High Availability on Virtual cluster with path-monitor and ha preemption

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

High Availability on Virtual cluster with path-monitor and ha preemption

Hi Folks,

 

I found myself in "catch 22" situation and I was hoping if you guys have some ideas to share...

 

We have customer with Palo Alto HA cluster running on two separate ESXi hosts, we use separete interfaces for HA1 and H2. The cluster is up and running and everything looking good...Since the PAs are virtual we have configured path-monitor for both to monitor the inside next-hop and in case if issue to failover to secondary member. So far so good, but the customer insist to enable the preemption as well and here comes the tricky part:

- If path-monitor fails on primary it swich over to secondary member

- The "path failuer" alarm on the primary is keept about 1min

- Since the routing engine for the primary (currently on standby) is disabled the path-monitor is also not running

- The preemption kicks in and switch back from secondary to primary member

- However the LAN issues (we disabled the next-hop interface for testing) are still ongoing the path-monitor fails again and swtich back to secondary

- These repeats couple of times until the "max flapping counter" kicks in and suspend on of the members

 

At the end we still have stable HA, but all of these uncessary failover back and forth is causing some of the applications to fail (path-monitor uses the default 6ping/5sec interface, which cause some voip to completely disconnect), also it is noticed by the end users.

 

I am hoping for some solution where the wolf is full and the lamb is alive, but cann't find good solution. In my personal opinion it is big disadvantache that path-monitor alarm is clear when device become standby.

 

Thank you in advance!

0 REPLIES 0
  • 1349 Views
  • 0 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!