- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
02-27-2019 05:50 PM
Hi All,
We have PA-820 models with Active-Passive configuration.
I have configured the static route path monitoring based on this guideline - https://docs.paloaltonetworks.com/pan-os/8-0/pan-os-admin/networking/static-routes/static-route-remo...
Just would like to know, would there any impact in removing the static route from Primary RIB and replaces it with the secondary route if testing is carried out by "removing cable of the primary link port (facing to ISP)".
OR
It's better to leave the cable connection of the primary link and just block the primary link source IP at the destination. In this way, the path monitoring wouldn't ping to a destination and it should replace with the secondary route.
I did the test with removing the primary link cable from the Active Palo Alto device and it didn't replace it with the secondary route. I guess, leave it cable in and block the source address at the destination its the best way. Any suggestions, please!
Thank you.
CP
02-28-2019 12:07 AM
Hi @ChiragP ,
As you said it yourself the path monitoring is just a constant ping sent from the Palo Alto firewall to the monitored IP.
So in theory any reason for the pings packets to fail should disable the given static route. I would say both actions should end with same result.
The only different I can think of for disconnecting the interface is the link monitoring under the HA setting. Are you sure that when you disconnected the cable the firewall hasn't failover to secondary member where the cable was still connected?
Also I would suggest to check the FIB during your tests in order to be 100% sure which route is actually the active one:
> show routing fib | match <your-destination-network>
04-02-2019 11:04 PM
Hi Alexander,
Many thanks for the reply.
I haven't done the test yet after your post so didn't reply.
I will complete the test again and post the results.
Thank you.
Regards.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!