<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Failover Link Monitoring too long in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/failover-link-monitoring-too-long/m-p/240020#M68750</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;On you PAN did both the interfaces you have on the ae go down when the switch rebooted? You condition is set to ALL to both would need to go down in order for the failover to occur.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please advise,&lt;/P&gt;</description>
    <pubDate>Thu, 15 Nov 2018 17:35:19 GMT</pubDate>
    <dc:creator>OtakarKlier</dc:creator>
    <dc:date>2018-11-15T17:35:19Z</dc:date>
    <item>
      <title>Failover Link Monitoring too long</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/failover-link-monitoring-too-long/m-p/239842#M68714</link>
      <description>&lt;P&gt;Hello guys,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have 2 plao alto configured with HA Active/passive mode.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;On both firewall, I configured link monitoring on link group with ethernet 1/11 and ethernet1/13 that are aggregated on Ae1 with condition "ALL".&amp;nbsp;Those interfaces are plugged to a switch with LACP configuration and this switch is plugged to the Intrernet Router. The objective is to monitor my internet access and trigger a failover (Make my seond (PAssive) firewall in active mode.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When I reboot the switch on which my palo alto is plugged to test the failover, I lost around 30pings.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Moreover, in system logs, I see&amp;nbsp;HA Group 1: Moved from state Passive to state Non-Functional. What does that mean ? There is no failover process ? Active to passive and passive to active&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Maybe I don't understand very well how it works but I would like that my failover be quicker.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is that possible ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 14 Nov 2018 16:33:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/failover-link-monitoring-too-long/m-p/239842#M68714</guid>
      <dc:creator>David7660</dc:creator>
      <dc:date>2018-11-14T16:33:18Z</dc:date>
    </item>
    <item>
      <title>Re: Failover Link Monitoring too long</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/failover-link-monitoring-too-long/m-p/240020#M68750</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;On you PAN did both the interfaces you have on the ae go down when the switch rebooted? You condition is set to ALL to both would need to go down in order for the failover to occur.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please advise,&lt;/P&gt;</description>
      <pubDate>Thu, 15 Nov 2018 17:35:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/failover-link-monitoring-too-long/m-p/240020#M68750</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2018-11-15T17:35:19Z</dc:date>
    </item>
    <item>
      <title>Re: Failover Link Monitoring too long</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/failover-link-monitoring-too-long/m-p/240212#M68845</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/100455"&gt;@David7660&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;So the AE still needs to form on the passive device to get things functional again. Depneding on your platform you can actually setup pre-negotiation on the LACP links to make things a bit faster.&amp;nbsp;&lt;/P&gt;&lt;P&gt;On the AE interface select the LACP tab and select the 'Enable in HA Passive State' and commit the configuration. This will allow LACP communication on the passive device so failover is drastrically faster. Just make sure that you don't also have 'Same System MAC Address for Active-Passive HA' option enabled, as this wouldn't work with pre-negotiation.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 16 Nov 2018 22:53:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/failover-link-monitoring-too-long/m-p/240212#M68845</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2018-11-16T22:53:04Z</dc:date>
    </item>
    <item>
      <title>Re: Failover Link Monitoring too long</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/failover-link-monitoring-too-long/m-p/240484#M68903</link>
      <description>&lt;P&gt;Thanks to you, every options you mentionned are correctly defined on my palo alto.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Finaly, we think that's a routing problem with our ISP.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;To be confirmed with him.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 20 Nov 2018 09:33:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/failover-link-monitoring-too-long/m-p/240484#M68903</guid>
      <dc:creator>David7660</dc:creator>
      <dc:date>2018-11-20T09:33:16Z</dc:date>
    </item>
  </channel>
</rss>

