- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
06-08-2011 07:00 AM
Hi,
I´m testing the HA configuration of our firewalls and experience unexpected behavior.
If both HA members experience link down errors, we want the appliance with the most active links to be active.
In the "PAN-OS HA - Understanding PAN-OS HA states, timers and loops" document I found this:
"If both the active and passive devices experience multiple failures, the device with the least number of failed links or paths will function as the active device."
Unfortunately this doesn´t work in our case.
If both members have one link down, the passive appliance goes into non-functional state and the active appliance stays active.
Now the active appliance looses another link but instead of switching to the 2nd appliance it stays active and in the ha-log you can read "staying in functional state upon monitor failed with peer not available to go active"
Maybe I missed a configuration task?
kind regards,
Alex
06-08-2011 05:40 PM
Hello,
I have confirmed with engineering that this statement is not valid for current HA behavior, in a non functional stat we will not compare the number of failed links between the active and the passive device.
We are in the process of correcting the online document.
Thanks for the feedback.
Regards,
Gary S.
06-09-2011 12:08 AM
thx for the information,
even I´m not happy about it
I think it would be better to change the behavior than to change the documentation.
Why should a appliance with 5 links down stay active when the backup device only has one link down?
Most of your competitors keep the the appliance with the most links up.
Is it possible to file a change / enhancement request that you return to the old behavior?
kind regards,
Alex
09-22-2011 05:07 AM
Hi,
Has there been any changes been made so that the Device with the most number of active links stay up ? I have a customer who has the same concerns.
It does make sense to keep the device with maximum number of active devices up with link monitoring is enabled.
Regards,
Sunil
09-22-2011 12:26 PM
Sunil/Alex,
I would request you to please contact your sales team from Paloalto networks to put in a feature request for your scenario.
Thanks
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!