we ran into a strange problem tonight.
We are running PA 4.0.8 in active/active because me might encounter asymmetric routing.
We have two A/A clusters in different data centers. Both clusters have the same cluster ID.
The traffic is going only over one cluster by design. We checked the traffic counters on the routers and confirmed that only one site is seeing traffic, BUT, the strange thing is that I saw traffic logs in the passive DC cluster.
At the same time the traffic crossing the PAs was very slow or not working at all.
Could it be that somehow the session information is forwarded to another cluster if it has the same cluster ID?
After disabling HA3 the problem went away and I don't see anything anymore in the traffic logs on the passive cluster.
the clusterID is what is used to announce cluster membership, so if both clusters have the same ID and reside on the same networks/VLANs this could potentially cause the wrong members to join a cluster. Please make sure to give each cluster a unique cluster ID so peers can't join the wrong cluster
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!