MarkTan wrote:
Hello,
In a scenario with two palo alto firewalls where the active firewall fails over to the passive firewall, if there are IPSEC tunnels established are they suppose to automatically come up on the second firewall when the failover occurs or do we have to initialize them manually? If we wanted them to automatically come up, how would we do so? Can someone provide a configuration example?
Thanks,
Mark
In my experience, as long as the tunnel is actually active (I.E. currently passing traffic), then yes, they do. And without interruption to traffic flows, normally. I have occasionally run into issues when failing *back* from the HA peer to the normal "primary" - sometimes that will drop and re-establish the tunnel almost immediately - but that's enough to break some things (I have a GRE tunnel which goes through the Palo Alto and terminates on another device inside my network - when this drop out occurs, the GRE tunnel always breaks). Cheers.
... View more