1&lt;/P&gt;&lt;P&gt;Apr 01 03:28:28 ha_peer_send_primary(src/ha_peer.c:4950): Group 1 (HA1-MGMT): Sending primary message&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Primary Msg&lt;/P&gt;&lt;P&gt;-----------&lt;/P&gt;&lt;P&gt;flags&amp;nbsp;&amp;nbsp;&amp;nbsp; : 0x0&lt;/P&gt;&lt;P&gt;reason&amp;nbsp;&amp;nbsp; : 2 (error)&lt;/P&gt;&lt;P&gt;num tlvs : 0&lt;/P&gt;&lt;P&gt;Apr 01 03:28:28 ha_sysd_peerip_modify(src/ha_sysd.c:3829): Attempting 1 modify for sw.sysd.peers&lt;/P&gt;&lt;P&gt;Apr 01 03:28:28 ha_sysd_peerip_modify(src/ha_sysd.c:3874): Clearing out peer sysd setting because stop for link reconfig&lt;/P&gt;&lt;P&gt;Apr 01 03:28:28 ha_sysd_peerip_modify(src/ha_sysd.c:3893): Setting sysd node to: { 'peer.': { }, }&lt;/P&gt;&lt;P&gt;Apr 01 03:28:28 ha_ping_stop(src/ha_ping.c:404): Group 1: Stopping pings for ha1&lt;/P&gt;&lt;P&gt;Apr 01 03:28:28 ha_ping_stop(src/ha_ping.c:404): Group 1: Stopping pings for ha1&lt;/P&gt;&lt;P&gt;Apr 01 03:28:28 ha_ping_start(src/ha_ping.c:210): Group 1: Starting pings for ha1&lt;/P&gt;&lt;P&gt;Apr 01 03:28:28 ha_peer_start(src/ha_peer.c:246): Group 1 (HA1-MAIN): waiting for ping response before starting connection&lt;/P&gt;&lt;P&gt;Apr 01 03:28:28 ha_peer_recv_primary(src/ha_peer.c:5020): Group 1 (HA1-MGMT): Receiving primary ack message&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So constantly heartbeats ping missed but failover is not actually happening due to mgmt back up link path. If l understood this correct form teh logs.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Chreers,&lt;/P&gt;&lt;P&gt;Myky&lt;/P&gt;</description>
      <pubDate>Fri, 02 Dec 2016 12:55:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-ha-concept-quick-question/m-p/130603#M46854</guid>
      <dc:creator>TranceforLife</dc:creator>
      <dc:date>2016-12-02T12:55:29Z</dc:date>
    </item>
    <item>
      <title>Re: PA HA concept quick question</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-ha-concept-quick-question/m-p/130605#M46855</link>
      <description>&lt;P&gt;hmmm i might be wrong &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt; possible that the pan_dha (dataplane HA agent) forwards the heartbeats on to the management plane... which would actually make sense ..&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;your backup does not seem to be configured&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Apr 01 03:28:28 ha_sysd_haX_link_change(src/ha_sysd.c:2223): Seeing HA1-Backup peer link unknown, waiting hold&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;so, indeed, yes it would be possible the HA is flapping due to CPU load&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;you could try enabling the ha1-backup to enable the simplified pings, this could help as it requires less intelligence, so less cpu cycles&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 02 Dec 2016 13:03:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-ha-concept-quick-question/m-p/130605#M46855</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2016-12-02T13:03:08Z</dc:date>
    </item>
    <item>
      <title>Re: PA HA concept quick question</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-ha-concept-quick-question/m-p/130606#M46856</link>
      <description>&lt;P&gt;Hi Reaper,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Unfortunately, l do have a control for this firewall so cannot confirm right away details, but this is what l have noticed. Apart of configuring HA1-Backup , &lt;SPAN&gt;would&amp;nbsp;&lt;/SPAN&gt;increasing heartbeats time help in this case?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thx,&lt;/P&gt;&lt;P&gt;Myky&lt;/P&gt;</description>
      <pubDate>Fri, 02 Dec 2016 13:08:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-ha-concept-quick-question/m-p/130606#M46856</guid>
      <dc:creator>TranceforLife</dc:creator>
      <dc:date>2016-12-02T13:08:25Z</dc:date>
    </item>
    <item>
      <title>Re: PA HA concept quick question</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-ha-concept-quick-question/m-p/130609#M46858</link>
      <description>&lt;P&gt;absolutely&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;if your firewall is working within 'expected' parameters you'll want to relax the heartbeat/hello interval and increase the hold time&lt;/P&gt;</description>
      <pubDate>Fri, 02 Dec 2016 13:10:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-ha-concept-quick-question/m-p/130609#M46858</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2016-12-02T13:10:48Z</dc:date>
    </item>
    <item>
      <title>Re: PA HA concept quick question</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-ha-concept-quick-question/m-p/130610#M46859</link>
      <description>&lt;P&gt;Will do a test and let you know. Thanks man!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;P.S Using different community forums for &amp;nbsp;dif vendors (Extreme, Aruba, Infoblox) but PA is the&amp;nbsp;best &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 02 Dec 2016 13:17:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-ha-concept-quick-question/m-p/130610#M46859</guid>
      <dc:creator>TranceforLife</dc:creator>
      <dc:date>2016-12-02T13:17:10Z</dc:date>
    </item>
    <item>
      <title>Re: PA HA concept quick question</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-ha-concept-quick-question/m-p/130632#M46862</link>
      <description>&lt;P&gt;You might want to try and get whoever owns this box to upgrade&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/37163"&gt;@TranceforLife﻿&lt;/a&gt;. That constant high high utilization is bound to be causing management issues across the board; I can't imagine the commit time or log query on this device.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here's a few live documents on potential steps to lower to the CPU utilization as long as they fit your needs.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Featured-Articles/Tips-amp-Tricks-Reducing-Management-Plane-Load/ta-p/64681" target="_blank"&gt;Part 1&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Featured-Articles/Tips-amp-Tricks-Reducing-Management-Plane-Load-Part-2/ta-p/66874" target="_self"&gt;Part 2&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 02 Dec 2016 14:15:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-ha-concept-quick-question/m-p/130632#M46862</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2016-12-02T14:15:11Z</dc:date>
    </item>
    <item>
      <title>Re: PA HA concept quick question</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-ha-concept-quick-question/m-p/130633#M46863</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Oh it is nightmare and you are correct about the&amp;nbsp;upgrade. Scheduled for the next week already&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thx,&lt;/P&gt;&lt;P&gt;Myky&lt;/P&gt;</description>
      <pubDate>Fri, 02 Dec 2016 14:17:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-ha-concept-quick-question/m-p/130633#M46863</guid>
      <dc:creator>TranceforLife</dc:creator>
      <dc:date>2016-12-02T14:17:36Z</dc:date>
    </item>
  </channel>
</rss>

