<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Palo Alto 7000 heartbeat backup icmp fail in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-7000-heartbeat-backup-icmp-fail/m-p/386808#M90301</link>
    <description>&lt;P&gt;Thanks for confirming this as I suspected this is the case and I tried to explain this to the TAC engineer and asked him to confirm this but for 1 week we have no reply to this question as the case priority is HIGH and still (not happy with the TAC support). About the issue we are partners and we have access to Auto Assistant which detected internal packet failure on one of the firewalls, which suggests a hardware issue. I also found bug &lt;SPAN&gt;&lt;STRONG&gt;PAN-114648&lt;/STRONG&gt;&lt;FONT face="&amp;quot;Lato&amp;quot;,&amp;quot;Helvetica Neue&amp;quot;,Helvetica,Arial,sans-serif" size="3" color="#002000"&gt;, that is resolved for 3200 devices but I don't know if it affects 7000 devices:&lt;/FONT&gt;&lt;/SPAN&gt; &lt;FONT&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/8-1/pan-os-release-notes/pan-os-8-1-addressed-issues/pan-os-8-1-13-addressed-issues.html" target="_blank" rel="noopener"&gt;https://docs.paloaltonetworks.com/pan-os/8-1/pan-os-release-notes/pan-os-8-1-addressed-issues/pan-os-8-1-13-addressed-issues.html&lt;/A&gt;. I also asked the TAC for their opinion for the Internal Packet failure on one of the firewalls and this bug but I am still waiting. Still thanks for confirming what I suspected and replying much faster than the TAC &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/FONT&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 19 Feb 2021 10:39:56 GMT</pubDate>
    <dc:creator>nikoolayy1</dc:creator>
    <dc:date>2021-02-19T10:39:56Z</dc:date>
    <item>
      <title>Palo Alto 7000 heartbeat backup icmp fail</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-7000-heartbeat-backup-icmp-fail/m-p/386566#M90275</link>
      <description>&lt;P&gt;Hello to All,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;From time to time the ICMP fails for the management connection between two firewalls model 7000 with 8.1.x version. The issue causes a failover but the 7000 firewalls have dedicated interfaces for HA and the management should be used only for&amp;nbsp;&lt;SPAN&gt;Heartbeat Backup as described&amp;nbsp;in&amp;nbsp;&lt;/SPAN&gt;&amp;nbsp; &lt;A href="https://docs.paloaltonetworks.com/pan-os/8-1/pan-os-admin/high-availability/ha-concepts/ha-links-and-backup-links/ha-ports-on-the-pa-7000-series-firewall.html" target="_blank" rel="noopener"&gt;https://docs.paloaltonetworks.com/pan-os/8-1/pan-os-admin/high-availability/ha-concepts/ha-links-and-backup-links/ha-ports-on-the-pa-7000-series-firewall.html&lt;/A&gt; . Shouldn't HA1 and the management connections fail at the same time for a failover? We opened Palo Alto case but they don't answer this question that I asked them (I am waiting for 1 week), they just say change the cable on the management interfaces and customer did that and the issue is still there.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;ha_agent log:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;xxx ha 2/17/2021 11:46 critical HA Group 1: HA heartbeat backup connection down xxx&lt;BR /&gt;xxx ha 2/17/2021 7:43 critical HA Group 1: HA heartbeat backup connection down xxx&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 18 Feb 2021 11:56:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-7000-heartbeat-backup-icmp-fail/m-p/386566#M90275</guid>
      <dc:creator>nikoolayy1</dc:creator>
      <dc:date>2021-02-18T11:56:47Z</dc:date>
    </item>
    <item>
      <title>Re: Palo Alto 7000 heartbeat backup icmp fail</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-7000-heartbeat-backup-icmp-fail/m-p/386667#M90287</link>
      <description>&lt;P&gt;Howdy there.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;So lets talk about HA1 vs Mgmt, and what they are used for.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;HA1 supports 3 things (link failure notification... HEARTBEAT (icmp) and HELLOs (status checks)&lt;/P&gt;
&lt;P&gt;When you enable Mgmt as the HeartBeat Backup, both the HA1 AND the Mgmt IPs are pinged to confirm connectivity.&lt;/P&gt;
&lt;P&gt;Is it possible for a ping between HA1 and HA1 is good, but that between Mgmt to Mmgt is is not good? YES.&lt;/P&gt;
&lt;P&gt;Would the firewall failover if you unplugged the mgmt interfaces on both FWs?&amp;nbsp; NO!!&amp;nbsp; Why.. it is merely a heartbeat backup, and the primary role of determine failure is the HA1 communication.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;So if HA1 to HA1 failed.. would the FW failover over NO!&amp;nbsp; Because pings from the mgmt to mgmt&amp;nbsp; IPs were still up. The reason for programming Mgmt IP as HeartBeat back up is to prevent Split Brain.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In your environment, maybe it is better to use HA1-A and HA1-B (for backup) and not use mgmt IP for backup.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;let us know if there are questions we can assist more with.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 18 Feb 2021 19:04:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-7000-heartbeat-backup-icmp-fail/m-p/386667#M90287</guid>
      <dc:creator>S.Cantwell</dc:creator>
      <dc:date>2021-02-18T19:04:20Z</dc:date>
    </item>
    <item>
      <title>Re: Palo Alto 7000 heartbeat backup icmp fail</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-7000-heartbeat-backup-icmp-fail/m-p/386808#M90301</link>
      <description>&lt;P&gt;Thanks for confirming this as I suspected this is the case and I tried to explain this to the TAC engineer and asked him to confirm this but for 1 week we have no reply to this question as the case priority is HIGH and still (not happy with the TAC support). About the issue we are partners and we have access to Auto Assistant which detected internal packet failure on one of the firewalls, which suggests a hardware issue. I also found bug &lt;SPAN&gt;&lt;STRONG&gt;PAN-114648&lt;/STRONG&gt;&lt;FONT face="&amp;quot;Lato&amp;quot;,&amp;quot;Helvetica Neue&amp;quot;,Helvetica,Arial,sans-serif" size="3" color="#002000"&gt;, that is resolved for 3200 devices but I don't know if it affects 7000 devices:&lt;/FONT&gt;&lt;/SPAN&gt; &lt;FONT&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/8-1/pan-os-release-notes/pan-os-8-1-addressed-issues/pan-os-8-1-13-addressed-issues.html" target="_blank" rel="noopener"&gt;https://docs.paloaltonetworks.com/pan-os/8-1/pan-os-release-notes/pan-os-8-1-addressed-issues/pan-os-8-1-13-addressed-issues.html&lt;/A&gt;. I also asked the TAC for their opinion for the Internal Packet failure on one of the firewalls and this bug but I am still waiting. Still thanks for confirming what I suspected and replying much faster than the TAC &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/FONT&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 19 Feb 2021 10:39:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-7000-heartbeat-backup-icmp-fail/m-p/386808#M90301</guid>
      <dc:creator>nikoolayy1</dc:creator>
      <dc:date>2021-02-19T10:39:56Z</dc:date>
    </item>
    <item>
      <title>Re: Palo Alto 7000 heartbeat backup icmp fail</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-7000-heartbeat-backup-icmp-fail/m-p/386811#M90302</link>
      <description>&lt;P&gt;I meant internal path failure. Sorry.&lt;/P&gt;</description>
      <pubDate>Fri, 19 Feb 2021 11:08:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-7000-heartbeat-backup-icmp-fail/m-p/386811#M90302</guid>
      <dc:creator>nikoolayy1</dc:creator>
      <dc:date>2021-02-19T11:08:00Z</dc:date>
    </item>
  </channel>
</rss>

