Enhanced Security Measures in Place:   To ensure a safer experience, we’ve implemented additional, temporary security measures for all users.

failover

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

failover

L4 Transporter

Is there anything such as a particle failover with a palo alto firewall? Can it start to failover and suddenly fail back and block some traffic

22 REPLIES 22

@jdprovine,

One would not expect so. When you say sync are you talking about the config sync? 

@BPry

Yes the config sync seems stuck

If you do a config audit between the active and passive firewall is anything actually different? Honestly it sounds like your Passive firewall got a little hosed; has it been restarted since the split-brain toke place? 

@BPry

I pushed a sync from the primary and it fixed it

@BPry

 

Yes we went ahead and restarted our secondary and that fixed the issue but I still don't know why it was going a route that no longer existed any ideas where to look? 

@jdprovine,

Initial guess would be that you should check the config audit and see if for some reason it didn't somehow jump back to an old config from when that was a valid route. Other than that I can't really think of why it would be using that IP if it was removed several months ago. 

@jdprovine,

 

PA will send traffic based on its own routing table or VRs. Was it static route pointing to that router IP or dynamically learned one? 

@TranceforLife

 

I would be able to search for it with the global search wouldn't I. The other issue is that this wasn't a problem until we last power, the heart beat connection failed and we went into a split brain condition. We did check before restarting the secondary, that the primary was listed as active and the secondary was list as passive. I checked the traffic monitor, system logs and did verify that it was only passing traffic on the secondary during the loss of heartbeat connection and then it was only passing on the primary. It was also only one of our zones not all. Very curious situation.

  • 5540 Views
  • 22 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!