- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
08-16-2017 09:09 AM
Are they still able to communicate over the control plane?
08-16-2017 09:33 AM
After hitting sync peer many times they finally worked and synced
08-16-2017 02:18 PM
Hello,
Do you have 'Device Priority' enabled? This does help with the split brian issues sometimes.
Election Settings | Specify or enable the following settings:
|
Regards,
08-16-2017 02:51 PM - edited 08-16-2017 02:56 PM
The problem is if firewalls are unable to communicate (exchange "Heartbeat" messages) then each device assumes active role.
EDIT:
Ohh misread your message. Yes, you are right. I thought we are talking about preemption
08-16-2017 02:54 PM
Hello,
Yes that is true, however the split brain arises when communication is restored. So this should help solve that issue, correct?
Regards,
08-16-2017 04:30 PM
The device priority does not help you in split-brain situations. Split-brain is, as described by @TranceforLife, when the firewalls cannot communicate, so both peers assume the other one is down -> both change to active state.
The device priority is primary needed if you have one firewall which should, in most cases, handle the traffic. So in combination with preemptive mode, this makes sure that after a problemsituation is solved, the firewall with the higher priority (lower value) will change back to active.
If you don't care which firewall is active, there is actually no need to set different values (even if I recommend to do it anyway), because if both firewalls have the same value, the one with the lowest mac address will become the active clustermember.
If you need to reboot the firewall after a split-brain to restore full functionality of the cluster, this sounds to me like a bug ... do you have PAN-OS 8.0.1 running?
08-17-2017 08:58 AM
no i am currently on os 7.1.10, I think we are going to try to connect the heartbeat via fiber without running through switches or any other devices which seem to be the main cause in our situtation.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!