- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
09-12-2019 09:58 AM
Howdy
I do not think it is a misconfiguration on either product. I think it understanding how the PANW firewall does passive firewall interfaces.
By default, in HA on the PANW firewalls, the EXACT configuration (minus HA and Admin accounts) is synch'd across both FWs.
Because both Active and Passive FW have the EXACT inside IP/mask, there needed to be a way to ensure the passive fw did NOT try to respond to arp requests, when it was in passive mode.
This is accomplished (and I think this the issue), by ensuring that the passive fw interfaces are administratively DOWN.
This seems to be the reason why you would not get LACP adjancency.
If you change the setting to up, it may assist in adjacency for LACP.