<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: HA link port failures and failover in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/ha-link-port-failures-and-failover/m-p/254688#M72277</link>
    <description>&lt;P&gt;This is why you should build disparate redundancy between your firewalls if they are not directly connected.&lt;/P&gt;</description>
    <pubDate>Fri, 22 Mar 2019 15:06:48 GMT</pubDate>
    <dc:creator>jeremy.larsen</dc:creator>
    <dc:date>2019-03-22T15:06:48Z</dc:date>
    <item>
      <title>HA link port failures and failover</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ha-link-port-failures-and-failover/m-p/254592#M72253</link>
      <description>&lt;P&gt;I have a pair of 5220s configured with HA1, HA1 Backup, HA2, &amp;nbsp;and HA2 Backup links in use. &amp;nbsp;All HA links show to be up and running. I have left all of the other knobs for tuning link and path monitoring off, taking all of the defaults. No preemption, etc. I am running in an Active/Passive configuration.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When I disconnect HA1 and HA1 Backup, at nearly the same time, the Passive unit becomes Active, but the Active unit remains Active. &amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Then when I went further to disconnect HA2 and HA2 Backup, at nearly the same time, and still, the old Active unit remains Active.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is this expected behavior?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is there any way to monitor the links on the HA ports themselves? &amp;nbsp;I do not see that as an option in the GUI.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Clarke&lt;/P&gt;</description>
      <pubDate>Thu, 21 Mar 2019 22:56:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ha-link-port-failures-and-failover/m-p/254592#M72253</guid>
      <dc:creator>ClarkeMorledge</dc:creator>
      <dc:date>2019-03-21T22:56:50Z</dc:date>
    </item>
    <item>
      <title>Re: HA link port failures and failover</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ha-link-port-failures-and-failover/m-p/254641#M72266</link>
      <description>&lt;P&gt;yes this is expected&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;HA1 is the brain of the operation, HA2 the brawn&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Disconnecting both HA1 + HA1-b at the same time basically creates 2 separate brains: each peer has lost its link to the other, so primary thinks secondary is down, secondary thinks primary is down and becomes active&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This scenario is therefore called 'split-brain'&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Further disconnecting HA2 only severs the syncing of sessions, which will have seized already when both HA1 were disconnected&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Whenever a HA link goes down, a critical event is created in the system log&lt;/P&gt;
&lt;P&gt;It's highly recommended to set up log forwarding for critical events so you are notified immediately&lt;/P&gt;</description>
      <pubDate>Fri, 22 Mar 2019 10:14:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ha-link-port-failures-and-failover/m-p/254641#M72266</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2019-03-22T10:14:19Z</dc:date>
    </item>
    <item>
      <title>Re: HA link port failures and failover</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ha-link-port-failures-and-failover/m-p/254688#M72277</link>
      <description>&lt;P&gt;This is why you should build disparate redundancy between your firewalls if they are not directly connected.&lt;/P&gt;</description>
      <pubDate>Fri, 22 Mar 2019 15:06:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ha-link-port-failures-and-failover/m-p/254688#M72277</guid>
      <dc:creator>jeremy.larsen</dc:creator>
      <dc:date>2019-03-22T15:06:48Z</dc:date>
    </item>
  </channel>
</rss>

