- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
12-11-2023 01:23 AM - edited 12-11-2023 02:09 AM
Dear Folks,
First time I'm deploying PAs with LACP active/passive for HA solutions. I have some doubts couldn't get enough information from Internet source.
1. In the event, if one firewall goes down, PC on SW1 goes down, how this mac and arp movement happening?
Interestingly when I give show interface on PA's both FW1 & 2 sharing same AE MAC, so wondering how MAC[GARP] movement will kick in during FO event.
2. When I see lacp on PAFW1and2's what does mean system MAC and Partner MAC, in fact I couldn't see any ware in the switch. Where I get those details to study more about this?
Pre-negotiation: Enabled
Local: System Priority: 32768
System MAC: D:A:B:C:1a:01
Key: 66
Partner: System Priority: 65534
System MAC: A:B:C:D19:34:00
Key: 1
3. LACPDUs message are seeing [Sent and Recv counters are getting increase] on both fws. Why passive fw also doing LACPDUs sending and participating LACP election?
12-11-2023 02:57 AM
Hi @Ramakrishnan ,
The switch will learn of the passive only if a failover happens, at which point the (formerly passive) firewall will send a gratuitous ARP which will tell the switch to forward packets on the new port even though the IP and MAC are the same.
https://live.paloaltonetworks.com/t5/Management-Articles/Gratuitous-ARP-in-HA-Failover/ta-p/62781
https://live.paloaltonetworks.com/t5/general-topics/ha-active-passive-mac-address/td-p/227316
Kind regards,
-Kim.
12-11-2023 02:57 AM
Hi @Ramakrishnan ,
The switch will learn of the passive only if a failover happens, at which point the (formerly passive) firewall will send a gratuitous ARP which will tell the switch to forward packets on the new port even though the IP and MAC are the same.
https://live.paloaltonetworks.com/t5/Management-Articles/Gratuitous-ARP-in-HA-Failover/ta-p/62781
https://live.paloaltonetworks.com/t5/general-topics/ha-active-passive-mac-address/td-p/227316
Kind regards,
-Kim.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!