- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
05-13-2025 11:57 PM - last edited on 05-15-2025 05:09 AM by kiwi
We’re experiencing a critical issue with our HA setup on a pair of Palo Alto PA‑3420 firewalls running PAN‑OS 11.1.6‑h3 in Active‑Passive mode (HA Group 25, preemptive disabled). Both firewalls simultaneously believed they were active, causing a complete traffic halt and requiring a manual reboot of the actual active node to restore service. We suspect the problem is tied to our LACP configuration on AE-group ae1 (aggregating Ethernet1/13–16 with LACP in fast mode). Logs indicate that interfaces were being moved out of the AE-group due to link down events, and there were HA sync issues (Can't synchronize control plane data). We’ve verified cabling, switch configuration, and LACP status (ports show collecting/distributing when stable). Our HA settings and IPs are correctly matched, and we’re using a PSK for HA communication. We’re looking for guidance on how to stabilize LACP and prevent AE-group flapping from affecting HA, whether there are known bugs in PAN-OS 11.1.6-h3 related to HA or LACP, and any best practices to ensure HA state remains consistent during link transitions. Any insights or suggestions would be greatly appreciated.
05-15-2025 09:58 AM
Did this start out of the blue or after you applied 11.1.6-h3? I've had multiple instances where recent PAN-OS releases have caused a split-brain scenario and reverting has immediately resolved the issue across multiple different models in active/passive setups.
As for the LACP issue causing a split-brain scenario, I think your LACP issues are more than likely a consequence of your split-brain scenario than the issue causing your split-brain scenario. Do you have HA1/HA2 directly connected between the two units or are you passing it through a switch? If you're passing it through a switch, is it the same one handling your aggregates?
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!