Have you ever done a failover before and have it work, yes we have tested the ha failover about 6 Months ago. is this a new Active/Passive configuration? no. On your passive firewall, what is the actual status of the device? the management plane works fine but the data plane is not working the data plane session count is zero. When you go through and reset things and configure it? after upgrading the passive i thought its a configuration issue so i factory rest the device to sure by using this command request system private-data-reset and also do the factory rest by palo alto factory reset maintenance mode same thing no responses on data plane are you seeing the auto-commit and subsequent commits succeed? yes, and I do some change and the commits working fine Attempting to ping an interface isn't really that great of a test with PAN, as there's moving parts to having the traffic allowed. When you did the factory reset on the passive firewall, did you remember to active an interface-management profile that allowed ICMP and actually allow it on your rulebase assuming you weren't relying on intrazone-default? yes i add icmp in the interface-management profile and apply this on the interface that was under test,and i creat new rule to allowed the traffic to pass the firewall , i also try do downgrade to 10.1.5h2 after factory rest and no luck
... View more