Incoming Traffic failed in Active Active HA

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Incoming Traffic failed in Active Active HA

L2 Linker

Hi,

I setup active/active configuration and everything seems to be working. We test HA by powering off the other peer and vice versa. All outgoing traffic are working as expected. But, we notice that we're not receiving incoming traffic if one of the PAN fails. I configured NAT and assign the active/active HA binding to both.

Please help.

Thanks,

Rex

5 REPLIES 5

L6 Presenter

Hi...You may want to double-check your dest (inbound) NAT as the dest NAT should only be binded to the active primary device.  Please refer to this document for more info.


Configuring Active Active HA:  https://live.paloaltonetworks.com/docs/DOC-1756

Thanks for the reply rmonvon.

I tried to bind it on the active primary device and also tried to use both but none of it is working. Everytime I reboot the device, incoming traffic never comes back until the rebooted is back online.

If you suspend the secondary device & keep primary running, does it work?

This is weird. Everytime I reboot the secondary device, incoming traffic stops. But if I reboot the primary device, both incoming and outgoing is normal. I follow the instructions in tech-note for HA.

That is odd.  Can you monitor the ARP cache/MAC table on your switch/router and see what happens to the ARP/MAC entry for the NAT IP.  It should reflect the change as the HA failover and recover.

  • 2679 Views
  • 5 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!