Palo alto Prisma Site deployment.

Showing results for 
Show  only  | Search instead for 
Did you mean: 

Palo alto Prisma Site deployment.

L0 Member

We have a site(Spoke) where we have one internet and MPLS circuit terminating on ION 3K. We have set up HA on ion 3k.


This site doesn't have a DIA Internet circuit but a Shared one and gets IP from DHCP.

The problem is when failover happens(bouncing Lan2 which is being tracked) the site goes down. Any suggestions?


L2 Linker

Hi @mohit.kukreti 

Bouncing LAN2 interface will trigger HA fail-over process but as soon as the primary device LAN2 interface goes up/up it will again claim for the HA-Active role. 

I recommend unplugging the cable from LAN 2 interface and waiting for the skew time to the secondary device to take an active role. (The skew time is calculated by taking 256 – the router priority / 256)

Once the secondary device is HA-Active it will request for DHCP IP to wan router and then start forwarding traffic.
It is recommended to use a static IP address on WAN side to minimize the fail over time. 

helpful commands...

#dump spoke-ha status ===> to check device HA state. 

#dump interface status internet1 ===> to check if the device got IP address from DHCP. 

#inspect flow brief ==> to see if traffic is working fine. 

  • 1 replies
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!