- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
06-25-2016 05:47 AM
I have a pair of PAN 5060 (v.7.1.2) firewalls in HA Passive/Active connected with LACP to pair of core Nexus 9000 switches. From time to time (every hour or few) connectivity to active firewall is faling (can't ping firewall LACP L3 interface ip address from core) for a few sec. When it happens I noticed presence of MAC adddress of firewall on the core switch where passive HA cluster member is connected but failover is not a case here (there is neither no reason not trace of failover). When connectivity is restored I can see MAC address of firewall back on core switch where active firewall is connected.
06-25-2016 06:12 PM
1. Any pattern/specific time frame when does this issue happen?
1. Have you try to run continue ping from a host behind the firewall to outside of the firewall?
2. Have you try to turn off LACP on the firewall and 9K ?
-E
07-03-2016 04:17 AM
No specific time frame, every hour or few. I've not try to turn off LACP neither ping from host behind the firewall to outside of the firewall. I was advised to trigger a GARP and catpure it.
07-03-2016 04:39 AM
Can you confirm that spanning tree is not enabled on the Nexus ports and potentially moving to blocking on the active link port.
If there is no spanning tree, then TAC is correct no mac migration should occur outside of a bug in the PanOS causing the passive device to arp this address. the packet captures should confirm the exact behavior.
07-06-2016 05:23 AM
Spanning tree is enabled on switch for that vlan where firewalls lives in. But there was no changes of active ports when firewall MAC appeared (on switch where Passive is connected)
07-08-2016 02:23 PM
Hello,
I agree with pulukas, try disabling spanning tree on just those ports where the PAN's are connected and see if that resolves the issue.
Regards,
07-10-2016 04:01 AM
If there is no spanning tree port status change, then this does have to be a bug. The mac move should not occur in that scenario.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!