<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: HA down PA-220 in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/ha-down-pa-220/m-p/412796#M92878</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/176411"&gt;@ChrisCon&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Check System logs in GUI and from CLI&lt;/P&gt;
&lt;P&gt;Check below logs&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;less mp-log ha_agent.log&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Also troubleshoot why HA ports are down?&lt;/P&gt;
&lt;P&gt;Check Physical connections.&lt;/P&gt;
&lt;P&gt;IF HA is enabled on both firewalls then if physical interfaces are up again then your issue should be fixed.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;
&lt;P&gt;Mahesh&lt;/P&gt;</description>
    <pubDate>Sat, 12 Jun 2021 22:38:17 GMT</pubDate>
    <dc:creator>MP18</dc:creator>
    <dc:date>2021-06-12T22:38:17Z</dc:date>
    <item>
      <title>HA down PA-220</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ha-down-pa-220/m-p/412701#M92865</link>
      <description>&lt;P&gt;I've a pair of PA-220 configured as cluster. After power off - on HA is down. But I can connect to both firewalls via https &amp;amp; ssh.&lt;BR /&gt;Active fw1 shows that HA ports 7 &amp;amp; 8 are down (red in GUI). On passive firewall fw2 all ports are grey.&lt;BR /&gt;But the real strange thing is, when looking into running-config (CLI), on active fw1 all the HA config is missing.&lt;BR /&gt;On passive (ok, not really passive, because HA is down) fw2 all the HA config in running-config is shown (CLI).&lt;BR /&gt;But when I enter the command "show high-availability state" fw2 shows "HA not enabled".&lt;BR /&gt;And "show interface all" gives me an error.&lt;BR /&gt;For me it would make sense, if fw1 would show this error, because of missing part in running-config.&lt;BR /&gt;Connections are working, I can reach all the stuff behind the firewall.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;user@fw2&amp;gt; show high-availability state&lt;BR /&gt;HA not enabled&lt;/P&gt;&lt;P&gt;user@fw2&amp;gt; show interface all&lt;BR /&gt;Server error : An error occured. See dagger.log for information.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;user@fw1(active)&amp;gt; show high-availability state&lt;BR /&gt;Group 1:&lt;BR /&gt;Mode: Active-Passive&lt;BR /&gt;Local Information:&lt;BR /&gt;Version: 1&lt;BR /&gt;Mode: Active-Passive&lt;BR /&gt;State: active (last 4 days)&lt;/P&gt;&lt;P&gt;user@fw1(active)&amp;gt; show interface all&lt;/P&gt;&lt;P&gt;total configured hardware interfaces: 9&lt;BR /&gt;name id speed/duplex/state mac address&lt;BR /&gt;--------------------------------------------------------------------------------&lt;BR /&gt;ethernet1/2 17 1000/full/up 00:1b:17:&lt;BR /&gt;ethernet1/3 18 1000/full/up 00:1b:17:&lt;BR /&gt;ethernet1/5 20 1000/full/up 00:1b:17:&lt;BR /&gt;ethernet1/7 22 ukn/ukn/down(autoneg) 34:e5:ec:&lt;BR /&gt;ethernet1/8 23 ukn/ukn/down(autoneg) 34:e5:ec:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is there a change to bring up the HA from remote (site is far, far away) with only minimum interrupt (reboot)?&lt;BR /&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Sat, 12 Jun 2021 07:23:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ha-down-pa-220/m-p/412701#M92865</guid>
      <dc:creator>ChrisCon</dc:creator>
      <dc:date>2021-06-12T07:23:39Z</dc:date>
    </item>
    <item>
      <title>Re: HA down PA-220</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ha-down-pa-220/m-p/412744#M92871</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/176411"&gt;@ChrisCon&lt;/a&gt; ,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It sound like hardware issue for me...Have you tried to power cycle (reboot) it again?&lt;/P&gt;</description>
      <pubDate>Sat, 12 Jun 2021 19:42:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ha-down-pa-220/m-p/412744#M92871</guid>
      <dc:creator>aleksandar.astardzhiev</dc:creator>
      <dc:date>2021-06-12T19:42:03Z</dc:date>
    </item>
    <item>
      <title>Re: HA down PA-220</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ha-down-pa-220/m-p/412796#M92878</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/176411"&gt;@ChrisCon&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Check System logs in GUI and from CLI&lt;/P&gt;
&lt;P&gt;Check below logs&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;less mp-log ha_agent.log&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Also troubleshoot why HA ports are down?&lt;/P&gt;
&lt;P&gt;Check Physical connections.&lt;/P&gt;
&lt;P&gt;IF HA is enabled on both firewalls then if physical interfaces are up again then your issue should be fixed.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;
&lt;P&gt;Mahesh&lt;/P&gt;</description>
      <pubDate>Sat, 12 Jun 2021 22:38:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ha-down-pa-220/m-p/412796#M92878</guid>
      <dc:creator>MP18</dc:creator>
      <dc:date>2021-06-12T22:38:17Z</dc:date>
    </item>
    <item>
      <title>Re: HA down PA-220</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ha-down-pa-220/m-p/412824#M92881</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/176411"&gt;@ChrisCon&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;I agree with&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/70130"&gt;@aleksandar.astardzhiev&lt;/a&gt;&amp;nbsp;that this is likely a hardware issue, but since you're also getting server errors it could also easily be a software issue that can be resolved with a reload of the firewall.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I would however actually caution against reloading either firewall until you have someone on-site that can actually troubleshoot what is going on. The reason for this is simply that restarting the fw2 and/or fw1 while something is in this sort of state could actually cause a split-brain situation. Since the network is "functional" and this isn't actively causing any issues outside of the lose of HA, I wouldn't want to introduce something that actually ends up effecting traffic by attempting to fix the issue until I'm on-site with the hardware.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 13 Jun 2021 04:01:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ha-down-pa-220/m-p/412824#M92881</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2021-06-13T04:01:35Z</dc:date>
    </item>
  </channel>
</rss>

