Backup HA link down with message "Connection down: Reason: HA1 backup links mismatch with HA1"

Backup HA link down with message "Connection down: Reason: HA1 backup links mismatch with HA1"

1019
Created On 11/26/24 01:38 AM - Last Modified 07/01/26 20:44 PM


Symptom


HA debug shows "Received mismatched Serial Number on non-primary link"


Error: ha_peer_disconnect(src/ha_peer.c:1665): Group 60 (HA1-MGMT): peer connection error msg set: HA1 backup links mismatch with HA1

 err code : HA1 backup links mismatch with HA1

Error: ha_peer_recv_tlv(src/ha_peer.c:3902): Group 2 (HA1-MGMT): Received mismatched Serial Number on non-primary link


Environment


  • PAN-OS
  • HA configuration


Cause


It happens if the build release of peer has changed.

Generally this issue happens after the import peer device configuration backup to the other peer.



Resolution


To mitigate this issue edit the HA1-backup link and change interface to none then commit the changes to the firewall.

Then again re-configure HA1-backup link and select the backup interface then commit the configuration again to the firewall.  



Additional Information


This error may happen if HA1 and HA2 are inside the same subnet or if they are in the same VLAN. They must be separated.



Actions
  • Print
  • Copy Link

    https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u000000HEXoCAO&lang=en_US&refURL=http%3A%2F%2Fknowledgebase.paloaltonetworks.com%2FKCSArticleDetail

Choose Language