Health probe failure on Load Balancer in Azure

Health probe failure on Load Balancer in Azure

20682
Created On 03/23/20 06:02 AM - Last Modified 04/06/20 17:16 PM


Symptom


External Load Balancer reporting PA-VM instances as unhealthy because health probes going through PA-VM are failing, which results in traffic disruption because Load balancer not forwarding traffic to unhealthy instances.

  • Review the Traffic logs for health probes traversing the firewall:
User-added image
  • Above details from traffic logs show there is no return traffic seen on the firewall.


Environment


  • Platform: VM-Series Firewall
  • PAN-OS / Plugin Version: 8.1.9 / -
  • Deployment: Azure


Cause


  • Traffic sent out of the firewall is not NAT’d correctly, so the return traffic is not re-directed back to the firewall interface


Resolution


  • Ensure that the NAT policy configured is performing both source (egress interface) and destination (internal resource IP) translations


Actions
  • Print
  • Copy Link

    https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000PPCZCA4&refURL=http%3A%2F%2Fknowledgebase.paloaltonetworks.com%2FKCSArticleDetail