In a HA Active-Active setup, how do you bring a firewall out of Suspended (Non-Functional Loop) mode when link monitoring is enabled, and is forcing the firewall back into Suspended state?

In a HA Active-Active setup, how do you bring a firewall out of Suspended (Non-Functional Loop) mode when link monitoring is enabled, and is forcing the firewall back into Suspended state?

310
Created On 04/09/25 17:43 PM - Last Modified 10/15/25 23:19 PM


Objective


In a HA Active-Active setup with 'any' link monitoring enabled, one of the firewalls may get into a state where:

  • The links go down (for reasons not discussed in this article) causing the firewall to go into Suspended (Non-Functional Loop) mode.
  • Enabling the links when firewall is in Suspended state would not bring the links up.
  • Moving the firewall out of Suspended mode would not work as the firewall would detect the links being down, and link monitoring forces the firewall back into Suspended state.

How do you bring the firewall back to Active state in such scenarios?



Environment


NGFW



Procedure


Disable and re-enable link monitoring:

  • Go to Device > High Availability > Link and Path Monitoring and uncheck Enabled.
  • Commit the configuration.
  • Move the firewall out of Suspended state.
  • Enable/bring the concerned links back up.
  • Go to Device > High Availability > Link and Path Monitoring and check Enabled.
  • Commit the configuration.

Alternatively, you can choose to remove the specific links from monitoring:

  • Remove interfaces from Device > High Availability > Link and Path Monitoring > Link Group.
  • Commit the configuration.
  • Move the firewall out of Suspended state.


Actions
  • Print
  • Copy Link

    https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA1Ki000000TN2DKAW&lang=en_US&refURL=http%3A%2F%2Fknowledgebase.paloaltonetworks.com%2FKCSArticleDetail