LACP in HA issue

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

LACP in HA issue

L3 Networker

I have a pair of PAN 5060 (v.7.1.2) firewalls  in HA Passive/Active connected with LACP to pair of core Nexus 9000 switches. From time to time (every hour or few) connectivity to active firewall is faling (can't ping firewall LACP L3 interface ip address from core) for a few sec. When it happens I noticed presence of MAC adddress of firewall on the core switch where passive HA cluster member is connected but failover is not a case here (there is neither no reason not trace of failover).  When connectivity is restored I can see MAC address of firewall back on core switch where active firewall is connected.

6 REPLIES 6

L4 Transporter

1.   Any pattern/specific time frame when does this issue happen?

1.   Have you try to run continue ping from a host behind the firewall to outside of the firewall?

2.   Have you try to turn off LACP on the firewall and 9K ?

 

-E

No specific time frame, every hour or few. I've not try to turn off LACP neither ping from host behind the firewall to outside of the firewall. I was advised to trigger a GARP and catpure it. 

Can you confirm that spanning tree is not enabled on the Nexus ports and potentially moving to blocking on the active link port.

 

If there is no spanning tree, then TAC is correct no mac migration should occur outside of a bug in the PanOS causing the passive device to arp this address.  the packet captures should confirm the exact behavior.

Steve Puluka BSEET - IP Architect - DQE Communications (Metro Ethernet/ISP)
ACE PanOS 6; ACE PanOS 7; ASE 3.0; PSE 7.0 Foundations & Associate in Platform; Cyber Security; Data Center

Spanning tree is enabled on switch for that vlan where firewalls lives in. But there was no changes of active ports when firewall MAC appeared (on switch where Passive is connected)

Hello,

I agree with pulukas, try disabling spanning tree on just those ports where the PAN's are connected and see if that resolves the issue.

 

Regards,

If there is no spanning tree port status change, then this does have to be a bug.  The mac move should not occur in that scenario.

Steve Puluka BSEET - IP Architect - DQE Communications (Metro Ethernet/ISP)
ACE PanOS 6; ACE PanOS 7; ASE 3.0; PSE 7.0 Foundations & Associate in Platform; Cyber Security; Data Center
  • 4349 Views
  • 6 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!