Palo Alto PA-5500 / PA-7500 Active/Active NGFW Cluster Architecture & Interface Behavior

Palo Alto PA-5500 / PA-7500 Active/Active NGFW Cluster Architecture & Interface Behavior

284
Created On 07/21/26 21:02 PM - Last Modified 07/24/26 17:20 PM


Symptom


• LACP not detecting peers on non-leader nodes
• LACP issues on all aggregates of Cluster 2, Node 2
• CLI tests indicate LACP does not find a peer
• Physical interfaces are visible
• Firewall appears to be operating in active-passive mode despite active-active cluster configuration
• LACP inconsistency observed in Cluster 1, including with the leader node
• Traffic appears to be passing through normally
 



Environment


**Product_versions**
• PAN-OS: 12.1.4
**Hardware Details**
• PA-5500, 7500

**Network Config**
• Active-active firewall clusters
• LACP
• Aggregate interfaces



Cause


It is important to distinguish the NGFW Cluster Active/Active architecture (used by PA-5500/7500 series) from Legacy Active/Active HA Pairs:  Legacy Active/Active
 HA Pairs: Require separate routing domains, complex asymmetric session handling via dedicated HA3 packet-forwarding links, and independent control planes on both nodes.  
 NGFW Cluster Active/Active: Fuses nodes into a single logical firewall with a unified
 routing domain. Both nodes process traffic in parallel across a dual active data plane, while control plane negotiation is centralized on a single node.  



Resolution


Core Cluster Characteristics
 
 1. Single Logical Device PerceptionTo neighboring network devices and upstream/downstream switches, 
 the entire NGFW cluster operates and presents itself as a single logical Layer 2 or Layer 3 device.
 
  
2. Dual Active Data Plane with Single Active Control PlaneData Plane:

 Active/Active — Both nodes simultaneously forward and process data traffic.  
 Control Plane: Active/Passive — Managed strictly by the Leader (Node 1) control plane. 

 Because only one Control Plane is active, the Leader node is exclusively
 responsible for managing the LACP (Link Aggregation Control Protocol) stack and negotiating active sessions for all Multi-Chassis Link Aggregation Group (MC-LAG) member
 ports across both nodes in the cluster.
 
 3. Non-Leader Node LACP BehaviorDue to the centralized control plane model:The Non-Leader (Follower) node forwards incoming MC-LAG
 LACP Protocol Data Units (PDUs) across the Inter-Firewall Link (IFL/HSCI)
 to the Leader node for processing.The Non-Leader node drops LACP PDUs originating from itself on these member interfaces.
 
 Consequently, from the Non-Leader node's local perspective, its Aggregate Ethernet (AE) member ports will report as "peer not detected" or "DOWN" in its local CLI and Management GUI.



Additional Information


Traffic appears to be passing through and it seems to be a visual issue (LACP peer not found, but services are functional).

Actions
  • Print
  • Copy Link

    https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA1Ki000000kC4qKAE&lang=en_US&refURL=http%3A%2F%2Fknowledgebase.paloaltonetworks.com%2FKCSArticleDetail