<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Error Message for AE1 Aggregate Group in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/error-message-for-ae1-aggregate-group/m-p/275020#M75218</link>
    <description>&lt;P&gt;Get that stable on the 1st of the HA pair.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Then create the second port group, and associated interfaces for the second firewall.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Rob&lt;/P&gt;</description>
    <pubDate>Fri, 05 Jul 2019 07:25:18 GMT</pubDate>
    <dc:creator>RobinClayton</dc:creator>
    <dc:date>2019-07-05T07:25:18Z</dc:date>
    <item>
      <title>Error Message for AE1 Aggregate Group</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/error-message-for-ae1-aggregate-group/m-p/273712#M75075</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We are getting below messages on and off for our HA pair.&lt;/P&gt;&lt;P&gt;eth 1/5 and 1/6 are part of the ae1 aggregate group&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;nego-fail,ethernet1/6,0,0,general,critical,"LACP interface ethernet1/6 moved out of AE-group ae1. Selection state Selected",450025,0x0,0,0,0,0,,FW-1&lt;BR /&gt;lacp-up,ethernet1/6,0,0,general,critical,"LACP interface ethernet1/6 moved into AE-group ae1.",450026,0x0,0,0,0,0,,FW-1&lt;BR /&gt;nego-fail,ethernet1/5,0,0,general,critical,"LACP interface ethernet1/5 moved out of AE-group ae1. Selection state Selected",161108,0x0,0,0,0,0,,FW-2&lt;BR /&gt;lacp-up,ethernet1/5,0,0,general,critical,"LACP interface ethernet1/5 moved into AE-group ae1.",161109,0x0,0,0,0,0,,FW-2&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What exactly needs to be checked?&lt;/P&gt;</description>
      <pubDate>Fri, 28 Jun 2019 00:57:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/error-message-for-ae1-aggregate-group/m-p/273712#M75075</guid>
      <dc:creator>FarzanaMustafa</dc:creator>
      <dc:date>2019-06-28T00:57:14Z</dc:date>
    </item>
    <item>
      <title>Re: Error Message for AE1 Aggregate Group</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/error-message-for-ae1-aggregate-group/m-p/273726#M75077</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/98673"&gt;@FarzanaMustafa&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;You need to look at the switch configuration and determine why LACP is failing to negotiate correctly. As it appears you are getting errors across both links the switch LACP configuration is likely either severly wrong or the uplinks were never actually configured to utilize LACP on the switch side of things.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 28 Jun 2019 03:18:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/error-message-for-ae1-aggregate-group/m-p/273726#M75077</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2019-06-28T03:18:25Z</dc:date>
    </item>
    <item>
      <title>Re: Error Message for AE1 Aggregate Group</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/error-message-for-ae1-aggregate-group/m-p/273883#M75087</link>
      <description>&lt;P&gt;Was it working?&lt;/P&gt;&lt;P&gt;Has somone changed something?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Rob&lt;/P&gt;</description>
      <pubDate>Fri, 28 Jun 2019 15:54:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/error-message-for-ae1-aggregate-group/m-p/273883#M75087</guid>
      <dc:creator>RobinClayton</dc:creator>
      <dc:date>2019-06-28T15:54:44Z</dc:date>
    </item>
    <item>
      <title>Re: Error Message for AE1 Aggregate Group</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/error-message-for-ae1-aggregate-group/m-p/274047#M75105</link>
      <description>I think the switch is missing LACP mode</description>
      <pubDate>Sun, 30 Jun 2019 13:52:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/error-message-for-ae1-aggregate-group/m-p/274047#M75105</guid>
      <dc:creator>Yevgeni</dc:creator>
      <dc:date>2019-06-30T13:52:36Z</dc:date>
    </item>
    <item>
      <title>Re: Error Message for AE1 Aggregate Group</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/error-message-for-ae1-aggregate-group/m-p/274990#M75208</link>
      <description>&lt;DIV&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&amp;nbsp;&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/116357"&gt;@Yevgeni&lt;/a&gt;&amp;nbsp;&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/71756"&gt;@RobinClayton&lt;/a&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;The Dell switch ports are configured as below&lt;/DIV&gt;&lt;DIV&gt;Are they not configured correctly?&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;interface GigabitEthernet 1/21&lt;BR /&gt;&amp;nbsp;description member port-channel 21&lt;BR /&gt;&amp;nbsp;no ip address&lt;BR /&gt;!&lt;BR /&gt;&amp;nbsp;port-channel-protocol LACP&lt;BR /&gt;&amp;nbsp; port-channel 21 mode active&lt;BR /&gt;&amp;nbsp;no shutdown&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet 1/22&lt;BR /&gt;&amp;nbsp;description member port-channel 22&lt;BR /&gt;&amp;nbsp;no ip address&lt;BR /&gt;!&lt;BR /&gt;&amp;nbsp;port-channel-protocol LACP&lt;BR /&gt;&amp;nbsp; port-channel 22 mode active&lt;BR /&gt;&amp;nbsp;no shutdown&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;interface Port-channel 21&lt;BR /&gt;&amp;nbsp;description Port-Channel to fw-1 lan ae2&lt;BR /&gt;&amp;nbsp;no ip address&lt;BR /&gt;&amp;nbsp;switchport&lt;BR /&gt;&amp;nbsp;vlt-peer-lag port-channel 21&lt;BR /&gt;&amp;nbsp;no shutdown&lt;BR /&gt;!&lt;BR /&gt;interface Port-channel 22&lt;BR /&gt;&amp;nbsp;description Port-Channel to fw-2 lan ae2&lt;BR /&gt;&amp;nbsp;no ip address&lt;BR /&gt;&amp;nbsp;switchport&lt;BR /&gt;&amp;nbsp;vlt-peer-lag port-channel 22&lt;BR /&gt;&amp;nbsp;no shutdown&lt;/DIV&gt;</description>
      <pubDate>Fri, 05 Jul 2019 00:29:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/error-message-for-ae1-aggregate-group/m-p/274990#M75208</guid>
      <dc:creator>FarzanaMustafa</dc:creator>
      <dc:date>2019-07-05T00:29:14Z</dc:date>
    </item>
    <item>
      <title>Re: Error Message for AE1 Aggregate Group</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/error-message-for-ae1-aggregate-group/m-p/275004#M75209</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/98673"&gt;@FarzanaMustafa&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Are you running both of these interfaces into the same AE group on the firewall, or is fw-1 and fw-2 utilizing port-channel 21 and port-channel 22 respectivly? From the configuration that you've shared it looks like you are only utilizing a sole interface to each firewall, at that point why are you using an AE at all? The configuration for the port-channel looks perfectly fine from the switch perspective, you could verify the LACP status by doing 'show lacp 21' and 'show lacp 22' to see why your members are dropping out, it should also be showing something within logging.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 05 Jul 2019 02:10:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/error-message-for-ae1-aggregate-group/m-p/275004#M75209</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2019-07-05T02:10:48Z</dc:date>
    </item>
    <item>
      <title>Re: Error Message for AE1 Aggregate Group</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/error-message-for-ae1-aggregate-group/m-p/275019#M75217</link>
      <description>&lt;P&gt;Yeah, are both ports on the switch connected to the AE1 on the firewall.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If so port Group 22 should not be used, both swithc ports in same group.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;interface GigabitEthernet 1/21&lt;BR /&gt;&amp;nbsp;description member port-channel 21&lt;BR /&gt;&amp;nbsp;no ip address&lt;BR /&gt;!&lt;BR /&gt;&amp;nbsp;port-channel-protocol LACP&lt;BR /&gt;&amp;nbsp; port-channel 21 mode active&lt;BR /&gt;&amp;nbsp;no shutdown&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet 1/22&lt;BR /&gt;&amp;nbsp;description member port-channel 21&lt;BR /&gt;&amp;nbsp;no ip address&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;interface Port-channel 21&lt;BR /&gt;&amp;nbsp;description Port-Channel to fw-1 lan ae2&lt;BR /&gt;&amp;nbsp;no ip address&lt;BR /&gt;&amp;nbsp;switchport&lt;BR /&gt;&amp;nbsp;vlt-peer-lag port-channel 21&lt;BR /&gt;&amp;nbsp;no shutdown&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 05 Jul 2019 07:22:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/error-message-for-ae1-aggregate-group/m-p/275019#M75217</guid>
      <dc:creator>RobinClayton</dc:creator>
      <dc:date>2019-07-05T07:22:56Z</dc:date>
    </item>
    <item>
      <title>Re: Error Message for AE1 Aggregate Group</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/error-message-for-ae1-aggregate-group/m-p/275020#M75218</link>
      <description>&lt;P&gt;Get that stable on the 1st of the HA pair.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Then create the second port group, and associated interfaces for the second firewall.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Rob&lt;/P&gt;</description>
      <pubDate>Fri, 05 Jul 2019 07:25:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/error-message-for-ae1-aggregate-group/m-p/275020#M75218</guid>
      <dc:creator>RobinClayton</dc:creator>
      <dc:date>2019-07-05T07:25:18Z</dc:date>
    </item>
    <item>
      <title>Re: Error Message for AE1 Aggregate Group</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/error-message-for-ae1-aggregate-group/m-p/275021#M75219</link>
      <description>&lt;P&gt;Also, from the logs..&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Are you running ACTIVE-ACTIVE? It's not the "recomended" configuration.&lt;/P&gt;</description>
      <pubDate>Fri, 05 Jul 2019 07:27:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/error-message-for-ae1-aggregate-group/m-p/275021#M75219</guid>
      <dc:creator>RobinClayton</dc:creator>
      <dc:date>2019-07-05T07:27:43Z</dc:date>
    </item>
  </channel>
</rss>

