Microsoft Hyper-V VM-Series HA2 link flaps when using NIC teaming on Windows Server

Microsoft Hyper-V VM-Series HA2 link flaps when using NIC teaming on Windows Server

1835
Created On 01/26/23 13:21 PM - Last Modified 04/30/24 03:40 AM


Symptom


  • Active and passive PA-VMs with HA2 keepalives enabled are each on different Windows Server hosts with Microsoft Hyper-V installed.
  • The hosts are connected to network switches using Windows Server NIC teaming in Switch Independent mode with Dynamic load-balancing.
  • When load balancing, said mode replaces the VM network adapter's source MAC address with that of one of the physical interfaces of the NIC team.
  • On the HA2 links, the peer PA-VM receives the packet with a source MAC address different from that of the HA2 interface of its peer and drops it.
  • The HA2 and HA2 backup links therefore flap continuously under heavy traffic load triggering link load balancing.
  • System logs (show log system) report HA2 keep-alive down messages
critical ha             ha2-kee 0  HA Group 1: Local HA2 keep-alive down


Environment


  • Microsoft Windows Server 2012(R)/2016
    • Microsoft Hyper-V
    • NIC team in Switch Independent mode with Dynamic load-balancing
    • External virtual switch connected to NIC team
  • Active/Passive High Availability (HA) VM-Series firewall pair
  • PAN-OS 10.1.5-h1
  • Network switch(es) connecting hosts


Cause


  • HA2 and/or HA2 backup links expect to receive HA2 keep-alives only with the source MAC address of its peer PA-VM's Hypervisor-assigned MAC address of its virtual network adapter.
  • Since the MAC address of the source is changed, they are dropped.


Resolution


On Windows Hyper-V VM-series Windows Server NIC teaming is not supported with High Availability (HA).
 


Actions
  • Print
  • Copy Link

    https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u000000kGZACA2&lang=en_US&refURL=http%3A%2F%2Fknowledgebase.paloaltonetworks.com%2FKCSArticleDetail