PA440 HA failover not working

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

PA440 HA failover not working

L0 Member

I'm having an issue with a HA failover with 2 PA440s. When I finished setting up the HA for both firewalls the first time, I was not able to sync them, it threw me a strange error and after some research, I found documentation where it stated that I had to clone both firewalls from firewall 1 to 2. I did that saving the device state from the active firewall, modifying some settings and uploading to the passive firewall. Everything went well, the devices sync without issue. I tested the HA failover unplugging the active firewall and letting the passive take over, it didn't work. After waiting some minutes, I reconnected the active firewall to get the internet back. So far, I have checked: 

 

- link and path monitoring are enabled: failure condition: any.

- devices sync without issues

- both ISPs configured on the active firewall work (I can ping from the firewall itself using troubleshooting feature)

- both ISPs on the passive firewall do not work (can't ping from the, I'm not sure if this is normal)

- HA communications: HA1 port: management / HA1 backup control link: ethernet 1/7 / HA2 data link: ethernet 1/8 enable session sync and HA2 keep alive enabled.

- Config sync enabled and Preemptive too.

 

The only thing I have setup different is using the HA1 port for management, and the HA1 backup for the HA failover, I'm not sure if this actually makes a difference.

 

So far, everything looks alright. I'm not sure where else to check for any issues. Any help is appreciated, thanks.

3 REPLIES 3

Cyber Elite
Cyber Elite

did you create Link Groups in link monitoring ?

 

reaper_0-1748344542532.png

 

Tom Piens
PANgurus - Strata specialist; config reviews, policy optimization

Is this necessary ? I have another failover setup with 1410s without any group configuration, just "enabled" with failure condition to "any" and they failover without issues.

yes, you must have at least one link group OR path monitor for failovers to work (based on link failures)

 

 

from the admin guide:

	
Enable and configure either path monitoring or link monitoring to help trigger a failover if a path or link goes down. Configure at least one Path Group for path monitoring and configure at least one Link Group for Link Monitoring.
Tom Piens
PANgurus - Strata specialist; config reviews, policy optimization
  • 804 Views
  • 3 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!