<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic session disconnect during A-P failover in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/session-disconnect-during-a-p-failover/m-p/352987#M87264</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can anyone suggest, if we failover from Active to Passive unit on PA firewall. will this maintains the established sessions by default.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Or we have to additionally enable some other setting to make this enable (should maintain session during cluster failover).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Additionally, one more observation while we did recent failover....We have 09 IPSec tunnels created on PA (phase-1 and phase-2 both active) .&lt;/P&gt;&lt;P&gt;- When we did failover from active to passive (and passive unit became the new active).&lt;/P&gt;&lt;P&gt;- We observed that approx 5-6 IPSec tunnels (phase-1 and phase-2 both) were active on new active unit.&lt;/P&gt;&lt;P&gt;- However rest 3-4 IPSec tunnels are showing Phase-2 down (but phase-1 active) on new Active but showing active (both phase-1 and phase-2) on new passive units.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Rgds&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 30 Sep 2020 14:34:29 GMT</pubDate>
    <dc:creator>Jimmy20</dc:creator>
    <dc:date>2020-09-30T14:34:29Z</dc:date>
    <item>
      <title>session disconnect during A-P failover</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/session-disconnect-during-a-p-failover/m-p/352987#M87264</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can anyone suggest, if we failover from Active to Passive unit on PA firewall. will this maintains the established sessions by default.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Or we have to additionally enable some other setting to make this enable (should maintain session during cluster failover).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Additionally, one more observation while we did recent failover....We have 09 IPSec tunnels created on PA (phase-1 and phase-2 both active) .&lt;/P&gt;&lt;P&gt;- When we did failover from active to passive (and passive unit became the new active).&lt;/P&gt;&lt;P&gt;- We observed that approx 5-6 IPSec tunnels (phase-1 and phase-2 both) were active on new active unit.&lt;/P&gt;&lt;P&gt;- However rest 3-4 IPSec tunnels are showing Phase-2 down (but phase-1 active) on new Active but showing active (both phase-1 and phase-2) on new passive units.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Rgds&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 14:34:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/session-disconnect-during-a-p-failover/m-p/352987#M87264</guid>
      <dc:creator>Jimmy20</dc:creator>
      <dc:date>2020-09-30T14:34:29Z</dc:date>
    </item>
    <item>
      <title>Re: session disconnect during A-P failover</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/session-disconnect-during-a-p-failover/m-p/353150#M87286</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;Check out these resources on HA.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClIbCAK" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClIbCAK&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;However the sessions should go over to the new Active unit. I have seen in the past where the VPN tunnels didnt like the failover, these were mostly to other products other than PAN. However PAN to PAN, they seem to be OK. See if passing traffic over the tunnels helps them establish, say a continuous ping.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;But check the logs to see why the tunnels are not coming up from the far side, i.e. the firewall receiving the tunnel connection.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 21:48:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/session-disconnect-during-a-p-failover/m-p/353150#M87286</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2020-09-30T21:48:37Z</dc:date>
    </item>
    <item>
      <title>Re: session disconnect during A-P failover</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/session-disconnect-during-a-p-failover/m-p/353154#M87290</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/144686"&gt;@Jimmy20&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In my experience&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/27580"&gt;@OtakarKlier&lt;/a&gt;&amp;nbsp;is absolutely correct. I would normally expect a PAN to PAN tunnel to stay online during a failover, but once you start crossing vendors things can be a bit hit or miss. A lot of this has to do with DPD and other similar settings not playing correctly if they are setup on one side or another.&lt;/P&gt;
&lt;P&gt;I'll still occasionally have issues with PAN to PAN tunnels, but DPD and tunnel monitoring will easily correct any issues that would be caused by this and bring the tunnels back online.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 22:12:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/session-disconnect-during-a-p-failover/m-p/353154#M87290</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2020-09-30T22:12:31Z</dc:date>
    </item>
  </channel>
</rss>

