<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Dataplane issue in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/dataplane-issue/m-p/301040#M78618</link>
    <description>&lt;P&gt;HI BPRY&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;tks for your answer&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;i noticed this config is very strange and bad at the same time hehhe we will plan a update of PANOS soon&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;tks&lt;/P&gt;&lt;P&gt;matheus&lt;/P&gt;</description>
    <pubDate>Wed, 27 Nov 2019 14:15:51 GMT</pubDate>
    <dc:creator>Support_IT</dc:creator>
    <dc:date>2019-11-27T14:15:51Z</dc:date>
    <item>
      <title>Dataplane issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dataplane-issue/m-p/299501#M78366</link>
      <description>&lt;P&gt;Hello&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;i have 2 Palo Alto in HA Mode Active/Passive and yesterday the Active when down and i lost all the LACPs ,then i start to troubleshooting to see the cause and i found this&lt;/P&gt;&lt;P&gt;could you tell me if is this bug issue or interface issue please ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;18/11/2019 16:09:23 ha ha2-link-change 0 general critical All HA2 links down&lt;BR /&gt;18/11/2019 16:09:23 ha session-synch 0 general high HA Group 1: Ignoring session synchronization due to HA2-unavailable&lt;BR /&gt;18/11/2019 16:09:23 ha ha2-link-change 0 general high HA2-Backup link down&lt;BR /&gt;18/11/2019 16:09:23 ha ha2-link-change 0 general critical HA2 link down&lt;BR /&gt;18/11/2019 16:09:23 general general 0 general critical Chassis Master Alarm: HA-event&lt;BR /&gt;18/11/2019 16:09:23 ha state-change 0 general critical HA Group 1: Moved from state Active to state Non-Functional&lt;BR /&gt;18/11/2019 16:09:23 ha dataplane-down 0 general critical HA Group 1: Dataplane is down: path monitor failure&lt;BR /&gt;18/11/2019 16:09:23 general general 0 general high 9: dp0-path_monitor HB failures seen, triggering HA DP down&lt;BR /&gt;18/11/2019 16:08:42 general general 0 general critical pktlog_forwarding: Exited 4 times, must be manually recovered.&lt;BR /&gt;18/11/2019 16:06:39 general general 0 general high all_pktproc_4: exiting because missed too many heartbeats&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;also the logs from the firewall&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;019-11-18 16:06:40.883 +0100 Dataplane HA state transition: from 5 to 5&lt;BR /&gt;2019-11-18 16:06:55.079 +0100 sysd notificatioon for object sw.mgmt.runtime.ncommits&lt;BR /&gt;2019-11-18 16:06:55.079 +0100 Peer HA3 MAC is 00:00:00:00:00:00&lt;BR /&gt;2019-11-18 16:06:55.079 +0100 Peer HA2 MAC is 00:00:00:00:00:00&lt;BR /&gt;2019-11-18 16:06:55.079 +0100 Peer HA2 MAC is e8:98:6d:67:ec:4b&lt;BR /&gt;2019-11-18 16:06:55.081 +0100 Dataplane HA state transition: from 5 to 5&lt;BR /&gt;2019-11-18 16:07:17.862 +0100 sending periodic gratuitous arp or nd/mld messages for all interfaces&lt;BR /&gt;2019-11-18 16:07:17.862 +0100 Send gratuitous ARP&lt;BR /&gt;2019-11-18 16:08:17.863 +0100 sending periodic gratuitous arp or nd/mld messages for all interfaces&lt;BR /&gt;2019-11-18 16:08:17.866 +0100 Send gratuitous ARP&lt;BR /&gt;2019-11-18 16:09:17.872 +0100 sending periodic gratuitous arp or nd/mld messages for all interfaces&lt;BR /&gt;2019-11-18 16:09:17.873 +0100 Send gratuitous ARP&lt;BR /&gt;2019-11-18 16:09:23.490 +0100 sysd notificatioon for object ha.app.local.lib-states&lt;BR /&gt;2019-11-18 16:09:23.505 +0100 Peer HA3 MAC is 00:00:00:00:00:00&lt;BR /&gt;2019-11-18 16:09:23.505 +0100 Peer HA2 MAC is 00:00:00:00:00:00&lt;BR /&gt;2019-11-18 16:09:23.505 +0100 Peer HA2 MAC is e8:98:6d:67:ec:4b&lt;BR /&gt;2019-11-18 16:09:23.506 +0100 Dataplane HA state transition: from 5 to 2&lt;BR /&gt;2019-11-18 16:09:23.506 +0100 Set dataplane interface link properties&lt;BR /&gt;2019-11-18 16:09:23.506 +0100 Device in inactive HA state, shut down all ports&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;2019-11-18 16:09:23.489 +0100 debug: ha_slot_sysd_dp_down_notify_cb(src/ha_slot.c:1006): Got initial dataplane down (slot 1; reason path monitor failure)&lt;BR /&gt;2019-11-18 16:09:23.489 +0100 The dataplane is going down&lt;BR /&gt;2019-11-18 16:09:23.489 +0100 debug: ha_rts_dp_ready_update(src/ha_rts.c:1119): RTS slot 1 set to NOT ready&lt;BR /&gt;2019-11-18 16:09:23.489 +0100 debug: ha_rts_dp_ready(src/ha_rts.c:791): Update dp ready bitmask for slots ; changed slots 1 for local device&lt;BR /&gt;2019-11-18 16:09:23.490 +0100 debug: ha_peer_send_hello(src/ha_peer.c:5066): Group 1 (HA1-MAIN): Sending hello message&lt;/P&gt;&lt;P&gt;Hello Msg&lt;BR /&gt;---------&lt;BR /&gt;flags : 0x0 ()&lt;BR /&gt;state : Active (5)&lt;BR /&gt;priority : 100&lt;BR /&gt;cookie : 9557&lt;BR /&gt;num tlvs : 2&lt;BR /&gt;Printing out 2 tlvs&lt;BR /&gt;TLV[1]: type 67 (DP_RTS_READY); len 4; value:&lt;BR /&gt;00000000&lt;BR /&gt;TLV[2]: type 11 (SYSD_PEER_DOWN); len 4; value:&lt;BR /&gt;00000000&lt;/P&gt;&lt;P&gt;2019-11-18 16:09:23.490 +0100 Warning: ha_event_log(src/ha_event.c:47): HA Group 1: Dataplane is down: path monitor failure&lt;BR /&gt;2019-11-18 16:09:23.490 +0100 Going to non-functional for reason Dataplane down: path monitor failure&lt;BR /&gt;2019-11-18 16:09:23.490 +0100 debug: ha_state_transition(src/ha_state.c:1420): Group 1: transition to state Non-Functional&lt;BR /&gt;2019-11-18 16:09:23.490 +0100 debug: ha_state_start_monitor_holdup(src/ha_state.c:2642): Skipping monitor holdup for group 1&lt;BR /&gt;2019-11-18 16:09:23.490 +0100 debug: ha_state_monitor_holdup_callback(src/ha_state.c:2740): Going to Non-Functional state state&lt;BR /&gt;2019-11-18 16:09:23.490 +0100 debug: ha_state_move(src/ha_state.c:1516): Group 1: moving from state Active to Non-Functional&lt;BR /&gt;2019-11-18 16:09:23.490 +0100 debug: sysd_queue_wr_event_add(sysd_queue.c:915): QUEUE: queue write event already added&lt;BR /&gt;2019-11-18 16:09:23.490 +0100 Warning: ha_event_log(src/ha_event.c:47): HA Group 1: Moved from state Active to state Non-Functional&lt;BR /&gt;2019-11-18 16:09:23.490 +0100 debug: ha_sysd_dev_state_update(src/ha_sysd.c:1431): Set dev state to Non-Functional&lt;BR /&gt;2019-11-18 16:09:23.490 +0100 debug: ha_state_move_action(src/ha_state.c:1331): No state transition script available on current platform&lt;BR /&gt;2019-11-18 16:09:23.490 +0100 debug: ha_sysd_dev_alarm_update(src/ha_sysd.c:1397): Set dev alarm to on&lt;BR /&gt;2019-11-18 16:09:23.490 +0100 debug: ha_state_move_degraded(src/ha_state.c:1836): Group 1: Non-functional loop count updated to 1&lt;BR /&gt;2019-11-18 16:09:23.490 +0100 debug: ha_state_check_nonfunc_hold(src/ha_state.c:2767): No non-func hold based on product/mode/dp/sys state&lt;BR /&gt;2019-11-18 16:09:23.490 +0100 debug: ha_peer_send_hello(src/ha_peer.c:5066): Group 1 (HA1-MAIN): Sending hello message&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;would be very helpful to have a good answer from you&lt;/P&gt;&lt;P&gt;thank you&lt;BR /&gt;Matheus&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 19 Nov 2019 17:54:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dataplane-issue/m-p/299501#M78366</guid>
      <dc:creator>Support_IT</dc:creator>
      <dc:date>2019-11-19T17:54:58Z</dc:date>
    </item>
    <item>
      <title>Re: Dataplane issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dataplane-issue/m-p/299527#M78367</link>
      <description>&lt;P&gt;Hello there.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am sure this will be multiple emails, back and forth, but this is what I see (understand from your logs)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;HA2 link down (there is no more connectivity between your HA2 (which is session to session based synch)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;HA Group 1: Dataplane is down: path monitor failure&amp;nbsp; (you have or maybe did not configure the FW's virtual router to do continuous icmp pings to sites upstream to the FW, and those upstream IPs were no longer responsive.&amp;nbsp; Because no longer responsive, then the FW felt/believed that your monitored path was no longer existent, and wanted to fail over to your backup FW.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Group 1: transition to state Non-Functional&amp;nbsp; (this means there is an error in your configuration.... and am guessing it is on the HA configuration side.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;To me, the FW was monitoring its links and saw that both links were no longer available and the path monitoring (network is down), so it went into error (non functional), all of which appears&amp;nbsp; to be completely normal.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The question(s) that we have, are what interfaces are you monitoring?&amp;nbsp; What path(s) are you monitoring?&lt;/P&gt;&lt;P&gt;We would need to see screen capture of your HA configuration (nothing private in the config discloses sensitive/user info,) so please upload screen captures of your HA config and your Link/Path monitoring.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What did you do to resolve your issues as well?&amp;nbsp; This will help us as well.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 19 Nov 2019 18:44:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dataplane-issue/m-p/299527#M78367</guid>
      <dc:creator>S.Cantwell</dc:creator>
      <dc:date>2019-11-19T18:44:35Z</dc:date>
    </item>
    <item>
      <title>Re: Dataplane issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dataplane-issue/m-p/299578#M78374</link>
      <description>&lt;P&gt;Hi Steve&lt;/P&gt;&lt;P&gt;tks for the quickly answer:)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;i m new in palo alto sorry im from cisco world ..also i m not to familiar yet with my setup as i just started not long time ago so still discovering stuff&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;HA Group 1: Dataplane is down: path monitor failure (you have or maybe did not configure the FW's virtual router to do continuous icmp pings to sites upstream to the FW, and those upstream IPs were no longer responsive. Because no longer responsive, then the FW felt/believed that your monitored path was no longer existent, and wanted to fail over to your backup FW.&lt;/P&gt;&lt;P&gt;there is no icmp pings from HA to HA ..&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;To me, the FW was monitoring its links and saw that both links were no longer available and the path monitoring (network is down), so it went into error (non functional), all of which appears to be completely normal.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Monitoring which links ? the LACP that i have to the network Core ?or HA ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thank you very much&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Matheus&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ha1.PNG" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/22461iBA65665C769D6189/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="ha1.PNG" alt="ha1.PNG" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ha2.PNG" style="width: 918px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/22462i741C70ED1C664E6E/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="ha2.PNG" alt="ha2.PNG" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ha3.PNG" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/22464i71AFD537C0264D72/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="ha3.PNG" alt="ha3.PNG" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ha4.PNG" style="width: 638px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/22463i0D81755E61174902/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="ha4.PNG" alt="ha4.PNG" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ha5.PNG" style="width: 622px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/22466iA66D3EAAB161E456/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="ha5.PNG" alt="ha5.PNG" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ha6.PNG" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/22467i104DF6D3F8880F48/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="ha6.PNG" alt="ha6.PNG" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ha7.PNG" style="width: 885px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/22468i9BFAB36F7A8C4458/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="ha7.PNG" alt="ha7.PNG" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ha8.PNG" style="width: 746px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/22465i3990D91808EC64C2/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="ha8.PNG" alt="ha8.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 19 Nov 2019 21:23:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dataplane-issue/m-p/299578#M78374</guid>
      <dc:creator>Support_IT</dc:creator>
      <dc:date>2019-11-19T21:23:26Z</dc:date>
    </item>
    <item>
      <title>Re: Dataplane issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dataplane-issue/m-p/299657#M78389</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/71871"&gt;@Support_IT&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;You need to start planning an upgrade on your system. You are currently running 8.1.4-h2 and it sounds like you could have run into&amp;nbsp;PAN-106914 which was addressed in 8.1.9 on your HA2 interfaces. The path-monitoring failures I would ignore as a side effect of the failover; you don't have path monitoring enabled on either units according to your screenshots and a link monitoring event would report as such.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;One that that immediately seems odd in your configuration is the use of LACP and aggregate links when you are relying on a sole link. It won't cause any issues, but its completely unnecessary from the look of things outside of your ae8 WAN links.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 20 Nov 2019 03:09:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dataplane-issue/m-p/299657#M78389</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2019-11-20T03:09:25Z</dc:date>
    </item>
    <item>
      <title>Re: Dataplane issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dataplane-issue/m-p/301040#M78618</link>
      <description>&lt;P&gt;HI BPRY&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;tks for your answer&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;i noticed this config is very strange and bad at the same time hehhe we will plan a update of PANOS soon&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;tks&lt;/P&gt;&lt;P&gt;matheus&lt;/P&gt;</description>
      <pubDate>Wed, 27 Nov 2019 14:15:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dataplane-issue/m-p/301040#M78618</guid>
      <dc:creator>Support_IT</dc:creator>
      <dc:date>2019-11-27T14:15:51Z</dc:date>
    </item>
    <item>
      <title>Re: Dataplane issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dataplane-issue/m-p/529125#M109236</link>
      <description>&lt;P&gt;Perhaps its problem is bug ,you should update you system.&lt;/P&gt;</description>
      <pubDate>Mon, 30 Jan 2023 08:33:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dataplane-issue/m-p/529125#M109236</guid>
      <dc:creator>BarcodeMaker</dc:creator>
      <dc:date>2023-01-30T08:33:40Z</dc:date>
    </item>
  </channel>
</rss>

