Palo alto passive link shutdown mode drawaback and auto mode advantage

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

Palo alto passive link shutdown mode drawaback and auto mode advantage

L1 Bithead

Hi All,

 

I want to know Palo alto passive link shutdown mode drawaback and auto mode advantage.

 

Is the any issue to confiigure passive link in shutdown mode

1 REPLY 1

Cyber Elite
Cyber Elite

Shutdown mode:

The passive device interfaces are physically down by default until an HA event, once the firewall has an HA event the passive unit brings it's interfaces online.  

 

Auto Mode:

Both the active and the passive units have active interfaces however the passive device gets set to discard any packets that reach it's interface, this is used in a layer-3 setup for faster failover. The IP and the MAC addresses of the L3 interfaces will have the same virtual MAC and IP addresses on both the active and passive units. In this state the passive firewall will not answer ARP requests until an HA event. 

 

Which you should use is dependent on how your network is setup. Auto is generally prefered as it will decrease the overall time to actually failover to your passive device.  There are downsides to Auto when we start talking about link and path monitoring and preemptive mode on the firewall and about a dozen other configuration settings that can make Auto mode less than ideal. 

  • 2240 Views
  • 1 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!