<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: failover in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/failover/m-p/167536#M53498</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/18719"&gt;@jdprovine&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Are you sure that your passive firewall is actually passive and not processing traffic. Just because this unit reports that it's staying in active after the split-brain event doesn't mean necessary&amp;nbsp;that the peer firewall didn't come to the same conclusion. During the 428s where you were in a split-brain event however you would definately have both firewalls processing traffic. &amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 20 Jul 2017 19:16:19 GMT</pubDate>
    <dc:creator>BPry</dc:creator>
    <dc:date>2017-07-20T19:16:19Z</dc:date>
    <item>
      <title>failover</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/failover/m-p/167499#M53484</link>
      <description>&lt;P&gt;Is there anything such as a particle failover with a palo alto firewall? Can it start to failover and suddenly fail back and block some traffic&lt;/P&gt;</description>
      <pubDate>Thu, 20 Jul 2017 17:12:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/failover/m-p/167499#M53484</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2017-07-20T17:12:46Z</dc:date>
    </item>
    <item>
      <title>Re: failover</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/failover/m-p/167508#M53485</link>
      <description>&lt;P&gt;There should be no partial failover.&lt;/P&gt;&lt;P&gt;Either active/passive or active/active.&lt;/P&gt;&lt;P&gt;Do you see failover event in System log?&lt;/P&gt;</description>
      <pubDate>Thu, 20 Jul 2017 17:29:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/failover/m-p/167508#M53485</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2017-07-20T17:29:01Z</dc:date>
    </item>
    <item>
      <title>Re: failover</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/failover/m-p/167510#M53486</link>
      <description>&lt;P&gt;PAN-OS 8.0.1?&lt;/P&gt;</description>
      <pubDate>Thu, 20 Jul 2017 17:33:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/failover/m-p/167510#M53486</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2017-07-20T17:33:14Z</dc:date>
    </item>
    <item>
      <title>Re: failover</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/failover/m-p/167511#M53487</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/16592"&gt;@Remo&lt;/a&gt;&lt;/P&gt;&lt;P&gt;I didn't think it was possible either but someone asked and I wanted more than just my answer I am about to check the system logs &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 20 Jul 2017 18:02:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/failover/m-p/167511#M53487</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2017-07-20T18:02:22Z</dc:date>
    </item>
    <item>
      <title>Re: failover</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/failover/m-p/167512#M53488</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/15603"&gt;@Raido_Rattameister&lt;/a&gt;&lt;/P&gt;&lt;P&gt;nope 7.1&lt;/P&gt;</description>
      <pubDate>Thu, 20 Jul 2017 18:02:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/failover/m-p/167512#M53488</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2017-07-20T18:02:42Z</dc:date>
    </item>
    <item>
      <title>Re: failover</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/failover/m-p/167513#M53489</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/15603"&gt;@Raido_Rattameister&lt;/a&gt;&amp;nbsp;&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/16592"&gt;@Remo&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;what is the event to look for in the system logs for a fail over is it failover?&lt;/P&gt;</description>
      <pubDate>Thu, 20 Jul 2017 18:10:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/failover/m-p/167513#M53489</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2017-07-20T18:10:27Z</dc:date>
    </item>
    <item>
      <title>Re: failover</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/failover/m-p/167521#M53491</link>
      <description>&lt;P&gt;( subtype eq ha)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 20 Jul 2017 18:29:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/failover/m-p/167521#M53491</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2017-07-20T18:29:07Z</dc:date>
    </item>
    <item>
      <title>Re: failover</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/failover/m-p/167524#M53493</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/15603"&gt;@Raido_Rattameister&lt;/a&gt;&lt;/P&gt;&lt;P&gt;I thought you were lauging at me LOL it seems to have lost it heartbeat connection but could that break anything once that condition is cleared?&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="spiltbraind.PNG" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/10471i0C0193DCEB635A77/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="spiltbraind.PNG" alt="spiltbraind.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 20 Jul 2017 18:39:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/failover/m-p/167524#M53493</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2017-07-20T18:39:21Z</dc:date>
    </item>
    <item>
      <title>Re: failover</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/failover/m-p/167525#M53494</link>
      <description>&lt;P&gt;If firewalls don't see each other over HA1 then both are active and accept sessions.&lt;/P&gt;&lt;P&gt;Shut down one firewall if you can't fix HA1 to get things up and running.&lt;/P&gt;&lt;P&gt;You have split brain situation.&lt;/P&gt;</description>
      <pubDate>Thu, 20 Jul 2017 18:49:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/failover/m-p/167525#M53494</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2017-07-20T18:49:08Z</dc:date>
    </item>
    <item>
      <title>Re: failover</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/failover/m-p/167528#M53496</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/15603"&gt;@Raido_Rattameister&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Its no longer in split brain that I can see , but we could restart the passive firewall right now and see what happens. It is trying to send traffice to a router IP that no longer exists&lt;/P&gt;</description>
      <pubDate>Thu, 20 Jul 2017 19:06:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/failover/m-p/167528#M53496</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2017-07-20T19:06:29Z</dc:date>
    </item>
    <item>
      <title>Re: failover</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/failover/m-p/167536#M53498</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/18719"&gt;@jdprovine&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Are you sure that your passive firewall is actually passive and not processing traffic. Just because this unit reports that it's staying in active after the split-brain event doesn't mean necessary&amp;nbsp;that the peer firewall didn't come to the same conclusion. During the 428s where you were in a split-brain event however you would definately have both firewalls processing traffic. &amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 20 Jul 2017 19:16:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/failover/m-p/167536#M53498</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2017-07-20T19:16:19Z</dc:date>
    </item>
    <item>
      <title>Re: failover</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/failover/m-p/167537#M53499</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&lt;/P&gt;&lt;P&gt;I am going to go check the traffic on the passive palo and see&lt;/P&gt;</description>
      <pubDate>Thu, 20 Jul 2017 19:26:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/failover/m-p/167537#M53499</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2017-07-20T19:26:33Z</dc:date>
    </item>
    <item>
      <title>Re: failover</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/failover/m-p/167538#M53500</link>
      <description>&lt;P&gt;But what would it route to an IP address that no longer is on the PA?&lt;/P&gt;</description>
      <pubDate>Thu, 20 Jul 2017 19:28:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/failover/m-p/167538#M53500</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2017-07-20T19:28:35Z</dc:date>
    </item>
    <item>
      <title>Re: failover</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/failover/m-p/167539#M53501</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/18719"&gt;@jdprovine&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Are the sessions routing to the non-existing IP possibly be tied to existing sessions? Depending on your policy setup it would continue to take that path, or attempt to. If this is tied to specific sources or destinations you could try clearing the session list with a filter for that criteria and see if that clears things up.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 20 Jul 2017 19:34:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/failover/m-p/167539#M53501</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2017-07-20T19:34:35Z</dc:date>
    </item>
    <item>
      <title>Re: failover</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/failover/m-p/167540#M53502</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&lt;/P&gt;&lt;P&gt;could there still be a session related to an IP that was removed several months ago from the PA? It also looks like the synch is still in progress between the two PA's and it seems like it is lasting too long&lt;/P&gt;</description>
      <pubDate>Thu, 20 Jul 2017 19:39:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/failover/m-p/167540#M53502</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2017-07-20T19:39:57Z</dc:date>
    </item>
    <item>
      <title>Re: failover</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/failover/m-p/167541#M53503</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/18719"&gt;@jdprovine&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;One would not expect so. When you say sync are you talking about the config sync?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 20 Jul 2017 19:42:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/failover/m-p/167541#M53503</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2017-07-20T19:42:11Z</dc:date>
    </item>
    <item>
      <title>Re: failover</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/failover/m-p/167542#M53504</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&lt;/P&gt;&lt;P&gt;Yes the config sync seems stuck&lt;/P&gt;</description>
      <pubDate>Thu, 20 Jul 2017 19:43:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/failover/m-p/167542#M53504</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2017-07-20T19:43:24Z</dc:date>
    </item>
    <item>
      <title>Re: failover</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/failover/m-p/167543#M53505</link>
      <description>&lt;P&gt;If you do a config audit between the active and passive firewall is anything actually different? Honestly it sounds like your Passive firewall got a little hosed; has it been restarted since the split-brain toke place?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 20 Jul 2017 19:45:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/failover/m-p/167543#M53505</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2017-07-20T19:45:17Z</dc:date>
    </item>
    <item>
      <title>Re: failover</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/failover/m-p/167544#M53506</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&lt;/P&gt;&lt;P&gt;I pushed a sync from the primary and it fixed it&lt;/P&gt;</description>
      <pubDate>Thu, 20 Jul 2017 19:48:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/failover/m-p/167544#M53506</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2017-07-20T19:48:36Z</dc:date>
    </item>
    <item>
      <title>Re: failover</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/failover/m-p/167545#M53507</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Yes we went ahead and restarted our secondary and that fixed the issue but I still don't know why it was going a route that no longer existed any ideas where to look?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 20 Jul 2017 20:06:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/failover/m-p/167545#M53507</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2017-07-20T20:06:07Z</dc:date>
    </item>
  </channel>
</rss>

