07-20-2017 10:12 AM
Is there anything such as a particle failover with a palo alto firewall? Can it start to failover and suddenly fail back and block some traffic
07-20-2017 12:16 PM
Are you sure that your passive firewall is actually passive and not processing traffic. Just because this unit reports that it's staying in active after the split-brain event doesn't mean necessary that the peer firewall didn't come to the same conclusion. During the 428s where you were in a split-brain event however you would definately have both firewalls processing traffic.
07-20-2017 12:26 PM
I am going to go check the traffic on the passive palo and see
07-20-2017 12:28 PM
But what would it route to an IP address that no longer is on the PA?
07-20-2017 12:34 PM
Are the sessions routing to the non-existing IP possibly be tied to existing sessions? Depending on your policy setup it would continue to take that path, or attempt to. If this is tied to specific sources or destinations you could try clearing the session list with a filter for that criteria and see if that clears things up.
07-20-2017 12:39 PM
could there still be a session related to an IP that was removed several months ago from the PA? It also looks like the synch is still in progress between the two PA's and it seems like it is lasting too long
07-20-2017 12:42 PM
One would not expect so. When you say sync are you talking about the config sync?
07-20-2017 12:43 PM
Yes the config sync seems stuck
07-20-2017 12:45 PM
If you do a config audit between the active and passive firewall is anything actually different? Honestly it sounds like your Passive firewall got a little hosed; has it been restarted since the split-brain toke place?
07-20-2017 12:48 PM
I pushed a sync from the primary and it fixed it
07-20-2017 01:06 PM
Yes we went ahead and restarted our secondary and that fixed the issue but I still don't know why it was going a route that no longer existed any ideas where to look?
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!