<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Active-Passive Cluster Link &amp;amp; Path Monitoring in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/active-passive-cluster-link-amp-path-monitoring/m-p/352343#M87172</link>
    <description>&lt;P&gt;Hi All,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Referring my prior discussion Subject - "Firmware Updation A-P" , We have below configuration enabled on Link &amp;amp; path monitoring configuration at this moment, have a look on screen shot.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Will this be sufficient to trigger auto failover to Passive , if in case we can disconnect / disabled any of the directly connected interface from Active firewall Unit.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Link and Path Monitoring Screen Shot.jpg" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/27959i926D1CC80C553B03/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Link and Path Monitoring Screen Shot.jpg" alt="Link and Path Monitoring Screen Shot.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Thought to ask here to avoid any understanding gap.&lt;/P&gt;</description>
    <pubDate>Sat, 26 Sep 2020 05:32:58 GMT</pubDate>
    <dc:creator>Jimmy20</dc:creator>
    <dc:date>2020-09-26T05:32:58Z</dc:date>
    <item>
      <title>Active-Passive Cluster Link &amp; Path Monitoring</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/active-passive-cluster-link-amp-path-monitoring/m-p/352343#M87172</link>
      <description>&lt;P&gt;Hi All,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Referring my prior discussion Subject - "Firmware Updation A-P" , We have below configuration enabled on Link &amp;amp; path monitoring configuration at this moment, have a look on screen shot.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Will this be sufficient to trigger auto failover to Passive , if in case we can disconnect / disabled any of the directly connected interface from Active firewall Unit.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Link and Path Monitoring Screen Shot.jpg" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/27959i926D1CC80C553B03/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Link and Path Monitoring Screen Shot.jpg" alt="Link and Path Monitoring Screen Shot.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Thought to ask here to avoid any understanding gap.&lt;/P&gt;</description>
      <pubDate>Sat, 26 Sep 2020 05:32:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/active-passive-cluster-link-amp-path-monitoring/m-p/352343#M87172</guid>
      <dc:creator>Jimmy20</dc:creator>
      <dc:date>2020-09-26T05:32:58Z</dc:date>
    </item>
    <item>
      <title>Re: Active-Passive Cluster Link &amp; Path Monitoring</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/active-passive-cluster-link-amp-path-monitoring/m-p/352390#M87177</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/144686"&gt;@Jimmy20&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You need to add the Ingress and Egress of the PA in the Link group.&lt;/P&gt;
&lt;P&gt;We have single link to ISP and Linkagg to switch with 2 ports.&lt;/P&gt;
&lt;P&gt;So in our case our Link group has 3 Interfaces and if anyone of those fails it will trigger the failover.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;</description>
      <pubDate>Sun, 27 Sep 2020 01:57:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/active-passive-cluster-link-amp-path-monitoring/m-p/352390#M87177</guid>
      <dc:creator>MP18</dc:creator>
      <dc:date>2020-09-27T01:57:03Z</dc:date>
    </item>
    <item>
      <title>Re: Active-Passive Cluster Link &amp; Path Monitoring</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/active-passive-cluster-link-amp-path-monitoring/m-p/352394#M87178</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/144686"&gt;@Jimmy20&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/75039"&gt;@MP18&lt;/a&gt;&amp;nbsp;briefly explained - no, your setup is not sufficient to trigger failover. You have two "components" - to define conditions for the failover and to tell the firewall to use these conditions for failover. From the image you provide you have enabled the link and path monitor, but you have not configured any conditions, no interface to monitor.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It is good to mention the purpose of both link and path monitor. Link monitor will trigger failover if there is an issue with firewall interface, either if you disconnect it or there is no physical signal over the connected cable. Path monitor go beyond just looking at the physical state of your interfaces. With path monitor firewall will try to ping provided IP address trying to confirm that all three layers are up and running (imagine you have virtual fw, its interfaces way never go down, but there is not connectivity with its directly connected router, link monitor will not work here, but rather path monitor).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Link Monitor gives you very granular control over the condition when to trigger failover. If you notice you need to configure "Link group" in which you can group the physical interfaces in your interest. You need to select group failure condition, this means how many of the interfaces in the group needs to be down to consider the whole group as down.&amp;nbsp; You can have multiple groups, so that is why you have "global" failure condition where you need to tell how many of your groups needs to be marked as down to trigger failover. How to group your interfaces and how to select the group and global&amp;nbsp; failure condition depends on your setup.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 27 Sep 2020 07:46:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/active-passive-cluster-link-amp-path-monitoring/m-p/352394#M87178</guid>
      <dc:creator>aleksandar.astardzhiev</dc:creator>
      <dc:date>2020-09-27T07:46:34Z</dc:date>
    </item>
  </channel>
</rss>

