Aggregate Interface Down on Passive Device

Aggregate Interface Down on Passive Device

26020
Created On 02/07/19 23:40 PM - Last Modified 06/18/20 00:54 AM


Symptom


  • Aggregate Interface is showing down on Passive device and is up on Active device.
  • Under "Device -> High Availability -> Active / Passive settings", Passive state link is set to auto ( In this state all the interfaces on the devices will be UP)
  • For aggregated interfaces, Firewall in passive mode will not participate in LACP pre-negotiations due to which it will show as down.
  • Devices such as PA-3000 Series, PA-5000 Series, and PA-7000 Series have an option available under LACP tab, select Enable in HA Passive State which will allow passive device to engage in LACP pre-negotiation.
 
Network -> Interfaces -> AE ( Interface ) -> Enable in HA Passive State


 


Environment


  • Only PA-3000 Series, PA-5000 Series, and PA-7000 Series firewall have option  to keep passive device aggregate interface up.


 


Cause


  • This is expected behavior with devices that are not PA-3000 Series, PA-5000 Series, and PA-7000 Series firewall as the option " Enable in HA Passive State" is not available.


Resolution


  1. Expected behavior with all devices expect PA-3000 Series, PA-5000 Series, and PA-7000 Series firewalls. Option to Enable in HA Passive State is not available in other firewall models and Aggregated interface will show down.


Additional Information


  • Check step number 14 in the below document for details

https://docs.paloaltonetworks.com/pan-os/8-0/pan-os-admin/high-availability/set-up-activepassive-ha/configure-activepassive-ha.html


 


Actions
  • Print
  • Copy Link

    https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000CmleCAC&lang=en_US%E2%80%A9&refURL=http%3A%2F%2Fknowledgebase.paloaltonetworks.com%2FKCSArticleDetail

Choose Language