- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
05-24-2025 07:05 PM
I'm having an issue with a HA failover with 2 PA440s. When I finished setting up the HA for both firewalls the first time, I was not able to sync them, it threw me a strange error and after some research, I found documentation where it stated that I had to clone both firewalls from firewall 1 to 2. I did that saving the device state from the active firewall, modifying some settings and uploading to the passive firewall. Everything went well, the devices sync without issue. I tested the HA failover unplugging the active firewall and letting the passive take over, it didn't work. After waiting some minutes, I reconnected the active firewall to get the internet back. So far, I have checked:
- link and path monitoring are enabled: failure condition: any.
- devices sync without issues
- both ISPs configured on the active firewall work (I can ping from the firewall itself using troubleshooting feature)
- both ISPs on the passive firewall do not work (can't ping from the, I'm not sure if this is normal)
- HA communications: HA1 port: management / HA1 backup control link: ethernet 1/7 / HA2 data link: ethernet 1/8 enable session sync and HA2 keep alive enabled.
- Config sync enabled and Preemptive too.
The only thing I have setup different is using the HA1 port for management, and the HA1 backup for the HA failover, I'm not sure if this actually makes a difference.
So far, everything looks alright. I'm not sure where else to check for any issues. Any help is appreciated, thanks.
05-27-2025 03:30 PM
Is this necessary ? I have another failover setup with 1410s without any group configuration, just "enabled" with failure condition to "any" and they failover without issues.
06-02-2025 06:43 AM
yes, you must have at least one link group OR path monitor for failovers to work (based on link failures)
from the admin guide:
Enable and configure either path monitoring or link monitoring to help trigger a failover if a path or link goes down. Configure at least one Path Group for path monitoring and configure at least one Link Group for Link Monitoring.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!