HA - Link Monitoring

Announcements
Attention: The LIVEcommunity is experiencing an interruption with videos in some areas. We apologize for any inconvenience this may cause. Thank you for your patience as we work towards a solution to restore videos.
Reply
Highlighted
Not applicable

HA - Link Monitoring

Hi,

I´m testing the HA configuration of our firewalls and experience unexpected behavior.

If both HA members experience link down errors, we want the appliance with the most active links to be active.

In the "PAN-OS HA - Understanding PAN-OS HA states, timers and loops" document I found this:

"If both the active and passive devices experience multiple failures, the device with the least number of failed links or paths will function as the active device."

Unfortunately this doesn´t work in our case.

If both members have one link down, the passive appliance goes into non-functional state and the active appliance stays active.

Now the active appliance looses another link but instead of switching to the 2nd appliance it stays active and in the ha-log you can read "staying in functional state upon monitor failed with peer not available to go active"

Maybe I missed a configuration task?

kind regards,

Alex

Highlighted
L3 Networker

Re: HA - Link Monitoring

Hello,

I have confirmed with engineering that this statement is not valid for current HA behavior, in a non functional stat we will not compare the number of failed links between the active and the passive device.

We are in the process of correcting the online document.

Thanks for the feedback.

Regards,

Gary S.

Highlighted
Not applicable

Re: HA - Link Monitoring

thx for the information,

even I´m not happy about it :smileysad:

I think it would be better to change the behavior than to change the documentation.

Why should a appliance with 5 links down stay active when the backup device only has one link down?

Most of your competitors keep the the appliance with the most links up.

Is it possible to file a change / enhancement request that you return to the old behavior?

kind regards,

Alex

Highlighted
L3 Networker

Re: HA - Link Monitoring

Hi,

Has there been any changes been made so that the Device with the most number of active links stay up ? I have a customer who has the same concerns.

It does make sense to keep the device with maximum number of active devices up with link monitoring is enabled.

Regards,

Sunil

Highlighted
L4 Transporter

Re: HA - Link Monitoring

Sunil/Alex,

I would request you to please contact your sales team from Paloalto networks to put in a feature request for your scenario.

Thanks

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!

The Live Community thanks you for your participation!