Health probe failure on Load Balancer in Azure
24355
Created On 03/23/20 06:02 AM - Last Modified 04/06/20 17:16 PM
Symptom
External Load Balancer reporting PA-VM instances as unhealthy because health probes going through PA-VM are failing, which results in traffic disruption because Load balancer not forwarding traffic to unhealthy instances.
- Review the Traffic logs for health probes traversing the firewall:
- Above details from traffic logs show there is no return traffic seen on the firewall.
Environment
- Platform: VM-Series Firewall
- PAN-OS / Plugin Version: 8.1.9 / -
- Deployment: Azure
Cause
- Traffic sent out of the firewall is not NAT’d correctly, so the return traffic is not re-directed back to the firewall interface
Resolution
- Ensure that the NAT policy configured is performing both source (egress interface) and destination (internal resource IP) translations