<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Normal behavior of LACP in passive/active HA setup. in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/normal-behavior-of-lacp-in-passive-active-ha-setup/m-p/207321#M60784</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When you said active links, is it the physical links or the aggregated interface?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;regards,&lt;/P&gt;&lt;P&gt;Jon&lt;/P&gt;</description>
    <pubDate>Mon, 26 Mar 2018 04:27:51 GMT</pubDate>
    <dc:creator>jlpanes24</dc:creator>
    <dc:date>2018-03-26T04:27:51Z</dc:date>
    <item>
      <title>Normal behavior of LACP in passive/active HA setup.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/normal-behavior-of-lacp-in-passive-active-ha-setup/m-p/207306#M60781</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I would just like to verify the normal behavior of LACP in an Active/Passive HA setting.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Currently we have a pair of PA-3060 running 6.1.10 in active/passive. Both devices have LACP bundles towards a Cisco router.&lt;/P&gt;&lt;P&gt;On the active firewall the LACP negotiates properly but on the passive firewall the interfaces shows up but doesnt negotiate the LACP session. Also on the Cisco router the portchannel towards the passive firewall goes into a suspended state since it detects that LACP is not enabled on the remote port.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is this the normal behavior? or is the prenegotiation of LACP for the passive firewall avaiable on this version or newer ones?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We are usually getting syslog messages from our Cisco router that the interfaces are down, and we need to check whether if its actually down or just connected to the passive firewall. We would like to minimize this false positives.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;regards,&lt;/P&gt;&lt;P&gt;Jon&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 26 Mar 2018 01:04:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/normal-behavior-of-lacp-in-passive-active-ha-setup/m-p/207306#M60781</guid>
      <dc:creator>jlpanes24</dc:creator>
      <dc:date>2018-03-26T01:04:12Z</dc:date>
    </item>
    <item>
      <title>Re: Normal behavior of LACP in passive/active HA setup.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/normal-behavior-of-lacp-in-passive-active-ha-setup/m-p/207314#M60782</link>
      <description>&lt;P&gt;This was added in PAN-OS 7.1 and should work with the PA-3000 series.&amp;nbsp; See the following documentation link from the PAN-OS 7.1 "new features guide":&lt;/P&gt;&lt;P&gt;&amp;nbsp;-&amp;nbsp;&lt;A href="https://www.paloaltonetworks.com/documentation/71/pan-os/newfeaturesguide/networking-features/lacp-and-lldp-pre-negotiation-on-an-ha-passive-firewall#_19978" target="_blank"&gt;https://www.paloaltonetworks.com/documentation/71/pan-os/newfeaturesguide/networking-features/lacp-and-lldp-pre-negotiation-on-an-ha-passive-firewall#_19978&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In releases before 7.1, it is expected that the passive firewall will not have an active LACP session and won't attempt to negotiate LACP until after it becomes the active firewall.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 26 Mar 2018 02:08:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/normal-behavior-of-lacp-in-passive-active-ha-setup/m-p/207314#M60782</guid>
      <dc:creator>jvalentine</dc:creator>
      <dc:date>2018-03-26T02:08:30Z</dc:date>
    </item>
    <item>
      <title>Re: Normal behavior of LACP in passive/active HA setup.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/normal-behavior-of-lacp-in-passive-active-ha-setup/m-p/207316#M60783</link>
      <description>It also depends on whether you have the fast fall-over enabled on the firewall. Forget the name for the option. With it disabled, the secondary firewall will not have active links until it becomes the primary, which could be a few seconds. With it enabled, the secondary firewall will have active links, but will not accept any ongoing traffic. When it becomes the primary, The active links start accepting traffic within milliseconds.</description>
      <pubDate>Mon, 26 Mar 2018 03:01:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/normal-behavior-of-lacp-in-passive-active-ha-setup/m-p/207316#M60783</guid>
      <dc:creator>fjwcash</dc:creator>
      <dc:date>2018-03-26T03:01:05Z</dc:date>
    </item>
    <item>
      <title>Re: Normal behavior of LACP in passive/active HA setup.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/normal-behavior-of-lacp-in-passive-active-ha-setup/m-p/207321#M60784</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When you said active links, is it the physical links or the aggregated interface?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;regards,&lt;/P&gt;&lt;P&gt;Jon&lt;/P&gt;</description>
      <pubDate>Mon, 26 Mar 2018 04:27:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/normal-behavior-of-lacp-in-passive-active-ha-setup/m-p/207321#M60784</guid>
      <dc:creator>jlpanes24</dc:creator>
      <dc:date>2018-03-26T04:27:51Z</dc:date>
    </item>
  </channel>
</rss>

