Backup HA link down with message "Connection down: Reason: HA1 backup links mismatch with HA1"
1019
Created On 11/26/24 01:38 AM - Last Modified 07/01/26 20:44 PM
Symptom
HA debug shows "Received mismatched Serial Number on non-primary link"
Error: ha_peer_disconnect(src/ha_peer.c:1665): Group 60 (HA1-MGMT): peer connection error msg set: HA1 backup links mismatch with HA1
err code : HA1 backup links mismatch with HA1
Error: ha_peer_recv_tlv(src/ha_peer.c:3902): Group 2 (HA1-MGMT): Received mismatched Serial Number on non-primary linkEnvironment
- PAN-OS
- HA configuration
Cause
It happens if the build release of peer has changed.
Generally this issue happens after the import peer device configuration backup to the other peer.
Resolution
To mitigate this issue edit the HA1-backup link and change interface to none then commit the changes to the firewall.
Then again re-configure HA1-backup link and select the backup interface then commit the configuration again to the firewall.
Additional Information
This error may happen if HA1 and HA2 are inside the same subnet or if they are in the same VLAN. They must be separated.