<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Failover issues with Active/Passive in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/failover-issues-with-active-passive/m-p/247404#M70392</link>
    <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/98673"&gt;@FarzanaMustafa&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/27580"&gt;@OtakarKlier&lt;/a&gt;&amp;nbsp;and&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/5300"&gt;@Brandon_Wertz&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;HA is configured directly from one firewall to another without any network devices in between.&amp;nbsp;We have four cables between the firewalls - two of them are used as primary HA links (Control&amp;nbsp;+ Data), and two ethernet interfaces are configured as backup HA interfaces (one for Control backup, and one for Data link backup, interfaces are not tagged).&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We manually suspend the primary firewall to fail-over to the secondary, then make the first one active again, and suspend the secondary to fail-over back primary.&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It makes no sense what-so-ever that you would have anything other than a milisecond failover on firewalls that are directly connected to each other.&amp;nbsp; Let alone multi-minute outages.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My deployment is acorss an OTV WAN link hundreds of miles away and our failover is instaneous.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 24 Jan 2019 18:44:55 GMT</pubDate>
    <dc:creator>Brandon_Wertz</dc:creator>
    <dc:date>2019-01-24T18:44:55Z</dc:date>
    <item>
      <title>Failover issues with Active/Passive</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/failover-issues-with-active-passive/m-p/246895#M70287</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Using 3020 HA pair.&amp;nbsp;We are currently having two issues regarding fail-over:&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Fail-over time from primary to secondary takes about two minutes. Fail-over back to the primary takes on average 10 minutes. This seems excessive for a production environment.&lt;/LI&gt;&lt;LI&gt;Once failed-over from primary to secondary, our externally-facing websites become inaccessible from the outside.&amp;nbsp;&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Both the issues have been observed since PAN-OS 7.1.10. Gone through several iterations of firmware upgrade and currently on 8.1.3, however, no change noticed.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Next device on the network after the firewalls are a Cisco Nexus stack.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Monitor Fail Hold Down Time (min)=1&lt;/P&gt;&lt;P&gt;Monitor Hold Time (ms)=3000&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any idea what is going on here?&lt;/P&gt;</description>
      <pubDate>Tue, 22 Jan 2019 05:43:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/failover-issues-with-active-passive/m-p/246895#M70287</guid>
      <dc:creator>FarzanaMustafa</dc:creator>
      <dc:date>2019-01-22T05:43:26Z</dc:date>
    </item>
    <item>
      <title>Re: Failover issues with Active/Passive</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/failover-issues-with-active-passive/m-p/246960#M70302</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/98673"&gt;@FarzanaMustafa&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Next device on the network after the firewalls are a Cisco Nexus stack.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Monitor Fail Hold Down Time (min)=1&lt;/P&gt;&lt;P&gt;Monitor Hold Time (ms)=3000&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any idea what is going on here?&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Nexus "stack?"&amp;nbsp; Can you ellaborate on the network architecure and how your HA interfaces are incorporated into the network?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The HA interfaces should be in a L2 VLAN, with no other ports anywhere on your network in that VLAN.&amp;nbsp; The HA interfaces themselves should just be normal access VLANs.&lt;/P&gt;</description>
      <pubDate>Tue, 22 Jan 2019 14:39:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/failover-issues-with-active-passive/m-p/246960#M70302</guid>
      <dc:creator>Brandon_Wertz</dc:creator>
      <dc:date>2019-01-22T14:39:58Z</dc:date>
    </item>
    <item>
      <title>Re: Failover issues with Active/Passive</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/failover-issues-with-active-passive/m-p/246973#M70307</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;What are you using as your test? Are you putting the active into suspend? Are you using ACI?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please advise,&lt;/P&gt;</description>
      <pubDate>Tue, 22 Jan 2019 16:24:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/failover-issues-with-active-passive/m-p/246973#M70307</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2019-01-22T16:24:08Z</dc:date>
    </item>
    <item>
      <title>Re: Failover issues with Active/Passive</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/failover-issues-with-active-passive/m-p/247257#M70364</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/27580"&gt;@OtakarKlier&lt;/a&gt;&amp;nbsp;and&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/5300"&gt;@Brandon_Wertz&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;HA is configured directly from one firewall to another without any network devices in between.&amp;nbsp;We have four cables between the firewalls - two of them are used as primary HA links (Control&amp;nbsp;+ Data), and two ethernet interfaces are configured as backup HA interfaces (one for Control backup, and one for Data link backup, interfaces are not tagged).&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We manually suspend the primary firewall to fail-over to the secondary, then make the first one active again, and suspend the secondary to fail-over back primary.&lt;/P&gt;</description>
      <pubDate>Thu, 24 Jan 2019 01:55:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/failover-issues-with-active-passive/m-p/247257#M70364</guid>
      <dc:creator>FarzanaMustafa</dc:creator>
      <dc:date>2019-01-24T01:55:47Z</dc:date>
    </item>
    <item>
      <title>Re: Failover issues with Active/Passive</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/failover-issues-with-active-passive/m-p/247395#M70387</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Are your Nexus in vPC? I have a similar setup and my failover is almost instantanious. Maybe open a tac case to make sure everything is running as it should?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Thu, 24 Jan 2019 17:17:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/failover-issues-with-active-passive/m-p/247395#M70387</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2019-01-24T17:17:47Z</dc:date>
    </item>
    <item>
      <title>Re: Failover issues with Active/Passive</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/failover-issues-with-active-passive/m-p/247404#M70392</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/98673"&gt;@FarzanaMustafa&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/27580"&gt;@OtakarKlier&lt;/a&gt;&amp;nbsp;and&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/5300"&gt;@Brandon_Wertz&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;HA is configured directly from one firewall to another without any network devices in between.&amp;nbsp;We have four cables between the firewalls - two of them are used as primary HA links (Control&amp;nbsp;+ Data), and two ethernet interfaces are configured as backup HA interfaces (one for Control backup, and one for Data link backup, interfaces are not tagged).&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We manually suspend the primary firewall to fail-over to the secondary, then make the first one active again, and suspend the secondary to fail-over back primary.&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It makes no sense what-so-ever that you would have anything other than a milisecond failover on firewalls that are directly connected to each other.&amp;nbsp; Let alone multi-minute outages.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My deployment is acorss an OTV WAN link hundreds of miles away and our failover is instaneous.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 24 Jan 2019 18:44:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/failover-issues-with-active-passive/m-p/247404#M70392</guid>
      <dc:creator>Brandon_Wertz</dc:creator>
      <dc:date>2019-01-24T18:44:55Z</dc:date>
    </item>
    <item>
      <title>Re: Failover issues with Active/Passive</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/failover-issues-with-active-passive/m-p/249346#M70906</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Just wanted to let you all know that TAC team has assisted on this issue. Below files/info were collected and after analyzing them the conclusion was:&amp;nbsp;&lt;SPAN&gt;Seems to be an external issue, PA ARP requests/replies are not delivered to end host.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;-Packet capture for Non-IP traffic on both the firewalls. Perform this packet capture while performing the failover. We want to see whether new primary firewall is sending GARP immediately or not.&lt;BR /&gt;-Keep a continuous ping running through HA and include this in packet filter for above capture. One filter will capture all non-IP traffic and other filter would be for ping.&lt;BR /&gt;-Perform a failover, write down timestamp, time required to recover and minutes of outage.&lt;BR /&gt;-Collect packet captures, session output for ping(from host machine), global counters.&lt;/P&gt;&lt;P&gt;-Tech Support files&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Closing this post now. Client will check&amp;nbsp;connected switches and devices to understand why ARP replies/requests are not delivered to end host.&lt;/P&gt;</description>
      <pubDate>Thu, 07 Feb 2019 21:49:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/failover-issues-with-active-passive/m-p/249346#M70906</guid>
      <dc:creator>FarzanaMustafa</dc:creator>
      <dc:date>2019-02-07T21:49:13Z</dc:date>
    </item>
  </channel>
</rss>

