07-20-2017 10:12 AM
Is there anything such as a particle failover with a palo alto firewall? Can it start to failover and suddenly fail back and block some traffic
07-20-2017 10:29 AM
There should be no partial failover.
Either active/passive or active/active.
Do you see failover event in System log?
07-20-2017 10:33 AM
PAN-OS 8.0.1?
07-20-2017 11:02 AM
I didn't think it was possible either but someone asked and I wanted more than just my answer I am about to check the system logs 🙂
07-20-2017 11:02 AM
nope 7.1
07-20-2017 11:10 AM
@Raido_Rattameister @vsys_remo
what is the event to look for in the system logs for a fail over is it failover?
07-20-2017 11:29 AM
( subtype eq ha)
07-20-2017 11:39 AM
I thought you were lauging at me LOL it seems to have lost it heartbeat connection but could that break anything once that condition is cleared?
07-20-2017 11:49 AM
If firewalls don't see each other over HA1 then both are active and accept sessions.
Shut down one firewall if you can't fix HA1 to get things up and running.
You have split brain situation.
07-20-2017 12:06 PM
Its no longer in split brain that I can see , but we could restart the passive firewall right now and see what happens. It is trying to send traffice to a router IP that no longer exists
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!