<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Any Packet Lost when Changeing Interface Type from HA to Aggregate (of HA type) in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/any-packet-lost-when-changeing-interface-type-from-ha-to/m-p/169788#M53904</link>
    <description>&lt;P&gt;I would not recommend doing this on a live environment outside a maintenance window&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Since the HA cluster is Active/Active I assume you have plenty of asymmetrical sessions?&lt;/P&gt;
&lt;P&gt;If you change the HA3 interface, this should not impact the firewall's ports or local processing, but this will temporarily interrupt the forwarding of packets over HA3 for remote processing.&lt;/P&gt;
&lt;P&gt;In case of asymmetric routing, a lot of packetforwarding could be happening over the HA3 links which will negatively impact your active sessions.&lt;/P&gt;</description>
    <pubDate>Thu, 03 Aug 2017 09:36:18 GMT</pubDate>
    <dc:creator>reaper</dc:creator>
    <dc:date>2017-08-03T09:36:18Z</dc:date>
    <item>
      <title>Any Packet Lost when Changeing Interface Type from HA to Aggregate (of HA type)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/any-packet-lost-when-changeing-interface-type-from-ha-to/m-p/169722#M53893</link>
      <description>&lt;P&gt;We have an Active/Active PA-5050's in production with HA3 running on a single ethernet (1GB).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I need to know if there will be any packet lost (HA packet forwarding) if I change this interface from HA type to AE type/AE group (e.g. ae8). Considering that this aggregated group (ae8) has been already created and have another ethernet (1GB) already as a member up and running.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have lab tested, making these changes on active-primary;&lt;/P&gt;&lt;P&gt;Changing the active/active config from ethernet interface to the new ae8&lt;/P&gt;&lt;P&gt;And also changing the old single HA3 ethernet interface to be the second member of this new ae8&lt;/P&gt;&lt;P&gt;Then commit on active-primary.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Config synced to peer, with no obvious evidence of interfaces going down or any change in firewalls states. Also, I had to change the active/active config from ethernet interface to the new ae8 on active-secondary and commit after above done.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Each of these two ethernet interfaces directly conencted to their peers on the other firewall.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Does it make sense to assume, there will be no packet lost on HA3 link or outage for customer during this process.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 03 Aug 2017 05:46:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/any-packet-lost-when-changeing-interface-type-from-ha-to/m-p/169722#M53893</guid>
      <dc:creator>Mass</dc:creator>
      <dc:date>2017-08-03T05:46:52Z</dc:date>
    </item>
    <item>
      <title>Re: Any Packet Lost when Changeing Interface Type from HA to Aggregate (of HA type)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/any-packet-lost-when-changeing-interface-type-from-ha-to/m-p/169770#M53899</link>
      <description>&lt;P&gt;I would suspect that there may&amp;nbsp;be some traffic issues. Possibly for those sessions which are already established. I would suggest to give a try with some live traffic.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Firewall has to internally create a map of ports and ids to forward the traffic.&lt;/P&gt;&lt;P&gt;Also MAC address linked to HA3 ports will change.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It is possible that the existing packets or sessions might see some issue during the change.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You can assume this to be same as if you change a network port from a standalone to HA or AGG port.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you run into issues with live traffic in your lab, I would suggest open a TAC case to investigate.&lt;/P&gt;</description>
      <pubDate>Thu, 03 Aug 2017 08:46:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/any-packet-lost-when-changeing-interface-type-from-ha-to/m-p/169770#M53899</guid>
      <dc:creator>abjain</dc:creator>
      <dc:date>2017-08-03T08:46:43Z</dc:date>
    </item>
    <item>
      <title>Re: Any Packet Lost when Changeing Interface Type from HA to Aggregate (of HA type)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/any-packet-lost-when-changeing-interface-type-from-ha-to/m-p/169788#M53904</link>
      <description>&lt;P&gt;I would not recommend doing this on a live environment outside a maintenance window&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Since the HA cluster is Active/Active I assume you have plenty of asymmetrical sessions?&lt;/P&gt;
&lt;P&gt;If you change the HA3 interface, this should not impact the firewall's ports or local processing, but this will temporarily interrupt the forwarding of packets over HA3 for remote processing.&lt;/P&gt;
&lt;P&gt;In case of asymmetric routing, a lot of packetforwarding could be happening over the HA3 links which will negatively impact your active sessions.&lt;/P&gt;</description>
      <pubDate>Thu, 03 Aug 2017 09:36:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/any-packet-lost-when-changeing-interface-type-from-ha-to/m-p/169788#M53904</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2017-08-03T09:36:18Z</dc:date>
    </item>
    <item>
      <title>Re: Any Packet Lost when Changeing Interface Type from HA to Aggregate (of HA type)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/any-packet-lost-when-changeing-interface-type-from-ha-to/m-p/169985#M53963</link>
      <description>&lt;P&gt;Indeed this will be done during an agreed change window with customer. I am planning to layout the steps in a way to minimize the outage or if possible eliminate it all together.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 04 Aug 2017 00:25:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/any-packet-lost-when-changeing-interface-type-from-ha-to/m-p/169985#M53963</guid>
      <dc:creator>Mass</dc:creator>
      <dc:date>2017-08-04T00:25:24Z</dc:date>
    </item>
  </channel>
</rss>

