failover

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

failover

L4 Transporter

Is there anything such as a particle failover with a palo alto firewall? Can it start to failover and suddenly fail back and block some traffic

22 REPLIES 22

Cyber Elite
Cyber Elite

There should be no partial failover.

Either active/passive or active/active.

Do you see failover event in System log?

Enterprise Architect, Security @ Cloud Carib Ltd
Palo Alto Networks certified from 2011

L7 Applicator

PAN-OS 8.0.1?

@Remo

I didn't think it was possible either but someone asked and I wanted more than just my answer I am about to check the system logs 🙂

@Raido_Rattameister  @Remo

 

what is the event to look for in the system logs for a fail over is it failover?

( subtype eq ha)

 

Enterprise Architect, Security @ Cloud Carib Ltd
Palo Alto Networks certified from 2011

@Raido_Rattameister

I thought you were lauging at me LOL it seems to have lost it heartbeat connection but could that break anything once that condition is cleared?spiltbraind.PNG

If firewalls don't see each other over HA1 then both are active and accept sessions.

Shut down one firewall if you can't fix HA1 to get things up and running.

You have split brain situation.

Enterprise Architect, Security @ Cloud Carib Ltd
Palo Alto Networks certified from 2011

@Raido_Rattameister

 

Its no longer in split brain that I can see , but we could restart the passive firewall right now and see what happens. It is trying to send traffice to a router IP that no longer exists

@jdprovine,

Are you sure that your passive firewall is actually passive and not processing traffic. Just because this unit reports that it's staying in active after the split-brain event doesn't mean necessary that the peer firewall didn't come to the same conclusion. During the 428s where you were in a split-brain event however you would definately have both firewalls processing traffic.  

@BPry

I am going to go check the traffic on the passive palo and see

But what would it route to an IP address that no longer is on the PA?

@jdprovine,

Are the sessions routing to the non-existing IP possibly be tied to existing sessions? Depending on your policy setup it would continue to take that path, or attempt to. If this is tied to specific sources or destinations you could try clearing the session list with a filter for that criteria and see if that clears things up. 

@BPry

could there still be a session related to an IP that was removed several months ago from the PA? It also looks like the synch is still in progress between the two PA's and it seems like it is lasting too long

  • 5704 Views
  • 22 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!