- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
05-08-2018 09:22 AM
I have two PaloAlto 850's in HA. I am unable to ping or reach the secondary/standby webgui. Both are connected to the same switch, when looking at the switch CAM table the secondary MGMT interface is not getting populated with the FW MAC address. Being that the switch is not recieving a frame from the FW to populate the CAM table I have tried the following: I have swapped out cables, interfaces on the switch and rebooted the FW multiple times.
Has anyone else ran into this issue or may have a suggestion?
TIA
05-09-2018 09:03 AM
Something got corrupted in the config itself. After reloading a named config file it started working.
05-08-2018 10:06 AM
Hello,
Just to make sure, both the active and standby PAN's have different management IP's? Do the vlans on the switch match the IP subnets of the PAN's?
The management interface should always have a light and be accessible even if it is the standby HA pair.
Just thinking out loud.
Regards,
05-08-2018 10:16 AM - edited 05-08-2018 10:18 AM
Indeed, both are in the same subnet and VLAN and they both have a different MGMT IP.
I even swaped the cable plugged into the primary and secondary MGMT interface and the issue followed.
05-08-2018 10:30 AM
Perhaps try a different IP on the same subnet?
05-08-2018 12:00 PM
Not sure the IP matters at this point. When the interface comes up it should send an ethernet frame to the connected device with its MAC. In this case it appears the FW is not sending that frame to let the switch know the MAC that's connected.
05-08-2018 12:02 PM
Maybe there is something in the switch logs?
05-09-2018 02:29 AM
Hi @jmarchant, from the switch perspective can you see that the port is (UP/UP)? Have you tried manually adding the mac address on the switch mac table?
05-09-2018 09:03 AM
Something got corrupted in the config itself. After reloading a named config file it started working.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!