<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Query on Path monitoring in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/query-on-path-monitoring/m-p/353564#M87332</link>
    <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/98673"&gt;@FarzanaMustafa&lt;/a&gt; ,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I believe you are confusing HA path monitor with static route path monitor.&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/8-1/pan-os-admin/networking/static-routes/static-route-removal-based-on-path-monitoring.html" target="_blank"&gt;https://docs.paloaltonetworks.com/pan-os/8-1/pan-os-admin/networking/static-routes/static-route-removal-based-on-path-monitoring.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The purpose of HA path monitor is to trigger failover, to the other member in the cluster, in case that FW detect issues in the path from the active member. As you can imagine, if you don't have HA enabled...there is no failover, so what would be the purpose to monitor the path at all.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Static route path monitor can be configured for each static route. Its purpose is to de-activate the static route in case of issues with that path. This has nothing to do with HA, so if the path is down FW will simply deactivate that static route so the traffic can take next best match in the routing table.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;P.S now that I re-read your question - I was thinking that you may refer to the failover loop. So what is happening is when you configure HA and enable path monitor the active FW will ping select address in order to detect issues in the path. If the ping is down the FW will think that there is some issues with the path and will failover to the secondary member. As you may know the passive FW in PAN cluster will keep its routing engine "disabled". This means that passive FW is not capable of sending or receiving any traffic over it dataplane interfaces. Which means when FW is in passive state it cannot send ping to test the path. So when secondary member become active only then it start sending ping to test the path.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;And here comes your failover loop - if the problem is not in the FW connection, but somewhere down the path, both members in the cluster will not be able to ping the provided ip. Unfortunately each member will discover this only when become active. So you will have&lt;BR /&gt;1. Path monitor on primary goes down.&lt;/P&gt;&lt;P&gt;2. Primary failover to secondary&lt;/P&gt;&lt;P&gt;3. Secondary start sending ping for path monitor&lt;/P&gt;&lt;P&gt;4. Path monitor on secondary member goes down (since the problem is at the next hop)&lt;/P&gt;&lt;P&gt;5. Secondary failover back to primary&lt;/P&gt;&lt;P&gt;6. Primary start sending pings for path monitor&lt;/P&gt;&lt;P&gt;7. There is still issues with next hop so path monitor from primary goes down&lt;/P&gt;&lt;P&gt;8. Primary failover to secondary&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This can keep going on and on. That is why PAN FW has failover loop prevention, which is basically a counter that is counting how many times there was failover for given period of time. When the count reach the configured limit one of the member move to suspended state, that way the currently active member will remain active even if the path monitor is still down.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;And that is how HA path monitor can cause "loop condition" aka failover loop. However still you need to have HA enable to have failover loop.&lt;/P&gt;</description>
    <pubDate>Fri, 02 Oct 2020 07:59:53 GMT</pubDate>
    <dc:creator>aleksandar.astardzhiev</dc:creator>
    <dc:date>2020-10-02T07:59:53Z</dc:date>
    <item>
      <title>Query on Path monitoring</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/query-on-path-monitoring/m-p/353538#M87330</link>
      <description>&lt;P&gt;Will Path monitoring kick in if Enable HA is not selected?&lt;/P&gt;&lt;P&gt;One of the KBs mentioned&amp;nbsp;path monitoring failure which cause the loop condition.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="HA.png" style="width: 803px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/28057i572595FE23766B25/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="HA.png" alt="HA.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Link and Path Monitoring.png" style="width: 850px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/28058iF60956A7AC672B31/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Link and Path Monitoring.png" alt="Link and Path Monitoring.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 02 Oct 2020 06:48:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/query-on-path-monitoring/m-p/353538#M87330</guid>
      <dc:creator>FarzanaMustafa</dc:creator>
      <dc:date>2020-10-02T06:48:06Z</dc:date>
    </item>
    <item>
      <title>Re: Query on Path monitoring</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/query-on-path-monitoring/m-p/353564#M87332</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/98673"&gt;@FarzanaMustafa&lt;/a&gt; ,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I believe you are confusing HA path monitor with static route path monitor.&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/8-1/pan-os-admin/networking/static-routes/static-route-removal-based-on-path-monitoring.html" target="_blank"&gt;https://docs.paloaltonetworks.com/pan-os/8-1/pan-os-admin/networking/static-routes/static-route-removal-based-on-path-monitoring.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The purpose of HA path monitor is to trigger failover, to the other member in the cluster, in case that FW detect issues in the path from the active member. As you can imagine, if you don't have HA enabled...there is no failover, so what would be the purpose to monitor the path at all.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Static route path monitor can be configured for each static route. Its purpose is to de-activate the static route in case of issues with that path. This has nothing to do with HA, so if the path is down FW will simply deactivate that static route so the traffic can take next best match in the routing table.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;P.S now that I re-read your question - I was thinking that you may refer to the failover loop. So what is happening is when you configure HA and enable path monitor the active FW will ping select address in order to detect issues in the path. If the ping is down the FW will think that there is some issues with the path and will failover to the secondary member. As you may know the passive FW in PAN cluster will keep its routing engine "disabled". This means that passive FW is not capable of sending or receiving any traffic over it dataplane interfaces. Which means when FW is in passive state it cannot send ping to test the path. So when secondary member become active only then it start sending ping to test the path.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;And here comes your failover loop - if the problem is not in the FW connection, but somewhere down the path, both members in the cluster will not be able to ping the provided ip. Unfortunately each member will discover this only when become active. So you will have&lt;BR /&gt;1. Path monitor on primary goes down.&lt;/P&gt;&lt;P&gt;2. Primary failover to secondary&lt;/P&gt;&lt;P&gt;3. Secondary start sending ping for path monitor&lt;/P&gt;&lt;P&gt;4. Path monitor on secondary member goes down (since the problem is at the next hop)&lt;/P&gt;&lt;P&gt;5. Secondary failover back to primary&lt;/P&gt;&lt;P&gt;6. Primary start sending pings for path monitor&lt;/P&gt;&lt;P&gt;7. There is still issues with next hop so path monitor from primary goes down&lt;/P&gt;&lt;P&gt;8. Primary failover to secondary&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This can keep going on and on. That is why PAN FW has failover loop prevention, which is basically a counter that is counting how many times there was failover for given period of time. When the count reach the configured limit one of the member move to suspended state, that way the currently active member will remain active even if the path monitor is still down.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;And that is how HA path monitor can cause "loop condition" aka failover loop. However still you need to have HA enable to have failover loop.&lt;/P&gt;</description>
      <pubDate>Fri, 02 Oct 2020 07:59:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/query-on-path-monitoring/m-p/353564#M87332</guid>
      <dc:creator>aleksandar.astardzhiev</dc:creator>
      <dc:date>2020-10-02T07:59:53Z</dc:date>
    </item>
    <item>
      <title>Re: Query on Path monitoring</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/query-on-path-monitoring/m-p/353619#M87342</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/98673"&gt;@FarzanaMustafa&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/70130"&gt;@aleksandar.astardzhiev&lt;/a&gt;&amp;nbsp;did a great job describing how this actually works, and how PAN prevents failover loops from happening with path monitoring and HA suspension. I just wanted to add that you actually&amp;nbsp;&lt;EM&gt;can&amp;nbsp;&lt;/EM&gt;enable Path-Monitoring or Link-Monitoring on a device which is not HA enabled. What happens in that situation is that a link-monitoring or path-monitoring failure would be logged under your system logs that you could use to potentially notify yourself of the issue. Since you don't have HA, nothing else happens at that point. The device simply generates system logs notifying you of the issue.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 02 Oct 2020 15:48:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/query-on-path-monitoring/m-p/353619#M87342</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2020-10-02T15:48:43Z</dc:date>
    </item>
  </channel>
</rss>

