07-20-2017 12:42 PM
07-20-2017 12:43 PM
07-20-2017 12:45 PM
If you do a config audit between the active and passive firewall is anything actually different? Honestly it sounds like your Passive firewall got a little hosed; has it been restarted since the split-brain toke place?
07-20-2017 12:48 PM
07-20-2017 01:06 PM
Yes we went ahead and restarted our secondary and that fixed the issue but I still don't know why it was going a route that no longer existed any ideas where to look?
07-20-2017 01:08 PM
Initial guess would be that you should check the config audit and see if for some reason it didn't somehow jump back to an old config from when that was a valid route. Other than that I can't really think of why it would be using that IP if it was removed several months ago.
07-21-2017 01:45 AM
PA will send traffic based on its own routing table or VRs. Was it static route pointing to that router IP or dynamically learned one?
07-21-2017 05:58 AM
I would be able to search for it with the global search wouldn't I. The other issue is that this wasn't a problem until we last power, the heart beat connection failed and we went into a split brain condition. We did check before restarting the secondary, that the primary was listed as active and the secondary was list as passive. I checked the traffic monitor, system logs and did verify that it was only passing traffic on the secondary during the loss of heartbeat connection and then it was only passing on the primary. It was also only one of our zones not all. Very curious situation.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!