HA Interfaces failover triggers

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

HA Interfaces failover triggers

L2 Linker

Hi All,

 

We currently have a pair of PA-5250 firewalls configured in active/passive. We have 4 port channel groups configured with the condition set to 'all'.

 

The question i have is we are using eth1/1 & eth1/2 as HA interfaces if one of these goes down will the firewalls failover?

 

Also is it possible to stop a interface from causing a failover? the global link monitoring configuration is set to 'any'



Please note you are posting a public message where community members and experts can provide assistance. Sharing private information such as serial numbers or company information is not recommended.
4 REPLIES 4

Cyber Elite
Cyber Elite

Hello @ElliotM

 

If one of the interface that is configured for HA goes down, it will not cause failover event because these interfaces are not tracked, however as a best practice you should have a backup link for HA1 as well as for HA2 interfaces.

 

If HA1 interface goes down without HA1 backup to be configured, it might cause split brain when both Firewalls go into active state: https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u0000004OPJCA2&lang=en_US%E2%80%A...

 

If HA2 interface goes down without HA2 backup to be configured, the state information between Firewalls will not be in sync.

 

Here is HA Best Practice KB: https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000Cm5ZCAS

 

If you want to exempt an interface from failover tracking, I would remove it from link interface monitoring.

 

Kind Regards

Pavel

Help the community: Like helpful comments and mark solutions.

Cyber Elite
Cyber Elite

Hello,

Set the setting on the interface group to ALL. This way both interfaces have to be down to trigger a failover.

Regards,

Hi,

 

Just to be sure you are saying the HA interfaces are not tracked via the link monitoring even if they are not the dedicated HA ports.

 

Also thanks for the other info, we have backup HA1 & HA2.

Cyber Elite
Cyber Elite

Thank you for reply @ElliotM

 

Yes, this is my understanding. It is possible to set regular data plane interfaces to HA type and add it to HA Link Monitoring, however based on my tests shutting this interface down does not trigger a failover. I was testing it with PA-220 where I used interfaces 1/7 and 1/8 for HA.

 

Kind Regards

Pavel

Help the community: Like helpful comments and mark solutions.
  • 2741 Views
  • 4 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!