the reason why some of the Palo Alto firewalls in HA are facing this split brain scenario is due to this BUG -106914. this is mentioned in 8.1.9 PAN OS as addressed issue. please find the detail: Fixed an issue on a firewall in a high availability (HA) active/passive configuration where HA1 and HA2 links stopped passing packets, which caused a split-brain condition after an automatic configuration sync. hence , either you are using AUX or mgmt port or any other port, if this bug is hit then HA will stop working and FWs will become active active. I am sure my config though having AUX for HA1 but mgmt for HA1 backup(not physical, but through election settings), was hit with this BUG as well. please do upgrade HA FWs with downtime only as there is no mention of any particular hardware model.
... View more