- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
03-19-2019 08:09 PM
Hi There,
I will be greatful if anyone can please help me to understand the below which is taken from https://docs.paloaltonetworks.com/pan-os/7-1/pan-os-admin/high-availability/session-owner.html
03-21-2019 03:52 AM
1. in that case the secondary firewall acts as a 'dumb' gateway: it will send and receive packets but all decisions are made on the active-primary. If the primary were to fail it will start inspecting again
2. Because the 'other' (primary) firewall was doing all the inspection, when there is a failover the secondary firewall will be able to resume the sessions because it is aware of the session table, but it cannot resume scanning as it is not aware of the scanning process while the session is being scanned remotely and cannot be 'started' mid-session
not silly questions, important considerations when weighing A/A vs A/P
03-22-2019 12:27 PM - edited 03-25-2019 03:50 PM
Thanks for this topic and reply. It now makes sense that in a failover event, the single active firewall will not create new sessions on the dead firewalls NAT tables bound by Group ID. This is because once it hands them back, L7 filtering would be unavailable on any sessions created during the failover event.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!