LACP Based aggregate interface status is "down" on an HA "suspended" device with LACP pre-negotiation enabled.

LACP Based aggregate interface status is "down" on an HA "suspended" device with LACP pre-negotiation enabled.

20018
Created On 02/12/24 08:17 AM - Last Modified 03/01/24 22:26 PM


Symptom


  • LACP pre-negotiation is enabled.
  • HA state of the device is "suspended".
  • LACP based aggregate interface status is "down"


Environment


  • Palo Alto Firewalls
  • Supported PAN-OS
  • High Availability Active/Passive
  • LACP pre-negotiation enabled.
  • Device is in HA "suspended" state.


Cause


  • As described in "LACP and LLDP Pre-Negotiation for Active/Passive HA ", LACP pre-negotiation will pre-negotiate LACP in HA passive or Non-Functional state.
  • As the device is in HA “Suspended” state, Firewall will not exchange LACP BPDU and LACP port will be in “Down” state.


Resolution


  1. Move the device to HA functional state for firewall to move to HA "Passive" state and negotiate LACP.
  2. Refer How to recover HA pair member  to make HA device functional.
System logs (show log system) provided for reference.

info     ha             state-c 0  HA Group 1: Moved from state Active to state Suspended
critical lacp    ethern link-do 0  LACP interface ethernet1/5 moved out of AE-group ae1. Selection state Unselected(Link down)
critical lacp    ethern link-do 0  LACP interface ethernet1/6 moved out of AE-group ae1. Selection state Unselected(Link down)
critical lacp    ethern link-do 0  LACP interface ethernet1/7 moved out of AE-group ae1. Selection state Unselected(Link down)
critical lacp    ethern link-do 0  LACP interface ethernet1/8 moved out of AE-group ae1. Selection state Unselected(Link down)

info     ha             state-c 0  HA Group 1: Moved from state Initial to state Passive
critical lacp    ethern lacp-up 0  LACP interface ethernet1/5 moved into AE-group ae1.
critical lacp    ethern lacp-up 0  LACP interface ethernet1/6 moved into AE-group ae1.
critical lacp    ethern lacp-up 0  LACP interface ethernet1/7 moved into AE-group ae1.
critical lacp    ethern lacp-up 0  LACP interface ethernet1/8 moved into AE-group ae1.

 



Additional Information



 



Actions
  • Print
  • Copy Link

    https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u0000008X6lCAE&lang=en_US&refURL=http%3A%2F%2Fknowledgebase.paloaltonetworks.com%2FKCSArticleDetail

Choose Language