- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
Enhanced Security Measures in Place: To ensure a safer experience, we’ve implemented additional, temporary security measures for all users.
09-03-2024 07:40 PM
Hi everyone!
I am having some confusion on HA Link Monitoring and Failover. I did exactly the same thing with video courses and Palo alto document guide but it still doesn't work
For context, i am monitoring my eth1/2 and eth1/3 for failover. So i shut down the G0/0 interfaces of the routers directly connected to them and still there's no failover. I even configured the ethernet interface in Palo Alto to "down" state but no good. Am I missing something here?
Thank you in advance!
09-03-2024 09:05 PM
From reply for #1, that's the reason.
Link Monitoring keeps looking for link status of specified ports. To trigger it, you need to link-down that ports.
Try to unplug LAN cable on both ports, I believe it works. (icon will change to RED and fail-over should be occurred)
09-03-2024 11:00 PM
Hi @renzanjo11
In any virtual environment (like EVE-NG) the link status will not be down even you shut down the other ending port of the link.
In such use cases, for VM firewalls in HA you can use Path Monitoring as failover trigger.
09-03-2024 07:51 PM
I need two more information to answer your question.
#1
Does the status of eth1/2 and 1/3 change to linkdown after you shutdown G0/0?
In another words, GREEN should be changed to RED as below.
#2
What is the device status of peer device?
Fail-over occurs only when peer device is ready for fail-over which means peer device have to be "passive" if you are configuring active-passive.
If it is other status such as non-functional, suspended, etc., it does not fail over.
09-03-2024 08:31 PM
Hi!
#1
When I shut down the G0/0, my Palo Eth interfaces still shows green.
#2
The status shows active-passive
HQ-FW as active and HQ-FW-2 as passive
09-03-2024 09:05 PM
From reply for #1, that's the reason.
Link Monitoring keeps looking for link status of specified ports. To trigger it, you need to link-down that ports.
Try to unplug LAN cable on both ports, I believe it works. (icon will change to RED and fail-over should be occurred)
09-03-2024 10:42 PM
I tried removing the link and the port still shows green. Is there something wrong with EVE-NG? I am trying this with EVE-NG.
09-03-2024 11:00 PM
Hi @renzanjo11
In any virtual environment (like EVE-NG) the link status will not be down even you shut down the other ending port of the link.
In such use cases, for VM firewalls in HA you can use Path Monitoring as failover trigger.
09-03-2024 11:05 PM
Ah, you are using PA-VM, I thought it is related to hardware appliance.
Even I'm not familiar with EVE-NG, seems EVE-PRO provides the feature related to link state.
If this doesn't work, maybe using path monitoring is easier than link monitoring.
https://www.eve-ng.net/index.php/documentation/professional-cookbook/
09-03-2024 11:58 PM
Hi @emr_1 , yep! This one is available on the pro i believe. But I resorted back to Path monitoring instead since I got a VM firewall. Much less of a headache 😄
Thank you very much!
09-03-2024 11:59 PM
Hi @CosminM , indeed! I tried path monitoring. Gave me much better reconvergence and failover. This is noted for VM deployments. Thank you very much!
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!