<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: suspend both firewall in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/suspend-both-firewall/m-p/198539#M58928</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/18719"&gt;@jdprovine&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Touching/expanding on what&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/9981"&gt;@Mick_Ball&lt;/a&gt;&amp;nbsp;stated; when you suspend the firewall HA is no longer functional. 'Suspend' is referenced a lot like it's some kind of 'HA Failover' command, and it is in the sense that it will cause an HA failover. That being said, you bring the device to a non-functional device. Once a firewall is in the 'suspended' state, it can&amp;nbsp;&lt;EM&gt;only&lt;/EM&gt; be made functional manually.&amp;nbsp;&lt;/P&gt;&lt;P&gt;This is done so that any issue that would normally force the firewall to enter a 'suspended' state automatically, such as interface/path monitoring flaps, preemption issues, do not continue to cause flapping across the HA pair. When you 'suspend' your other HA unit you'll effectively be left without a functional device.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 02 Feb 2018 15:18:10 GMT</pubDate>
    <dc:creator>BPry</dc:creator>
    <dc:date>2018-02-02T15:18:10Z</dc:date>
    <item>
      <title>suspend both firewall</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/suspend-both-firewall/m-p/198203#M58853</link>
      <description>&lt;P&gt;What would happen if you suspended both of your firewall in an active/passive HA configuration? Starting with suspending the passive firewall first and then the primary firewall.&lt;/P&gt;</description>
      <pubDate>Thu, 01 Feb 2018 14:23:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/suspend-both-firewall/m-p/198203#M58853</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2018-02-01T14:23:17Z</dc:date>
    </item>
    <item>
      <title>Re: suspend both firewall</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/suspend-both-firewall/m-p/198212#M58854</link>
      <description>&lt;P&gt;two things....&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1. helpdesk phones begin to melt..&lt;/P&gt;&lt;P&gt;2. start looking for a job at your local supermarket..&lt;/P&gt;</description>
      <pubDate>Thu, 01 Feb 2018 14:33:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/suspend-both-firewall/m-p/198212#M58854</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2018-02-01T14:33:25Z</dc:date>
    </item>
    <item>
      <title>Re: suspend both firewall</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/suspend-both-firewall/m-p/198219#M58856</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/9981"&gt;@Mick_Ball&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I like your answer it's very creative. So the flow stops passing through both PA's. I would have thought they would just no longer be in HA or maybe they would be in a split-brain state.&lt;/P&gt;</description>
      <pubDate>Thu, 01 Feb 2018 14:52:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/suspend-both-firewall/m-p/198219#M58856</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2018-02-01T14:52:39Z</dc:date>
    </item>
    <item>
      <title>Re: suspend both firewall</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/suspend-both-firewall/m-p/198228#M58858</link>
      <description>&lt;P&gt;well i did have a little play on our test boxes after your post and I suppose the most logical explanation is that you are suspending the device, not the HA status. Albeit not the management interface.... and yes all interfaces were rouge..&lt;/P&gt;</description>
      <pubDate>Thu, 01 Feb 2018 15:30:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/suspend-both-firewall/m-p/198228#M58858</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2018-02-01T15:30:34Z</dc:date>
    </item>
    <item>
      <title>Re: suspend both firewall</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/suspend-both-firewall/m-p/198236#M58859</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/9981"&gt;@Mick_Ball&lt;/a&gt;&lt;/P&gt;&lt;P&gt;Thanks for testing it for me, wish I had some test boxes are they hardware or virtual? I guess I won't be trying that on my real network since I don't like melting phones or slinging burgers.&lt;/P&gt;</description>
      <pubDate>Thu, 01 Feb 2018 15:32:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/suspend-both-firewall/m-p/198236#M58859</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2018-02-01T15:32:58Z</dc:date>
    </item>
    <item>
      <title>Re: suspend both firewall</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/suspend-both-firewall/m-p/198246#M58861</link>
      <description>&lt;P&gt;they are hardware (3050's).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;for the record....&lt;/P&gt;&lt;P&gt;we are currently running all of our boxes on 7.1.15, we tried an upgrade to 8 last year and had to roll back,&lt;/P&gt;&lt;P&gt;partly because of the early release of 8 that we were using, partly because I'm still struggling with some of the next generation stuff...&lt;/P&gt;&lt;P&gt;the company took the option to purchase 2 spares for testing the next upgrade to 8.07, also it's nice to have a hot standby as not all of our firewalls are HA. further down the line we have a new site to cope with so they will eventually be used for that...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;off the record....&lt;/P&gt;&lt;P&gt;you know how it works when departments have asked for x ammount of money and don't spend it by the end of the year...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;laters...&lt;/P&gt;</description>
      <pubDate>Thu, 01 Feb 2018 15:50:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/suspend-both-firewall/m-p/198246#M58861</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2018-02-01T15:50:56Z</dc:date>
    </item>
    <item>
      <title>Re: suspend both firewall</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/suspend-both-firewall/m-p/198268#M58869</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/9981"&gt;@Mick_Ball&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Your company must have access to way more money than we do LOL. I have be comtemplating upgrading to 8 during the summer break but the issues with xauth &amp;amp; the VPN are making me thing twice about it&lt;/P&gt;</description>
      <pubDate>Thu, 01 Feb 2018 16:46:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/suspend-both-firewall/m-p/198268#M58869</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2018-02-01T16:46:44Z</dc:date>
    </item>
    <item>
      <title>Re: suspend both firewall</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/suspend-both-firewall/m-p/198539#M58928</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/18719"&gt;@jdprovine&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Touching/expanding on what&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/9981"&gt;@Mick_Ball&lt;/a&gt;&amp;nbsp;stated; when you suspend the firewall HA is no longer functional. 'Suspend' is referenced a lot like it's some kind of 'HA Failover' command, and it is in the sense that it will cause an HA failover. That being said, you bring the device to a non-functional device. Once a firewall is in the 'suspended' state, it can&amp;nbsp;&lt;EM&gt;only&lt;/EM&gt; be made functional manually.&amp;nbsp;&lt;/P&gt;&lt;P&gt;This is done so that any issue that would normally force the firewall to enter a 'suspended' state automatically, such as interface/path monitoring flaps, preemption issues, do not continue to cause flapping across the HA pair. When you 'suspend' your other HA unit you'll effectively be left without a functional device.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 02 Feb 2018 15:18:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/suspend-both-firewall/m-p/198539#M58928</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2018-02-02T15:18:10Z</dc:date>
    </item>
    <item>
      <title>Re: suspend both firewall</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/suspend-both-firewall/m-p/337721#M84997</link>
      <description>&lt;P&gt;If i suspended the primary firewall and doing restart the same primary firewall. post restart it will be in suspended state or functional state ?&lt;/P&gt;</description>
      <pubDate>Fri, 10 Jul 2020 14:16:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/suspend-both-firewall/m-p/337721#M84997</guid>
      <dc:creator>CSSCORP</dc:creator>
      <dc:date>2020-07-10T14:16:22Z</dc:date>
    </item>
    <item>
      <title>Re: suspend both firewall</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/suspend-both-firewall/m-p/337728#M84998</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/78296"&gt;@CSSCORP&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;Once you restart the device it will be in the default 'functional' state, not suspended. This is why the upgrade procedure says that you should disable preempt, as it would prevent the primary device from automatically re-taking the active state until you want it to do so.&lt;/P&gt;</description>
      <pubDate>Fri, 10 Jul 2020 14:23:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/suspend-both-firewall/m-p/337728#M84998</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2020-07-10T14:23:31Z</dc:date>
    </item>
  </channel>
</rss>

