Why should LACP Pre-negotiation be disabled on HA Active/Passive L3 firewalls neighboring a single switch?
19749
Created On 08/01/20 23:42 PM - Last Modified 04/22/24 21:50 PM
Question
Why should LACP Pre-negotiation be disabled on HA Active/Passive L3 firewalls neighboring a single switch?
Environment
- PANOS versions: 8.1.x, 9.0.x, 9.1.x, 10.0.x
- Active/Passive HA firewall with L3 interfaces enabled neighboring a single L3 switch
- Topology
- LACP Pre-negotiation is enabled on Active HA firewall and Passive-HA firewall
Answer
- With LACP pre-negotiation enabled, ports on both Active and Passive firewalls will send/process LACP PDUs and neighboring device observe both physical ports of ae interface are UP.
- This causes neighboring device to send traffic to either one of those physical links as both are part of ae interface.
- Any traffic going towards Passive firewall will be blackholed and result in network outage/ high latency.