PA-5400 Series Port HA1 Down every time there is an upgrade

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

PA-5400 Series Port HA1 Down every time there is an upgrade

L2 Linker

Hi everyone,

 

I found a problem every time we upgrade the PA-5420 firmware. After the device reboots, port HA1 is always down. I tried to find the relevant logs. It could not find any reason for this happening.

Has anyone encountered this kind of problem? I want to know what is the root cause of this problem.

We directly connect Active and Passive.

We upgraded from PAN-OS 10.2.3 to 10.2.4 and encountered this problem on both devices.

We work around this by unplugging and re-inserting Port HA1 every time the device reboots.

 

Thank you.

 

1 accepted solution

Accepted Solutions

Hey everyone I get summary in this case.

TAC informed me about the SFP issue.
I used copper SFP for HA1 and HA1-B.
TAC said it was a problem with the SFP driver itself not being compatible with the 5400 series. The solution was to switch to fiber sfp+ SR for HA1 and HA1-B, and I didn't have the problem again. When we reboot the device.

 

Hope it can help you.

View solution in original post

4 REPLIES 4

L2 Linker

I see only log about "HA1 MAIN link flapping recovering after monitor-hold-time of 3000ms"

I'm not sure what caused it.

L0 Member

Seeing the same on two of my PA-5420 pairs that are in Active/Passive configuration. They are using sfp-rj45 modules with cat 6a connecting the firewalls. Ran into it again today with the 10.2.4-h3 update.

L0 Member

I have pairs of PA-5410 in active/passive and I've had this problem every time I've upgraded - including to the latest preferred v10.2.4-h4.  The pairs go into a split-brain with HA1 showing down and it takes several minutes for the issue to resolve itself.  I do *not* have this problem on any of the PA-4x0 series in acitve/passive. 

Hey everyone I get summary in this case.

TAC informed me about the SFP issue.
I used copper SFP for HA1 and HA1-B.
TAC said it was a problem with the SFP driver itself not being compatible with the 5400 series. The solution was to switch to fiber sfp+ SR for HA1 and HA1-B, and I didn't have the problem again. When we reboot the device.

 

Hope it can help you.

  • 1 accepted solution
  • 2264 Views
  • 4 replies
  • 2 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!