- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
03-14-2024 04:49 PM
I noticed HA2 link down between the HA A/P peers.
I tried to bounce the link but it didn't help
Disabled session synchronisation and HA2 came up
Re-enabled session synchorisation, HA2 link went down.
Disabled keep-alive on both active and passive firewalls and HA2 link came up
This is when HA2 keepalive is enabled.
This is when HA2 keepalive is disabled.
Has anyone come across this issue before?
03-16-2024 07:56 PM
I would advise against HA setups in Azure heavily. It's best to deploy two 'active' firewalls as standalone device and use the 'load balancer sandwich' method to facilitate this. PAN HA sitting in Azure has come a long way since it was initially released, but it simply doesn't scale well and still causes long failover times. I'd avoid an HA config in Azure outright.
https://www.paloaltonetworks.com/resources/guides/azure-transit-vnet-deployment-guide
03-17-2024 01:18 AM
@BPry, thanks for your reply! I 100% agree with you but this is just an existing environment that I’ve picked up as I work in a MSSP and this setup was working fine until it broke a couple weeks ago, no changes at all that could’ve caused the issue. I opened a TAC case and waiting on PA team to advise, I have a feeling it’s a bug 🙂
03-19-2024 02:23 PM
So... I upgraded the firewalls from 10.1.11 to 10.2.8 and re-enabled HA2 keep-alive and HA2 link stays up. It turned out to be a bug as expected.
@BPry FYI
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!