Mismatched URL Vendor on High Availability Pair

Mismatched URL Vendor on High Availability Pair

29767
Created On 09/25/18 19:48 PM - Last Modified 06/12/23 20:55 PM


Resolution


Issue

Two Palo Alto Networks devices are running the same PAN-OS version. The active device is configured for PAN-DB and the passive device is set to BrightCloud. High Availability (HA) is enabled on the active device. HA is then enabled on the passive device. As the commit operation finishes on the passive device, the active device goes into the non-functional state, and the passive device becomes active.

 

The log on the original active device shows:

Group 1:

Mode: Active-Passive

Local Information:

Version: 1

Mode: Active-Passive

State: active (last 21 hours)

Last non-functional state reason: URL vendor mismatch

 

The passive device (with BrightCloud) forced the active unit to go into a non-functional state with the message, Set dev peer state to Non-Functional. This triggers the passive device to become the active.

 

Cause

The failover is due to the mismatch of URL vendor between the HA pair of devices.

Further, if different URL vendors are used on the HA pair of devices, the one with PAN-DB will go into the non-functional state. For example, if the scenario has the active device using BrightCloud and passive device with PAN-DB, the passive unit with PAN-DB will go into the non-functional state.

 

Resolution

Ensure that both HA devices are using the same URL vendor (PAN-DB or BrightCloud).

If you do not have a license for either URL database vendor, generate a trial license to load on the passive firewall to match the database that the active firewall has loaded.

 

  1. If the active firewall is running BrightCloud, and the passive firewall is running PAN-DB, generate a trial license for BrightCloud to load on your passive firewall.
  2. Suspend the HA for the passive firewall.
  3. Load the BrightCloud trial license on the passive firewall.
  4. Activate and download the BrightCloud database on the passive firewall.
  5. Restore the high-availability state to functional for the passive firewall.

 

Note: If a new configuration snapshot is loaded on a Palo Alto Networks device with PAN-DB activated, the admin will still have to activate PAN-DB after the load. If a device with an activated PAN-DB has no DNS connection, it will still remain activated.

 

owner: shasnain



Actions
  • Print
  • Copy Link

    https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000CldrCAC&refURL=http%3A%2F%2Fknowledgebase.paloaltonetworks.com%2FKCSArticleDetail

Choose Language