Aggregate Interface Down on Passive Device
26020
Created On 02/07/19 23:40 PM - Last Modified 06/18/20 00:54 AM
Symptom
- Aggregate Interface is showing down on Passive device and is up on Active device.
- Under "Device -> High Availability -> Active / Passive settings", Passive state link is set to auto ( In this state all the interfaces on the devices will be UP)
- For aggregated interfaces, Firewall in passive mode will not participate in LACP pre-negotiations due to which it will show as down.
- Devices such as PA-3000 Series, PA-5000 Series, and PA-7000 Series have an option available under LACP tab, select Enable in HA Passive State which will allow passive device to engage in LACP pre-negotiation.
Network -> Interfaces -> AE ( Interface ) -> Enable in HA Passive State
Environment
- Only PA-3000 Series, PA-5000 Series, and PA-7000 Series firewall have option to keep passive device aggregate interface up.
Cause
- This is expected behavior with devices that are not PA-3000 Series, PA-5000 Series, and PA-7000 Series firewall as the option " Enable in HA Passive State" is not available.
Resolution
- Expected behavior with all devices expect PA-3000 Series, PA-5000 Series, and PA-7000 Series firewalls. Option to Enable in HA Passive State is not available in other firewall models and Aggregated interface will show down.
Additional Information
- Check step number 14 in the below document for details
https://docs.paloaltonetworks.com/pan-os/8-0/pan-os-admin/high-availability/set-up-activepassive-ha/configure-activepassive-ha.html