<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Failover Behaviors in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/failover-behaviors/m-p/302121#M78774</link>
    <description>&lt;P&gt;did the secondary device go to non-functional ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;the primary should not go into a faulty state if the HA2 links go down. the secondary, however, just lost it's capability of taking over seamlessly if the primary were to go down, since it no longer receives session state information.&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;in case both HA1 links go down, the primary peer will remain active as it will assume the secondary peer went down, the secondary peer will assume an active role as it thinks the primary went down, so now both are active and no one is happy&lt;/P&gt;</description>
    <pubDate>Wed, 04 Dec 2019 14:05:05 GMT</pubDate>
    <dc:creator>reaper</dc:creator>
    <dc:date>2019-12-04T14:05:05Z</dc:date>
    <item>
      <title>Failover Behaviors</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/failover-behaviors/m-p/302095#M78766</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Setup: Active-Passive&lt;/P&gt;&lt;P&gt;Path Monitoring: enabled, but not configured(nothing under that Path group)&lt;/P&gt;&lt;P&gt;Version: 7.1.14&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Would an Active firewall change its state to non-functional if both of its HA2/HA-Backup goes down?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Related Logs:&lt;/P&gt;&lt;P&gt;2019/12/04 09:41:04 critical ha ha2-lin 0 All HA2 links down&lt;BR /&gt;2019/12/04 09:41:04 high ha session 0 HA Group 1: Ignoring session synchronization due to HA2-unavailable&lt;BR /&gt;2019/12/04 09:41:04 high ha ha2-lin 0 HA2-Backup link down&lt;BR /&gt;2019/12/04 09:41:04 critical general general 0 Chassis Master Alarm: HA-event&lt;BR /&gt;2019/12/04 09:41:04 critical ha ha2-lin 0 HA2 link down&lt;BR /&gt;2019/12/04 09:41:04 critical ha state-c 0 HA Group 1: Moved from state Active to state Non-Functional&lt;BR /&gt;2019/12/04 09:41:04 critical ha datapla 0 HA Group 1: Dataplane is down: path monitor failure&lt;BR /&gt;2019/12/04 09:41:04 high general general 0 9: path_monitor HB failures seen, triggering HA DP down&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also is there an HA Failover table that I could refer so I can reference what is Palo Altos behavior when lets say HA1 fails or HA2 fails etc..&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;John&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 04 Dec 2019 11:40:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/failover-behaviors/m-p/302095#M78766</guid>
      <dc:creator>Jonathan_Panes</dc:creator>
      <dc:date>2019-12-04T11:40:32Z</dc:date>
    </item>
    <item>
      <title>Re: Failover Behaviors</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/failover-behaviors/m-p/302121#M78774</link>
      <description>&lt;P&gt;did the secondary device go to non-functional ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;the primary should not go into a faulty state if the HA2 links go down. the secondary, however, just lost it's capability of taking over seamlessly if the primary were to go down, since it no longer receives session state information.&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;in case both HA1 links go down, the primary peer will remain active as it will assume the secondary peer went down, the secondary peer will assume an active role as it thinks the primary went down, so now both are active and no one is happy&lt;/P&gt;</description>
      <pubDate>Wed, 04 Dec 2019 14:05:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/failover-behaviors/m-p/302121#M78774</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2019-12-04T14:05:05Z</dc:date>
    </item>
    <item>
      <title>Re: Failover Behaviors</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/failover-behaviors/m-p/302143#M78782</link>
      <description>&lt;P&gt;Very good and useful info.&lt;/P&gt;</description>
      <pubDate>Wed, 04 Dec 2019 15:39:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/failover-behaviors/m-p/302143#M78782</guid>
      <dc:creator>MP18</dc:creator>
      <dc:date>2019-12-04T15:39:50Z</dc:date>
    </item>
    <item>
      <title>Re: Failover Behaviors</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/failover-behaviors/m-p/302221#M78789</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The active firewall went into non-functional state, so the passive firewall took over as active.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;xxxx@xxxxxx-fw(passive)&amp;gt; show high-availability state&lt;/P&gt;&lt;P&gt;Group 1:&lt;BR /&gt;Mode: Active-Passive&lt;BR /&gt;Local Information:&lt;BR /&gt;Version: 1&lt;BR /&gt;Mode: Active-Passive&lt;BR /&gt;State: passive (last 17 hours)&lt;BR /&gt;Last non-functional state reason: Dataplane down: path monitor failure.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Some related logs on the ha_agent.log:&lt;/P&gt;&lt;P&gt;2019-12-04 09:41:04.464 +0000 debug: ha_slot_sysd_dp_down_notify_cb(src/ha_slot.c:641): Got initial dataplane down (slot 1; reason path monitor failure)&lt;BR /&gt;2019-12-04 09:41:04.464 +0000 The dataplane is going down&lt;BR /&gt;2019-12-04 09:41:04.464 +0000 Warning: ha_event_log(src/ha_event.c:47): HA Group 1: Dataplane is down: path monitor failure&lt;BR /&gt;2019-12-04 09:41:04.464 +0000 Going to non-functional for reason Dataplane down: path monitor failure&lt;BR /&gt;2019-12-04 09:41:04.464 +0000 debug: ha_state_transition(src/ha_state.c:1329): Group 1: transition to state Non-Functional&lt;BR /&gt;2019-12-04 09:41:04.464 +0000 debug: ha_state_start_monitor_holdup(src/ha_state.c:2518): Skipping monitor holdup for group 1&lt;BR /&gt;2019-12-04 09:41:04.464 +0000 debug: ha_state_monitor_holdup_callback(src/ha_state.c:2611): Going to Non-Functional state state&lt;BR /&gt;2019-12-04 09:41:04.464 +0000 debug: ha_state_move(src/ha_state.c:1423): Group 1: moving from state Active to Non-Functional&lt;BR /&gt;2019-12-04 09:41:04.464 +0000 Warning: ha_event_log(src/ha_event.c:47): HA Group 1: Moved from state Active to state Non-Functional&lt;BR /&gt;2019-12-04 09:41:04.464 +0000 debug: ha_sysd_dev_state_update(src/ha_sysd.c:1434): Set dev state to Non-Functional&lt;BR /&gt;2019-12-04 09:41:04.464 +0000 debug: ha_sysd_dev_alarm_update(src/ha_sysd.c:1400): Set dev alarm to on&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 05 Dec 2019 03:34:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/failover-behaviors/m-p/302221#M78789</guid>
      <dc:creator>Jonathan_Panes</dc:creator>
      <dc:date>2019-12-05T03:34:39Z</dc:date>
    </item>
    <item>
      <title>Re: Failover Behaviors</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/failover-behaviors/m-p/302491#M78823</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I also did a test&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Active Passive &amp;nbsp;PA&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Only HA1 is connected and no HA1 backup connected.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Heartbeat backup is checked on Both Firewalls.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Disconnected the HA1 and &amp;nbsp;Dashboard shows both HA1 and heartbeat are down.&lt;/P&gt;&lt;P&gt;Both PA became active.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Need to know even though heartbeat backup is checked and management interface on both PA is up why &amp;nbsp;heartbeat backup &amp;nbsp;show down on both firewalls?&lt;/P&gt;&lt;P&gt;Is this expected behaviour?&lt;/P&gt;</description>
      <pubDate>Sat, 07 Dec 2019 17:27:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/failover-behaviors/m-p/302491#M78823</guid>
      <dc:creator>MP18</dc:creator>
      <dc:date>2019-12-07T17:27:56Z</dc:date>
    </item>
    <item>
      <title>Re: Failover Behaviors</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/failover-behaviors/m-p/302526#M78832</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/110025"&gt;@Jonathan_Panes&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Losing HA2 and having a device go into a non-function status is certainty not expected behavior. There are however multiple HA fixes that have been made in 7.1 in later maintenance releases, so you could possibly be running into a bug. While I generally don't like recommending someone upgrade unless I can point towards a specific issue ID, you are running an older maintenance release that has open security advisories present, so I'm going to use those instead and recommend you upgrade to 7.1.25 which will hopefully fix the issue you ran into here as well as patching some security issues.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;PAN-SA-2019-0013&lt;/P&gt;&lt;P&gt;PAN-SA-2019-0019&lt;/P&gt;&lt;P&gt;PAN-SA-2019-0021&lt;/P&gt;&lt;P&gt;PAN-SA-2019-0022&lt;/P&gt;&lt;P&gt;&lt;A href="https://securityadvisories.paloaltonetworks.com/" target="_blank"&gt;https://securityadvisories.paloaltonetworks.com/&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 08 Dec 2019 06:47:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/failover-behaviors/m-p/302526#M78832</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2019-12-08T06:47:07Z</dc:date>
    </item>
    <item>
      <title>Re: Failover Behaviors</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/failover-behaviors/m-p/302527#M78833</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/75039"&gt;@MP18&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;How do you have your MGMT traffic routing. It's possible that due to the split-brain scenario present when HA1 is removed the two devices actually can't send heartbeat traffic to each other due to routing issues present when both firewalls are active. We would need to look at your actual network design to verify to be certain, but that would be my first guess.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 08 Dec 2019 06:50:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/failover-behaviors/m-p/302527#M78833</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2019-12-08T06:50:49Z</dc:date>
    </item>
    <item>
      <title>Re: Failover Behaviors</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/failover-behaviors/m-p/302561#M78836</link>
      <description>&lt;P&gt;Hi BPry,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We are running 8.1.9 on this PA 3020.&lt;/P&gt;&lt;P&gt;These are our LAB firewalls and they do not have any traffic passing via Data plane.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Management Plane routing both firewalls are in same subnet.&lt;/P&gt;&lt;P&gt;All the service Routing is via Management plane only.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Mike&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 08 Dec 2019 15:20:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/failover-behaviors/m-p/302561#M78836</guid>
      <dc:creator>MP18</dc:creator>
      <dc:date>2019-12-08T15:20:03Z</dc:date>
    </item>
    <item>
      <title>Re: Failover Behaviors</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/failover-behaviors/m-p/302568#M78839</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/75039"&gt;@MP18&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Disconnected the HA1 and &amp;nbsp;Dashboard shows both HA1 and heartbeat are down.&lt;/P&gt;
&lt;P&gt;Both PA became active.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;
&lt;P&gt;that's not how it's supposed to work &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 08 Dec 2019 20:42:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/failover-behaviors/m-p/302568#M78839</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2019-12-08T20:42:15Z</dc:date>
    </item>
    <item>
      <title>Re: Failover Behaviors</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/failover-behaviors/m-p/302570#M78841</link>
      <description>&lt;P&gt;I am running 8.1.9 on PA 3020.&lt;/P&gt;&lt;P&gt;Am i hitting the bug?&lt;/P&gt;</description>
      <pubDate>Sun, 08 Dec 2019 21:08:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/failover-behaviors/m-p/302570#M78841</guid>
      <dc:creator>MP18</dc:creator>
      <dc:date>2019-12-08T21:08:23Z</dc:date>
    </item>
    <item>
      <title>Re: Failover Behaviors</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/failover-behaviors/m-p/302571#M78842</link>
      <description>&lt;P&gt;Anything i should check from config wise?&lt;/P&gt;&lt;P&gt;OR i can open the tac case&lt;/P&gt;</description>
      <pubDate>Sun, 08 Dec 2019 21:10:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/failover-behaviors/m-p/302571#M78842</guid>
      <dc:creator>MP18</dc:creator>
      <dc:date>2019-12-08T21:10:27Z</dc:date>
    </item>
    <item>
      <title>Re: Failover Behaviors</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/failover-behaviors/m-p/302590#M78846</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/75039"&gt;@MP18&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;I'd be interested in seeing what your ha_agent.log actually reports when you see this issue pop up to see exactly what the agent is seeing. I haven't seen any keepalive bugs with 8.1.9, and we don't have any addressed issues with 8.1.10 or 8.1.11 that appear to address anything related to this issue.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 09 Dec 2019 03:46:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/failover-behaviors/m-p/302590#M78846</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2019-12-09T03:46:22Z</dc:date>
    </item>
    <item>
      <title>Re: Failover Behaviors</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/failover-behaviors/m-p/303342#M78966</link>
      <description>&lt;P&gt;Hi BPry,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Seems i was testing the HA1 by disabling the encryption on one firewall and leaving enabled on another.&lt;/P&gt;&lt;P&gt;It is not supposed to work like this similar to routing protocols like ospf neighbourship when we enable authentication on one router and&amp;nbsp;&lt;/P&gt;&lt;P&gt;do&amp;nbsp; not enable on another.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Many thanks for pointing me in right direction.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 12 Dec 2019 05:39:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/failover-behaviors/m-p/303342#M78966</guid>
      <dc:creator>MP18</dc:creator>
      <dc:date>2019-12-12T05:39:51Z</dc:date>
    </item>
    <item>
      <title>Re: Failover Behaviors</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/failover-behaviors/m-p/310464#M80391</link>
      <description>&lt;P&gt;Hi All,&lt;BR /&gt;&lt;BR /&gt;There was a 15 min downtime when customer working on replacing the Passive device in a A/P pair with RMA device.&lt;/P&gt;&lt;P&gt;Soon they connected HA1 (Aux1) cable only to New RMA device (no interfaces connected bcz link monitoring was enabled), there was split brain scenario for few mins where peer firewall running active became passive and dropped traffic. Customer suspended the new RMA device and both firewalls recovered from split brain scenario and the traffic was passing through expected firewall (Active Firewall).&lt;BR /&gt;&lt;BR /&gt;My question: With preemption disabled if split brain scenario occurs in A/P pair, after recovery from split brain which firewall owns the active state?? ( my answer is firewall that has lowest priority will have the Active role after recovery even the network interfaces are not connected and link monitoring also enabled on these interfaces ).&lt;BR /&gt;&lt;BR /&gt;Thanks in advance.&lt;BR /&gt;&lt;BR /&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 10 Feb 2020 22:10:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/failover-behaviors/m-p/310464#M80391</guid>
      <dc:creator>snekkanti</dc:creator>
      <dc:date>2020-02-10T22:10:13Z</dc:date>
    </item>
  </channel>
</rss>

