Impact on traffic for high-availability active-passive port failure
2308
Created On 03/03/20 10:29 AM - Last Modified 02/05/25 21:12 PM
Question
What is the impact on the traffic when a High-Availability (HA) port get a failure?
Environment
- PAN-OS
- High-Availability
- Active-Passive mode
Answer
The table showing the impact what happened when HA port(s) get down.
| HA1 | HA1-B | HA2 | HA2-B | FW1(active) | FW2(passive) | System log messages | Impact on network traffic |
|---|---|---|---|---|---|---|---|
| DOWN | UP | UP | UP | active | passive |
| No impact |
| UP | DOWN | UP | UP | active | passive |
| No impact |
| UP | UP | DOWN | UP | active | passive |
| No impact |
| UP | UP | UP | DOWN | active | passive |
| No impact |
| DOWN | DOWN | UP | UP | active | active |
|
|
| DOWN | UP | DOWN | UP | active | passive |
| No impact |
| DOWN | UP | UP | DOWN | active | passive |
| No impact |
| UP | DOWN | DOWN | UP | active | passive |
| No impact |
| UP | DOWN | UP | DOWN | active | passive |
| No impact |
Additional Information
Test performed on 2 PA-3050
PAN-OS 9.0.6
Passive state : shutdown
HA encryption disabled
Heatbeat Backup disabled
HA2 Kepp-alive enabled - action set to Log Only
"Heartbeat Backup" can prevent a split brain when both HA1 links are down.
Related KB articles
DotW: What is Peer-Split-Brain?
How To Avoid HA Split-Brain due to Missed Heartbeats
Reference
PAN-OS Administrator guide
HA links and backup links