Issue with PA-445 Failover - Interface Reset

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Issue with PA-445 Failover - Interface Reset

L1 Bithead

We just replaced our active-passive PA-850s with PA-445s and have run into an issue when we failover the firewalls.  On failover, all the data-plane interfaces on the new active node go down for 20 seconds before coming back up.  This is dropping every active connection through the firewall.  We did not see this behavior on the PA-850s (failover was basically instantaneous) and we do not see it on PA-1410s we recently deployed either.

 

Support is claiming this is working as designed and this interface reset behavior was intentionally introduced to the PA-440 series in 11.1.  We did not get a straight answer if the issue is limited to just the PA-440 and PA-445, but we know at least the PA-1410 does not have it.  Anyone else experiencing this? 

2 REPLIES 2

Community Team Member

Hi @ControlAdmins ,

 

There was a known issue (PAN-181968) that affected the PA-4xx series where interfaces could take longer than expected to come up during HA failover. That behavior wasn’t intentional and it’s been corrected in later releases so you should already have the fix in 11.1.

 

With that resolved, the most common factor I’ve seen influence longer failover times on the PA-400 series is the Passive Link State setting. What do you currently have that configured as? If it’s set to shutdown, the passive unit keeps its interfaces physically down. Switching Passive Link State to Auto keeps the ports up on the passive firewall, which prevents link renegotiation during failover and improves failover times. 

LIVEcommunity team member
Stay Secure,
Jay
Don't forget to Like items if a post is helpful to you!

Please help out other users and “Accept as Solution” if a post helps solve your problem !

Read more about how and why to accept solutions.

L1 Bithead

We have passive link state set to auto in the "Active/Passive Settings" in the HA config.  We are also on 11.1.10-h1.  If it is in a newer release than that, we haven't taken it yet, as we usually only take preferred releases and haven't made the jump to 11.2 yet.

  • 76 Views
  • 2 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!