We have a pair of VM300 PAs in Azure set up in Active-Passive. They are running 9.0.7 code with VM Series plug in 1.0.8.
There was an issue in Azure on 19/10/20 which caused a failover and recovery (we use pre-emption). Post this issue the PAs were up and running but not passing traffic. we found that the secondary IP addresses (i.e. floating IPs) had been moved to the Azure VM for the Passive firewall (PA2). Hence no traffic flowing as this firewall was passive. We failed from the Active (PA1) over to this Firewall (PA2) and some traffic started to flow but everything was incredibly slow. we tried restarting VMs, failing back over, etc but nothing would change the state of the secondary IP addresses, they were locked to PA2.
Eventually we completely powered down the VM which was running PA1 and things started to run ok again. we then configured PA2 to always be Active and powered PA1 back up. PA1 came back up, re-established HA and things were running fine, PA2 Acitve, PA1 Passive. We then suspended PA2 to trigger failover and again we had issues with secondary addresses. The secondary addresses on the untrust VM interface floated over to PA1 correctly, but the secondary address on Trust VM interface disappeared completely from both PA1 and PA2. No failovers, restarts etc recovered this address.
We powered down PA2 and had to manually re-create the secondary address on Trust on PA1 to restore service. this is the state we are now in.
can someone please assist / recommend next steps? Failover it seems is broken.
Does any of the interfaces has a Public IP's associated with them?
I also had a similar issue but in my case I had public IP's associated with the interface and I used the Standard SKU for it. Once I changed it to Basic SKU the failover is working fine for me. However, the failover time was 6 to 8 mins each time.
In your Active/Passive Scenario Do you have L2L VPN tunnels configured?
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!