- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
06-22-2023 07:10 AM
Hi everyone,
we recently re-IP'd a set of two ION3000s in an HA group and saw that site losing connectivity at every single step. That got me thinking - these IONs have two controller ports, one of which is completely unused. Can we configure that empty controller port on both IONs to be in some none-routable /30 subnet and connect the IONs directly to each other? We're doing essentially that on all our panOS firewalls already and it works great.
06-22-2023 09:12 PM
Hi @Markus_B
In-person, I don't think connecting the ION controller2 interfaces back to back is a smart idea. When the active ION is powered off, the backup ION cannot become operational since its HA-control port (controller2) is likewise shut down.
You may run a fast test on this behavior to confirm the above assertion.
-kn
06-23-2023 05:53 AM
Thanks for your reply, @kn
unfortunately, I don't have any lab units to test this with. I also haven't been able to find any technical details on how HA is designed, so I can only speculate. However, let me think your comment a bit further.
You're essentially saying, that an ION in an operational HA-group and passive state will refuse to ever become active, if the port configured for HA-sync is physically down. That would mean, that if I have the controller ports on a physically separate management network and the corresponding switch fails (or the cable gets damaged or unplugged), I lose HA completely. I would personally consider that questionable system design and be worried about deploying these IONs until an Engineer with Palo/Cloudgenix has a very good explanation on why that is. However I assume, that you're guessing as much as I am?
Thanks
06-23-2023 06:11 AM
Hi @Markus_B
The possibility you explained with the switch will not face the issue because the drive with an HA-active state will continue its functioning. All my inputs are from experience. and HA logic is similar to VRRP here with Prisma-SDWAN.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!