Primary palo alto 220 missing on panorama but I can access it via CLI

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

Primary palo alto 220 missing on panorama but I can access it via CLI

L2 Linker

Needing your help I'm newbie on Palo alto . We have a Panorama on one of our sites this is PA 200 before I'm seeing the primary on panorama but not its not. Although I can access it via SSH and use the CLI but when I run the show running sync-to-panorama command it was not on list. This panoramas are old ones and slow. The mgmt and policies are allowed. We have a fail over testing within the next 2 weeks for audit.

8 REPLIES 8

Cyber Elite
Cyber Elite

Hello @weezy

 

to troubleshoot Firewall connection / registration issue with Panorama, could you check this KB: Troubleshooting Panorama Connectivity. If the issue is not resolved after following steps in KB, could you provide output from below commands from Firewall:

 

show panorama-status
show netstat all yes numeric-hosts yes numeric-ports yes

 

Also, could you check content of below file from CLI?

less mp-log ms.log

 

Kind Regards

Pavel

Help the community: Like helpful comments and mark solutions.

Hi when I check the status  it says HA disconnected 

 

 

Connected : no
HA state : disconnected

 

We have our senior engr on Palo alto working on this and I don't have an update yet as still waiting for his reply. I know as well that this old Palo alto 200 are lots of issues before I came in. But I notice before HA is connected and I'm seeing the primary on Panorama

Hi Pavel,

 

When I do the sh netstat command I got this message 

 

 

 

 

 

 

 

 

Server error : op command for client dagger timed out as client is not available

 

Also when doing a fail over test on palo alto the best way is shutting down the primary device? or suspend HA and shut the interface of primary PA facing internet

Cyber Elite
Cyber Elite

Hello @weezy

 

thank you for reply.

 

The error you reported seems related to this KB: CLI command 'show netstat listening yes' fails intermittently.

 

Regarding HA Failover, no need to reboot Firewall nor shut down interface. You can trigger a failover by suspending Firewall:

 

CLI: request high-availability state suspend
GUI: Device > High Availability > Operational Commands - click Suspend local device 

 

Kind Regards

Pavel

Help the community: Like helpful comments and mark solutions.

Hi Pavel,

 

I tried to do it on LAB suspending the HA will lead only to split brain. from active passive setup. It will become active active as they are both forwarding the same data and it might cause a problem. So was it better to shut the primary firewall instead?

Cyber Elite
Cyber Elite

Hello @weezy

 

thank you for reply.

 

Regarding split brain, could you confirm whether you enabled HA1 backup link? This is a mitigation against split brain scenario.

High-Availability - Split Brain

DotW: What is Peer-Split-Brain?

 

If you have no other choice, then I would shut down / disconnect data plane interfaces (In this case you can still access Firewall by management port) or power Firewall off.

 

Kind Regards

Pavel

Help the community: Like helpful comments and mark solutions.

Hi Pavel,

 

Unfortunately we don't have a back up MGMT ip configured and I don't want to add because our PA 200 is so slow it has a lot of weird issues. So what I will do is disconnect the cables 

 

weezy_0-1693979702006.png

 

 

 

 

 

Also I see some post on group that the heartbackup will help on preventing split brain. Please see below the post that I see on PA live community

 

 

Split brain conditions can be prevented by configuring an HA1 Backup link and/or enabling Heartbeat Backup.

 

https://live.paloaltonetworks.com/t5/general-topics/what-is-peer-split-brain/m-p/19825#U19825

  • 1037 Views
  • 8 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!