<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Active/Active HA tentative state question in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/active-active-ha-tentative-state-question/m-p/214304#M62285</link>
    <description>&lt;P&gt;OK, since the packet is processed by the active peer, where should the packet be seen in the traffic log. On the active one or the tentative one?&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 15 May 2018 12:44:28 GMT</pubDate>
    <dc:creator>PerryK</dc:creator>
    <dc:date>2018-05-15T12:44:28Z</dc:date>
    <item>
      <title>Active/Active HA tentative state question</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/active-active-ha-tentative-state-question/m-p/214196#M62259</link>
      <description>&lt;P&gt;Let's say we have 2 firewalls in A/A HA&lt;/P&gt;&lt;P&gt;each firewall has 2 vWire (single interfaces, no aggregration)&lt;/P&gt;&lt;P&gt;eth1/eth2 = vWire 1 and eth3/eth4=vWire2&lt;/P&gt;&lt;P&gt;link monitoring is set such that if any of eth1/eth2 interfaces are down or any of eth3/eth4 are down the firewall will go into tentative state.&lt;/P&gt;&lt;P&gt;Say I unplug eth1/eth2 on FW1. FW1 goes into tentative state. Now, no traffic should flow on vWire2 (eth3/eth4) of FW1.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can ayone confirm this?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 14 May 2018 15:08:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/active-active-ha-tentative-state-question/m-p/214196#M62259</guid>
      <dc:creator>PerryK</dc:creator>
      <dc:date>2018-05-14T15:08:24Z</dc:date>
    </item>
    <item>
      <title>Re: Active/Active HA tentative state question</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/active-active-ha-tentative-state-question/m-p/214262#M62273</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/83727"&gt;@PerryK&lt;/a&gt;&lt;/P&gt;
&lt;P&gt;in an AP cluster a link monitor failure is a global failure causing the membert to go into a non-functional state and stop passing traffic altogether, passing over all responsabilities to the secondary peer&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;in an AA cluster, however, the member will continue accepting packets, if at all possible, but will pass everything over to it's peer for processiong via the HA3 link&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.paloaltonetworks.com/documentation/80/pan-os/pan-os/high-availability/ha-firewall-states" target="_blank"&gt;https://www.paloaltonetworks.com/documentation/80/pan-os/pan-os/high-availability/ha-firewall-states&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;so, if you unplug eth1, eth2 will go down (link state passthrough property of vwire), eth1/eth2 vwire functionality passes over to member2 completely as this will be the only member with an active set left.&lt;/P&gt;
&lt;P&gt;eth3/eth4 vwire, however, will remain active and will accept packets on member1, but all packets are forwarded through the HA3 interface to member2, processed and sent back to member1 and then egressed out on the other end of the vwire&lt;/P&gt;</description>
      <pubDate>Tue, 15 May 2018 06:55:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/active-active-ha-tentative-state-question/m-p/214262#M62273</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2018-05-15T06:55:00Z</dc:date>
    </item>
    <item>
      <title>Re: Active/Active HA tentative state question</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/active-active-ha-tentative-state-question/m-p/214304#M62285</link>
      <description>&lt;P&gt;OK, since the packet is processed by the active peer, where should the packet be seen in the traffic log. On the active one or the tentative one?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 15 May 2018 12:44:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/active-active-ha-tentative-state-question/m-p/214304#M62285</guid>
      <dc:creator>PerryK</dc:creator>
      <dc:date>2018-05-15T12:44:28Z</dc:date>
    </item>
    <item>
      <title>Re: Active/Active HA tentative state question</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/active-active-ha-tentative-state-question/m-p/214305#M62286</link>
      <description>&lt;P&gt;probably both &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 15 May 2018 12:53:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/active-active-ha-tentative-state-question/m-p/214305#M62286</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2018-05-15T12:53:17Z</dc:date>
    </item>
  </channel>
</rss>

