<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic LCAP down on Passive Firewal in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/lcap-down-on-passive-firewal/m-p/254678#M72275</link>
    <description>&lt;P&gt;Hello team,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In an HA environment, with pre-negotiation for LCAP disabled , but passive link state set to "Auto" in the HA configuration, if all physical interfaces show as up, is the AE (Aggregated Interface) supposed to be up or down,&amp;nbsp; as the partner (Cisco Switch) is showing suspended on the LCAP interface.&lt;/P&gt;&lt;P&gt;Also from PA the CLi is showing no partner:&lt;/P&gt;&lt;PRE&gt;AE group: ae1
Members:          Bndl Rx state       Mux state  Sel state
  ethernet1/1    no   Defaulted      Detached   Unselected(Link down)
  ethernet1/2    no   Port Disabled  Detached   Unselected(Link down)
Status:           Enabled
Mode:             Active
Rate:             Slow
Max-port:         8
Fast-failover:    Disabled
Pre-negotiation:  Disabled
Local:            System Priority: 32768
                  System MAC:      00:56:4c:60:32:45
                  Key:             19
Partner:          System Priority: 0
                  System MAC:      00:00:00:00:00:00
                  Key:             0
Port State
--------------------------------------------------------------------------------
Interface                 Port                                
              Number Priority  Mode    Rate  Key      State
--------------------------------------------------------------------------------
ethernet1/1   74     32768    Active  Slow  19       0x45
Partner        0      0        Passive Slow  0        0x00

ethernet1/2   75     32768    Active  Slow  19       0x45
Partner        0      0        Passive Slow  0        0x00&lt;/PRE&gt;&lt;P&gt;LCAP is configured as Active - Active between PA and Cisco switch.&lt;/P&gt;&lt;P&gt;Is this the normal ehaviour, and a fail over will turn the interface up, or is there a misconfiguration or an issue here.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 22 Mar 2019 14:33:55 GMT</pubDate>
    <dc:creator>AbdulRahman_Safwat</dc:creator>
    <dc:date>2019-03-22T14:33:55Z</dc:date>
    <item>
      <title>LCAP down on Passive Firewal</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/lcap-down-on-passive-firewal/m-p/254678#M72275</link>
      <description>&lt;P&gt;Hello team,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In an HA environment, with pre-negotiation for LCAP disabled , but passive link state set to "Auto" in the HA configuration, if all physical interfaces show as up, is the AE (Aggregated Interface) supposed to be up or down,&amp;nbsp; as the partner (Cisco Switch) is showing suspended on the LCAP interface.&lt;/P&gt;&lt;P&gt;Also from PA the CLi is showing no partner:&lt;/P&gt;&lt;PRE&gt;AE group: ae1
Members:          Bndl Rx state       Mux state  Sel state
  ethernet1/1    no   Defaulted      Detached   Unselected(Link down)
  ethernet1/2    no   Port Disabled  Detached   Unselected(Link down)
Status:           Enabled
Mode:             Active
Rate:             Slow
Max-port:         8
Fast-failover:    Disabled
Pre-negotiation:  Disabled
Local:            System Priority: 32768
                  System MAC:      00:56:4c:60:32:45
                  Key:             19
Partner:          System Priority: 0
                  System MAC:      00:00:00:00:00:00
                  Key:             0
Port State
--------------------------------------------------------------------------------
Interface                 Port                                
              Number Priority  Mode    Rate  Key      State
--------------------------------------------------------------------------------
ethernet1/1   74     32768    Active  Slow  19       0x45
Partner        0      0        Passive Slow  0        0x00

ethernet1/2   75     32768    Active  Slow  19       0x45
Partner        0      0        Passive Slow  0        0x00&lt;/PRE&gt;&lt;P&gt;LCAP is configured as Active - Active between PA and Cisco switch.&lt;/P&gt;&lt;P&gt;Is this the normal ehaviour, and a fail over will turn the interface up, or is there a misconfiguration or an issue here.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 22 Mar 2019 14:33:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/lcap-down-on-passive-firewal/m-p/254678#M72275</guid>
      <dc:creator>AbdulRahman_Safwat</dc:creator>
      <dc:date>2019-03-22T14:33:55Z</dc:date>
    </item>
    <item>
      <title>Re: LCAP down on Passive Firewal</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/lcap-down-on-passive-firewal/m-p/254714#M72284</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I may have missed it but are your PAN's Active/Passive or Active/Active regarding HA?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please advise,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 22 Mar 2019 18:09:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/lcap-down-on-passive-firewal/m-p/254714#M72284</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2019-03-22T18:09:05Z</dc:date>
    </item>
    <item>
      <title>Re: LCAP down on Passive Firewal</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/lcap-down-on-passive-firewal/m-p/254757#M72305</link>
      <description>&lt;P&gt;Seesm it is by design on PAssive LACP is down&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 22 Mar 2019 21:32:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/lcap-down-on-passive-firewal/m-p/254757#M72305</guid>
      <dc:creator>MP18</dc:creator>
      <dc:date>2019-03-22T21:32:30Z</dc:date>
    </item>
    <item>
      <title>Re: LCAP down on Passive Firewal</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/lcap-down-on-passive-firewal/m-p/254766#M72307</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;In an active/passive HA model, the passive interfaces are shutdown.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Sat, 23 Mar 2019 00:47:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/lcap-down-on-passive-firewal/m-p/254766#M72307</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2019-03-23T00:47:42Z</dc:date>
    </item>
    <item>
      <title>Re: LCAP down on Passive Firewal</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/lcap-down-on-passive-firewal/m-p/254813#M72319</link>
      <description>&lt;P&gt;Thank you&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/27580"&gt;@OtakarKlier&lt;/a&gt;&amp;nbsp;and&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/75039"&gt;@MP18&lt;/a&gt;&amp;nbsp;for the replys,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It is Active/Passive on the firewalls but LACP is Active on all components (PA HA and Switches).&lt;/P&gt;&lt;P&gt;Passive link state is auto and the physical interfaces are up on the replica but AE interfaces are down, and on the switch that is communicating with the passive it is suspended.&lt;/P&gt;&lt;P&gt;It seems that this is the normal behaviour, but will pre-negotiate turn it to up, or will it only show the partner's Mac address.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Sun, 24 Mar 2019 11:46:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/lcap-down-on-passive-firewal/m-p/254813#M72319</guid>
      <dc:creator>AbdulRahman_Safwat</dc:creator>
      <dc:date>2019-03-24T11:46:14Z</dc:date>
    </item>
    <item>
      <title>Re: LCAP down on Passive Firewal</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/lcap-down-on-passive-firewal/m-p/254822#M72322</link>
      <description>&lt;P&gt;as per my understanding&amp;nbsp;&lt;SPAN&gt;pre-negotiate turn it to up.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 24 Mar 2019 17:11:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/lcap-down-on-passive-firewal/m-p/254822#M72322</guid>
      <dc:creator>MP18</dc:creator>
      <dc:date>2019-03-24T17:11:42Z</dc:date>
    </item>
    <item>
      <title>Re: LCAP down on Passive Firewal</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/lcap-down-on-passive-firewal/m-p/254831#M72326</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/85175"&gt;@AbdulRahman_Safwat&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Currently as you have it confiugured a failover would cause the switch and the firewall to go through the entire LACP negotiation process; as this process takes a small amount of time, traffic would be disrupted until LACP can actually form and the interfaces start passing traffic.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Pre-Negotiation will turn the interfaces online so that they can start passing traffic just as quickly as a normal interface following a failover.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 24 Mar 2019 20:07:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/lcap-down-on-passive-firewal/m-p/254831#M72326</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2019-03-24T20:07:49Z</dc:date>
    </item>
    <item>
      <title>Re: LCAP down on Passive Firewal</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/lcap-down-on-passive-firewal/m-p/254927#M72353</link>
      <description>&lt;P&gt;Also In our setup we have interface in HA as auto so on passive PA they are green.&lt;/P&gt;&lt;P&gt;For LACP we do no have pre negotiation.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;IF we enable pre negotiation for LACP that will make the interface on the passive PA as green?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please confirm?&lt;/P&gt;</description>
      <pubDate>Mon, 25 Mar 2019 17:18:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/lcap-down-on-passive-firewal/m-p/254927#M72353</guid>
      <dc:creator>MP18</dc:creator>
      <dc:date>2019-03-25T17:18:07Z</dc:date>
    </item>
    <item>
      <title>Re: LCAP down on Passive Firewal</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/lcap-down-on-passive-firewal/m-p/254994#M72369</link>
      <description>&lt;P&gt;Yes.&amp;nbsp; That's exactly what prenegotiation does.&amp;nbsp; It "prenegotiates" the LACP EtherChannel (Ciscoeze language).&amp;nbsp; LACPBDUs are passed but there is no "active firewall" traffic (ie - IPs/etc).&lt;/P&gt;</description>
      <pubDate>Mon, 25 Mar 2019 22:44:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/lcap-down-on-passive-firewal/m-p/254994#M72369</guid>
      <dc:creator>jeremy.larsen</dc:creator>
      <dc:date>2019-03-25T22:44:37Z</dc:date>
    </item>
  </channel>
</rss>

