PA in active-active mode and Cluster ID

cancel
Showing results for 
Search instead for 
Did you mean: 

PA in active-active mode and Cluster ID

L2 Linker

Dear all,

we ran into a strange problem tonight.

We are running PA 4.0.8 in active/active because me might encounter asymmetric routing.

We have two A/A clusters in different data centers. Both clusters have the same cluster ID.

The traffic is going only over one cluster by design. We checked the traffic counters on the routers and confirmed that only one site is seeing traffic, BUT, the strange thing is that I saw traffic logs in the passive DC cluster.

At the same time the traffic crossing the PAs was very slow or not working at all.

Could it be that somehow the session information is forwarded to another cluster if it has the same cluster ID?

After disabling HA3 the problem went away and I don't see anything anymore in the traffic logs on the passive cluster.

Regards,

Andreas

1 REPLY 1

Cyber Elite
Cyber Elite

Hi Andreas

the clusterID is what is used to announce cluster membership, so if both clusters have the same ID and reside on the same networks/VLANs this could potentially cause the wrong members to join a cluster. Please make sure to give each cluster a unique cluster ID so peers can't join the wrong cluster

regards

Tom

Tom Piens
PANgurus
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!