<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Vsys + Failover config (Urgent!) in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/vsys-failover-config-urgent/m-p/230320#M66203</link>
    <description>&lt;P&gt;thanks&amp;nbsp;&lt;SPAN class=""&gt;&lt;A href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/16592" target="_self"&gt;vsys_remo&lt;/A&gt;&amp;nbsp;for your swift response.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;Just one more question before I let you go. The reason I was asking my original question was that I have been told that currently one of the VSYS i.e VSYS4 is configured with "No Failover" and the task is to reconfigure it to "failover"&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;I had a brief look and here is my finding on the appliance:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;vsys4(active)&amp;gt; show high-availability state&lt;/P&gt;&lt;P&gt;Group 16: abcdef&lt;BR /&gt;Mode: Active-Passive&lt;BR /&gt;Local Information:&lt;BR /&gt;Version: 1&lt;BR /&gt;Mode: Active-Passive&lt;BR /&gt;State: active (last 205 days)&lt;BR /&gt;Last non-functional state reason: Link down&lt;BR /&gt;Device Information:&lt;BR /&gt;Management IPv4 Address: x.x.x.x/24&lt;BR /&gt;Management IPv6 Address:&lt;BR /&gt;Mgmt HB Backup configured&lt;BR /&gt;Jumbo-Frames disabled; MTU 1500&lt;BR /&gt;HA1 Control Links Joint Configuration:&lt;BR /&gt;Encryption Enabled: no&lt;BR /&gt;Election Option Information:&lt;BR /&gt;Priority: 100&lt;BR /&gt;Preemptive: yes&lt;BR /&gt;Version Compatibility:&lt;BR /&gt;Software Version: Match&lt;BR /&gt;Application Content Compatibility: Match&lt;BR /&gt;Anti-Virus Compatibility: Match&lt;BR /&gt;Threat Content Compatibility: Match&lt;BR /&gt;VPN Client Software Compatibility: Match&lt;BR /&gt;Global Protect Client Software Compatibility: Match&lt;BR /&gt;State Synchronization: Complete; type: ethernet&lt;BR /&gt;Peer Information:&lt;BR /&gt;Connection status: up&lt;BR /&gt;Version: 1&lt;BR /&gt;Mode: Active-Passive&lt;BR /&gt;State: passive (last 205 days)&lt;BR /&gt;Last non-functional state reason: Link down&lt;BR /&gt;Device Information:&lt;BR /&gt;Management IPv4 Address: x.x.x.b/24&lt;BR /&gt;Management IPv6 Address:&lt;BR /&gt;Mgmt HB Backup Connection up&lt;BR /&gt;Jumbo-Frames disabled; MTU 1500&lt;BR /&gt;Connection up; Primary HA1 link&lt;BR /&gt;Connection up&lt;BR /&gt;Election Option Information:&lt;BR /&gt;Priority: 200&lt;BR /&gt;Preemptive: yes&lt;BR /&gt;Configuration Synchronization:&lt;BR /&gt;Enabled: yes&lt;BR /&gt;Running Configuration: synchronized&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Do you this the statemen: configured with "no failover" is true? as form what you said it doesnt look like. if it is, then how I would configure it with failover.&lt;/P&gt;&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/16592"&gt;@Remo&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/97168"&gt;@qasim02&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;No, in general the HA failover is not vsys specific, which means in Active/Passive HA all vsys are active on one firewall and in case of a failover they all switch to the other device. With active/active mode you can configure "something" to distribute the vsys over the two devices but with the vsys specific failover it gets tricky.&lt;/P&gt;&lt;P&gt;You can find all the HA related information in the official documentation:&amp;nbsp;&lt;A href="https://www.paloaltonetworks.com/documentation/71/pan-os/pan-os/high-availability" target="_blank"&gt;https://www.paloaltonetworks.com/documentation/71/pan-os/pan-os/high-availability&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Btw: in case you are running PAN-OS 7.0.x you should upgrade to at least the latest 7.1.x release because 7.0 is end of life since December 4, 2017. The software end of life dates you can find here:&amp;nbsp;&lt;A href="https://www.paloaltonetworks.com/services/support/end-of-life-announcements/end-of-life-summary" target="_blank"&gt;https://www.paloaltonetworks.com/services/support/end-of-life-announcements/end-of-life-summary&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Remo&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;PS: What is the "urgent" for in the title? In case of urgent problems you may be should reach out to support (even though the answers in the live community are pretty fast &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 11 Sep 2018 10:39:49 GMT</pubDate>
    <dc:creator>qasim02</dc:creator>
    <dc:date>2018-09-11T10:39:49Z</dc:date>
    <item>
      <title>Vsys + Failover config (Urgent!)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vsys-failover-config-urgent/m-p/230308#M66200</link>
      <description>&lt;P&gt;&amp;nbsp;Hi,&lt;/P&gt;&lt;P&gt;I am very new to PaloAlto and currently trying to figure out the following:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1. is HA or Failover VSYS specific?&amp;nbsp;&lt;/P&gt;&lt;P&gt;2. if so, how do I find failover/HA config per vsys?&lt;/P&gt;&lt;P&gt;3. How do I setup failover/HA per vsys?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;the appliance i am using is&amp;nbsp;&lt;SPAN&gt;PA-3020 software version 7.x.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I will really appreciate your help with this.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Kind regards,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Ali&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 11 Sep 2018 09:35:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vsys-failover-config-urgent/m-p/230308#M66200</guid>
      <dc:creator>qasim02</dc:creator>
      <dc:date>2018-09-11T09:35:18Z</dc:date>
    </item>
    <item>
      <title>Re: Vsys + Failover config (Urgent!)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vsys-failover-config-urgent/m-p/230318#M66202</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/97168"&gt;@qasim02&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;No, in general the HA failover is not vsys specific, which means in Active/Passive HA all vsys are active on one firewall and in case of a failover they all switch to the other device. With active/active mode you can configure "something" to distribute the vsys over the two devices but with the vsys specific failover it gets tricky.&lt;/P&gt;&lt;P&gt;You can find all the HA related information in the official documentation:&amp;nbsp;&lt;A href="https://www.paloaltonetworks.com/documentation/71/pan-os/pan-os/high-availability" target="_blank"&gt;https://www.paloaltonetworks.com/documentation/71/pan-os/pan-os/high-availability&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Btw: in case you are running PAN-OS 7.0.x you should upgrade to at least the latest 7.1.x release because 7.0 is end of life since December 4, 2017. The software end of life dates you can find here:&amp;nbsp;&lt;A href="https://www.paloaltonetworks.com/services/support/end-of-life-announcements/end-of-life-summary" target="_blank"&gt;https://www.paloaltonetworks.com/services/support/end-of-life-announcements/end-of-life-summary&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Remo&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;PS: What is the "urgent" for in the title? In case of urgent problems you may be should reach out to support (even though the answers in the live community are pretty fast &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 11 Sep 2018 10:13:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vsys-failover-config-urgent/m-p/230318#M66202</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2018-09-11T10:13:06Z</dc:date>
    </item>
    <item>
      <title>Re: Vsys + Failover config (Urgent!)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vsys-failover-config-urgent/m-p/230320#M66203</link>
      <description>&lt;P&gt;thanks&amp;nbsp;&lt;SPAN class=""&gt;&lt;A href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/16592" target="_self"&gt;vsys_remo&lt;/A&gt;&amp;nbsp;for your swift response.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;Just one more question before I let you go. The reason I was asking my original question was that I have been told that currently one of the VSYS i.e VSYS4 is configured with "No Failover" and the task is to reconfigure it to "failover"&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;I had a brief look and here is my finding on the appliance:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;vsys4(active)&amp;gt; show high-availability state&lt;/P&gt;&lt;P&gt;Group 16: abcdef&lt;BR /&gt;Mode: Active-Passive&lt;BR /&gt;Local Information:&lt;BR /&gt;Version: 1&lt;BR /&gt;Mode: Active-Passive&lt;BR /&gt;State: active (last 205 days)&lt;BR /&gt;Last non-functional state reason: Link down&lt;BR /&gt;Device Information:&lt;BR /&gt;Management IPv4 Address: x.x.x.x/24&lt;BR /&gt;Management IPv6 Address:&lt;BR /&gt;Mgmt HB Backup configured&lt;BR /&gt;Jumbo-Frames disabled; MTU 1500&lt;BR /&gt;HA1 Control Links Joint Configuration:&lt;BR /&gt;Encryption Enabled: no&lt;BR /&gt;Election Option Information:&lt;BR /&gt;Priority: 100&lt;BR /&gt;Preemptive: yes&lt;BR /&gt;Version Compatibility:&lt;BR /&gt;Software Version: Match&lt;BR /&gt;Application Content Compatibility: Match&lt;BR /&gt;Anti-Virus Compatibility: Match&lt;BR /&gt;Threat Content Compatibility: Match&lt;BR /&gt;VPN Client Software Compatibility: Match&lt;BR /&gt;Global Protect Client Software Compatibility: Match&lt;BR /&gt;State Synchronization: Complete; type: ethernet&lt;BR /&gt;Peer Information:&lt;BR /&gt;Connection status: up&lt;BR /&gt;Version: 1&lt;BR /&gt;Mode: Active-Passive&lt;BR /&gt;State: passive (last 205 days)&lt;BR /&gt;Last non-functional state reason: Link down&lt;BR /&gt;Device Information:&lt;BR /&gt;Management IPv4 Address: x.x.x.b/24&lt;BR /&gt;Management IPv6 Address:&lt;BR /&gt;Mgmt HB Backup Connection up&lt;BR /&gt;Jumbo-Frames disabled; MTU 1500&lt;BR /&gt;Connection up; Primary HA1 link&lt;BR /&gt;Connection up&lt;BR /&gt;Election Option Information:&lt;BR /&gt;Priority: 200&lt;BR /&gt;Preemptive: yes&lt;BR /&gt;Configuration Synchronization:&lt;BR /&gt;Enabled: yes&lt;BR /&gt;Running Configuration: synchronized&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Do you this the statemen: configured with "no failover" is true? as form what you said it doesnt look like. if it is, then how I would configure it with failover.&lt;/P&gt;&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/16592"&gt;@Remo&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/97168"&gt;@qasim02&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;No, in general the HA failover is not vsys specific, which means in Active/Passive HA all vsys are active on one firewall and in case of a failover they all switch to the other device. With active/active mode you can configure "something" to distribute the vsys over the two devices but with the vsys specific failover it gets tricky.&lt;/P&gt;&lt;P&gt;You can find all the HA related information in the official documentation:&amp;nbsp;&lt;A href="https://www.paloaltonetworks.com/documentation/71/pan-os/pan-os/high-availability" target="_blank"&gt;https://www.paloaltonetworks.com/documentation/71/pan-os/pan-os/high-availability&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Btw: in case you are running PAN-OS 7.0.x you should upgrade to at least the latest 7.1.x release because 7.0 is end of life since December 4, 2017. The software end of life dates you can find here:&amp;nbsp;&lt;A href="https://www.paloaltonetworks.com/services/support/end-of-life-announcements/end-of-life-summary" target="_blank"&gt;https://www.paloaltonetworks.com/services/support/end-of-life-announcements/end-of-life-summary&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Remo&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;PS: What is the "urgent" for in the title? In case of urgent problems you may be should reach out to support (even though the answers in the live community are pretty fast &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 11 Sep 2018 10:39:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vsys-failover-config-urgent/m-p/230320#M66203</guid>
      <dc:creator>qasim02</dc:creator>
      <dc:date>2018-09-11T10:39:49Z</dc:date>
    </item>
    <item>
      <title>Re: Vsys + Failover config (Urgent!)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vsys-failover-config-urgent/m-p/230321#M66204</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/97168"&gt;@qasim02&lt;/a&gt;&lt;/P&gt;&lt;P&gt;There isn't any "no failover" setting that you can set for a single vsys.&lt;/P&gt;</description>
      <pubDate>Tue, 11 Sep 2018 10:46:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vsys-failover-config-urgent/m-p/230321#M66204</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2018-09-11T10:46:47Z</dc:date>
    </item>
    <item>
      <title>Re: Vsys + Failover config (Urgent!)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vsys-failover-config-urgent/m-p/230322#M66205</link>
      <description>&lt;P&gt;hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/97168"&gt;@qasim02&lt;/a&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;there is no 'no failover' settings for vsys in a HA environment&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;in A/P the entire chassis goes doen if there is a failover (so there is no way for a vsys to 'remain behind')&lt;/P&gt;
&lt;P&gt;in A/A you could potentially set something up with dynamic routing that directs specific 'vsys' oriented traffic to either one of the peers, but this is still external to the vsys themselves&lt;/P&gt;</description>
      <pubDate>Tue, 11 Sep 2018 10:47:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vsys-failover-config-urgent/m-p/230322#M66205</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2018-09-11T10:47:22Z</dc:date>
    </item>
    <item>
      <title>Re: Vsys + Failover config (Urgent!)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vsys-failover-config-urgent/m-p/230333#M66213</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/97168"&gt;@qasim02&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Is it possible that whoever told you vsys4 is setup with 'no failover' was simply refering to Link/Path monitoring not being configured. For example vsys4 is assigned ethernet1/4 and you aren't actually monitoring that interface?&amp;nbsp;&lt;/P&gt;&lt;P&gt;That's the only thing I can think of that they could have said "yup, vsys4 isn't configured for HA". It would be a&amp;nbsp;&lt;EM&gt;really&lt;/EM&gt; bad way of communicating that, but short of them having no idea what they're talking about that's the only solution I can come up with.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 11 Sep 2018 13:10:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vsys-failover-config-urgent/m-p/230333#M66213</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2018-09-11T13:10:13Z</dc:date>
    </item>
    <item>
      <title>Re: Vsys + Failover config (Urgent!)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vsys-failover-config-urgent/m-p/230662#M66264</link>
      <description>&lt;P&gt;Thanks Bpry,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;you were absolutely right as thats exactly what I discovered upon furthe rinvestigation.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;now question is how I should go about enabling link/path monitoring for the interfaces assigned to this Vsys. I know I can find alot of documents online that says it all but nothing beats experience? could you kindly summarise the steps? and what do you think are the main things I should be looking out for?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Kind regards,&lt;/P&gt;&lt;P&gt;Ali&lt;/P&gt;</description>
      <pubDate>Thu, 13 Sep 2018 07:55:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vsys-failover-config-urgent/m-p/230662#M66264</guid>
      <dc:creator>qasim02</dc:creator>
      <dc:date>2018-09-13T07:55:21Z</dc:date>
    </item>
    <item>
      <title>Re: Vsys + Failover config (Urgent!)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vsys-failover-config-urgent/m-p/230731#M66281</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/97168"&gt;@qasim02&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Link and Path monitoring is pretty easy.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Link Monitoring&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Generally I configure a Link Group for each Zone of the vsys, and set the Group Failure Condition to whatever makes the most sense. Do I have a single 10Gb connection to my Trust zone; but it in a Link Group and set the failure condition to any and assign that interface to the link group. If I have 4 interfaces assigned to an aggregate-group for my Datacenter zone I would assign all of those interfaces to a Link Group and would probably want to set the Group Failure Condition to all instead of any.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Path Group&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;I normally recommend that you monitor a couple hosts within any zone and setup the rules however you would want. Essentially what I'm using Path Group for is ensuring that I might still have a link state of Up, but I want to ensure that I don't have a break further along.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 13 Sep 2018 15:01:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vsys-failover-config-urgent/m-p/230731#M66281</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2018-09-13T15:01:14Z</dc:date>
    </item>
  </channel>
</rss>

