We've configured HA Active\Passive on a pair of 5250's running PAN-OS 8.1.5 and it works a treat and pre-emption also works as expected.
I've configured Link monitoring so if we get an HA failure if the trusted links fail which works and it fails over to the passive as expected but when the links come back it doesn't fail back again to the active unit.
Does Pre-emption work with Link and Path monitoring and if it does how is it configured?
Any help would be much appreciated.
Thanks
Jon
Solved! Go to Solution.
hi @JonHill
Pre-emption will wait an amount of time after a failover and then try to 'fall back' to the original setup
If after a configurable amount of retries the active device still has link monitor failures, the passive device will take over permanently until you manually fail over
Hello,
I take it you have it preemption enabled on both devices?
Preemptive—Enables the higher priority firewall to resume active (active/passive) or active-primary (active/active> operation after recovering from a failure. The Preemption option must be enabled on both firewalls for the higher priority firewall to resume active or active-primary operation upon recovery following a failure. If this setting is off, then the lower priority firewall remains active or active-primary even after the higher priority firewall recovers from a failure. |
As you say it was down to the speed at which I re-enabled the interfaces that it had permanently stayed with the peer.
Is there anyway of changing these timers and where do I find them?
Thanks
for this we should have pre enabled on both active and passive right.
Our Active PA has priority 80 and passive has 100.
Link Monitoring is only configured on Acitve PA.
With this config when link on Active PA is down and passive should takover the active role untill link on Active PA is up right?
so when link Monitoring interface comes up then the active PA which is currently passive will take over right?
How does Passive PA which becomes active will know if Link monitor interface comes up ?
Via HA1 link?
1>So it means when Link Monitored Interface on the Passive PA comes back up then PAssive PA has no way to know that
even through HA1 then as Prempt times is expired also right?
2>So in this case user has to do the manual failover like PA which become Active we should suspend it right?
3>how much is preemt timer? before newly Active PA stops checking with Passive PA?
Hi Reaper,
IF you can answer the questions please?
This stuff I never know before
Best Regards
Mike
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!
The Live Community thanks you for your participation!