Friday, July 10, 2026

Palo Alto - HA Configuration

request high-availability sync-to-remote running-config
show high-availability state
show high-availability all
show high-availability interface ha1
show high-availability interface ha2


admin@myfwl-tst01(active)> set cli config-output-format set
admin@myfwl-tst01(active)> configure
Entering configuration mode
[edit]
admin@myfwl-tst01(active)#


admin@myfwl-tst01(active)# show deviceconfig high-availability interface ha1-backup
set deviceconfig high-availability interface ha1-backup port ha1-b
set deviceconfig high-availability interface ha1-backup ip-address 192.168.101.5
set deviceconfig high-availability interface ha1-backup netmask 255.255.255.252
[edit]
admin@myfwl-tst01(active)# 


admin@myfwl-tst01(active)#  show deviceconfig high-availability interface ha2-backup
set deviceconfig high-availability interface ha2-backup port ethernet1/12
[edit]
admin@myfwl-tst01(active)# 


admin@myfwl-tst01(active)# show deviceconfig high-availability interface
set deviceconfig high-availability interface ha1 port ha1-a
set deviceconfig high-availability interface ha1 ip-address 192.168.100.5
set deviceconfig high-availability interface ha1 netmask 255.255.255.252
set deviceconfig high-availability interface ha1 monitor-hold-time 3000
set deviceconfig high-availability interface ha1-backup port ha1-b
set deviceconfig high-availability interface ha1-backup ip-address 192.168.101.5
set deviceconfig high-availability interface ha1-backup netmask 255.255.255.252
set deviceconfig high-availability interface ha2 port ethernet1/11
set deviceconfig high-availability interface ha2-backup port ethernet1/12
[edit]
admin@myfwl-tst01(active)# 


admin@myfwl-tst02(passive)> set cli config-output-format set
admin@myfwl-tst02(passive)> configure
Entering configuration mode
[edit]
admin@myfwl-tst02(passive)#
[edit]
admin@myfwl-tst02(passive)# show deviceconfig high-availability interface
set deviceconfig high-availability interface ha1 port ha1-a
set deviceconfig high-availability interface ha1 ip-address 192.168.100.6
set deviceconfig high-availability interface ha1 netmask 255.255.255.252
set deviceconfig high-availability interface ha1 monitor-hold-time 3000
set deviceconfig high-availability interface ha1-backup port ha1-b
set deviceconfig high-availability interface ha1-backup ip-address 192.168.101.6
set deviceconfig high-availability interface ha1-backup netmask 255.255.255.252
set deviceconfig high-availability interface ha2 port ethernet1/11
set deviceconfig high-availability interface ha2-backup port ethernet1/12
[edit]
admin@myfwl-tst02(passive)#

admin@myfwl-tst02(passive)# show deviceconfig high-availability interface ha1-backup
set deviceconfig high-availability interface ha1-backup port ha1-b
set deviceconfig high-availability interface ha1-backup ip-address 192.168.101.6
set deviceconfig high-availability interface ha1-backup netmask 255.255.255.252
[edit]
admin@myfwl-tst02(passive)# show deviceconfig high-availability interface ha2-backup
set deviceconfig high-availability interface ha2-backup port ethernet1/12
[edit]
admin@myfwl-tst02(passive)#



admin@myfwl-tst02(passive)> show high-availability state

Group 4: N/A
  Mode: Active-Passive
  Local Information:
    Version: 1
    Mode: Active-Passive
    State: passive (last 23 days)
    Last suspended state reason: User requested
    Device Information:
      Management IPv4 Address: 10.15.37.88/24
      Management IPv6 Address:
      Jumbo-Frames disabled; MTU 1500
    HA1 Control Links Joint Configuration:
      Encryption Enabled: no
    Election Option Information:
      Priority: 2
      Preemptive: no
    Version Compatibility:
      Software Version: Match
      Application Content Compatibility: Match
      IOT Content Compatibility: Match
      Anti-Virus Compatibility: Match
      Threat Content Compatibility: Match
      VPN Client Software Compatibility: Match
      Global Protect Client Software Compatibility: Match
      Plugin Information:
        DLP: Match
    State Synchronization: Complete; type: ethernet
  Peer Information:
    Connection status: up
    Version: 1
    Mode: Active-Passive
    State: active (last 23 days)
    Last suspended state reason: User requested
    Device Information:
      Management IPv4 Address: 10.15.37.87/24
      Management IPv6 Address:
      Jumbo-Frames disabled; MTU 1500
      Connection up; Primary HA1 link
      Connection up
      Keep-alive config log-only; status up; Primary HA2 Link
        Monitor Hold inactive; Allow settling after failure
      Keep-alive status up
    Election Option Information:
      Priority: 1
      Preemptive: no
  Configuration Synchronization:
    Enabled: yes
    Running Configuration: synchronized
admin@myfwl-tst02(passive)>




admin@myfwl-tst02(passive)> show high-availability all

Group 4: N/A
  Mode: Active-Passive
  Local Information:
    Version: 1
    Mode: Active-Passive
    State: passive (last 23 days)
    Last suspended state reason: User requested
    Device Information:
      Model: PA-1420
      Serial: 026909006934
      Management IPv4 Address: 10.15.37.88/24
      Management IPv6 Address:
      Jumbo-Frames disabled; MTU 1500
    HA1 Control Links Joint Configuration:
      Link Monitor Interval: 3000 ms
      Encryption Enabled: no
    HA1 Control Link Information:
      IP Address: 192.168.100.6/30
      MAC Address: 58:76:9c:03:46:19
      Interface: ha1-a
      Link State: Up; Setting: 1Gb/s-full
      Key Imported : no
    HA1 Backup Control Link Information:
      IP Address: 192.168.101.6/30
      MAC Address: 58:76:9c:03:46:00
      Interface: ha1-b
      Link State: Up; Setting: 1Gb/s-full
    HA2 Data Link Information:
      MAC Address: 00:da:27:5e:6e:00
      Interface: ethernet1/11
      Link State: Up; Setting: 5Gb/s-full
      Keep-alive config log-only; threshold 10000 ms
    HA2 Backup Data Link Information:
      MAC Address: 00:da:27:5e:6e:100
      Interface: ethernet1/12
      Link State: Up; Setting: 5Gb/s-full
    Election Option Information:
      Priority: 2
      Preemptive: no
      Promotion Hold Interval: 2000 ms
      Hello Message Interval: 8000 ms
      Heartbeat Ping Interval: 2000 ms
      Max # of Flaps: 3
      Preemption Hold Interval: 1 min
      Monitor Fail Hold Up Interval: 0 ms
      Addon Master Hold Up Interval: 500 ms
    Active-Passive Mode:
      Passive Link State: auto
      Monitor Fail Hold Down Interval: 1 min
    Version Information:
      Build Release: 11.2.7-h15
      URL Database: 20260616.20327
      Application Content: 9123-10147
      IOT Content: 233-736
      Anti-Virus: 5609-6136
      Threat Content: 9123-10147
      VPN Client Software: Not Installed
      Global Protect Client Software: Not Installed
      Plugin Information:
        DLP: 5.0.1
    Version Compatibility:
      Software Version: Match
      Application Content Compatibility: Match
      IOT Content Compatibility: Match
      Anti-Virus Compatibility: Match
      Threat Content Compatibility: Match
      VPN Client Software Compatibility: Match
      Global Protect Client Software Compatibility: Match
      Plugin Information:
        DLP: Match
    State Synchronization: Complete; type: ethernet
  
Peer Information:
    Connection status: up
    Version: 1
    Mode: Active-Passive
    State: active (last 23 days)
    Last suspended state reason: User requested
    Device Information:
      Model: PA-1420
      Serial: 026909006933
      Management IPv4 Address: 10.15.37.87/24
      Management IPv6 Address:
      Jumbo-Frames disabled; MTU 1500
    HA1 Control Link Information:
      IP Address: 192.168.100.5
      MAC Address: 58:76:9c:03:46:15
      Connection up; Primary HA1 link
    HA1 Backup Control Link Information:
      IP Address: 192.168.101.5
      MAC Address: 58:76:9c:03:46:14
      Connection up
    HA2 Data Link Information:
      MAC Address: 00:da:27:5e:6c:1a
      Keep-alive config log-only; status up; Primary HA2 Link
        Monitor Hold inactive; Allow settling after failure
    HA2 Backup Data Link Information:
      MAC Address: 00:da:27:5e:6c:00
      Keep-alive status up
    Election Option Information:
      Priority: 1
      Preemptive: no
    Version Information:
      Build Release: 11.2.7-h15
      URL Database: 20260710.20252
      Application Content: 9123-10147
      IOT Content: 233-736
      Anti-Virus: 5609-6136
      Threat Content: 9123-10147
      VPN Client Software: Not Installed
      Global Protect Client Software: Not Installed
      Plugin Information:
        DLP: 5.0.1
  Initial Monitor Hold inactive; Allow Network/Links to Settle:
    Link and path monitoring failures honored
  Link Monitoring Information:
    Enabled: yes
    Failure condition: any
    Group link group 1:
      Enabled: yes
      Failure condition: any
      Interface ethernet1/1: up
      Interface ethernet1/15: up
      Interface ethernet1/16: up
  Path Monitoring Information:
    Enabled: no
    Failure condition: any
    Virtual-Wire Groups:
      No Virtual-Wire path monitoring groups
    VLAN Groups:
      No VLAN path monitoring groups
    Virtual-Router Groups:
      No Virtual-Router path monitoring groups
  Configuration Synchronization:
    Enabled: yes
    Running Configuration: synchronized
admin@myfwl-tst02(passive)>




admin@myfwl-tst02(passive)>show high-availability interface ha1

Interface ha1: ha1-a
-------------------------------------------------------------------
Name: ha1-a, ID: 5
Link status:
  Runtime link speed/duplex/state: 1000/full/up
  Configured link speed/duplex/state: auto/auto/auto
MAC address:
  Port MAC address 58:76:9c:03:46:00
Operation mode: ha
Untagged sub-interface support: no
--------------------------------------------------------------------
Name: ha1-a, ID: 5
Operation mode: ha
HA interface role: ha1, function: control-link
Interface IP address: 192.168.100.6/30
Interface management profile: N/A
Service configured:
Zone: N/A, virtual system: vsys1
Adjust TCP MSS: no
Policing: no
--------------------------------------------------------------------

--------------------------------------------------------------------
Logical interface counters:
--------------------------------------------------------------------
bytes received                    1415422384
bytes transmitted                 1316095758
packets received                  5373476
packets transmitted               5368784
receive errors                    0
transmit errors                   0
receive packets dropped           0
transmit packets dropped          0
multicast packets received        0
--------------------------------------------------------------------


admin@myfwl-tst02(passive)>


admin@myfwl-tst02(passive)>show high-availability interface ha2

Interface ha2: ethernet1/11
---------------------------------------------------------------------
Name: ethernet1/11, ID: 26
Link status:
  Runtime link speed/duplex/state: 5000/full/up
  Configured link speed/duplex/state: auto/auto/auto
MAC address:
  Port MAC address 00:da:27:5e:6e:00
Interface Type :
  Port Type: RJ45
Capability : auto, 10Mb/s-full, 100Mb/s-full, 1Gb/s-full, 2.5Gb/s-full, 5Gb/s-full
Operation mode: ha
Untagged sub-interface support: no
---------------------------------------------------------------------
Name: ethernet1/11, ID: 26
Operation mode: ha
HA interface role: ha2, function: data-link
Interface management profile: N/A
Service configured:
Zone: N/A, virtual system: vsys1
Adjust TCP MSS: no
Policing: no
---------------------------------------------------------------------
--------------------------------------------------------------------
Physical port counters read from MAC:
--------------------------------------------------------------------------------
rx-broadcast                  0
rx-bytes                      291113138266
rx-multicast                  0
rx-unicast                    653587888
tx-broadcast                  0
tx-bytes                      378936588
tx-multicast                  0
tx-unicast                    4371765
-------------------------------------------------------------------

--------------------------------------------------------------------
Detailed physical port counters read from MAC:
--------------------------------------------------------------------
rx packets 64 bytes                      8226572
rx packets 65 to 127 bytes               313787
rx packets 256 to 511 bytes              649419294
---------------------------------------------------------------------

Hardware interface counters read from CPU:
--------------------------------------------------------------------
bytes received                           288498794766
bytes transmitted                        324437532
packets received                         653587907
packets transmitted                      4371978
receive incoming errors                  0
receive discarded                        0
receive errors                           0
packets dropped                          0
--------------------------------------------------------------------


Logical interface counters read from CPU:
-------------------------------------------------------------------
bytes received                           288498794766
bytes transmitted                        324437532
packets received                         653587907
packets transmitted                      4371978
receive errors                           0
packets dropped                          0
packets dropped by flow state check      0
forwarding errors                        0
no route                                 0
arp not found                            0
neighbor not found                       0
neighbor info pending                    0
mac not found                            0
packets routed to different zone         0
land attacks                             0
ping-of-death attacks                    0
teardrop attacks                         0
ip spoof attacks                         0
mac spoof attacks                        0
ICMP fragment                            0
layer2 encapsulated packets              0
layer2 decapsulated packets              0
tcp cps                                  0
udp cps                                  0
sctp cps                                 0
other cps                                0
---------------------------------------------------------------------



admin@myfwl-tst02(passive)>


palo alto firewall active passive does not sync

If a Palo Alto Networks Active/Passive HA pair is not syncing, the cause is usually one of a few common issues. Here's a systematic way to troubleshoot.

1. Check HA Status

On both firewalls, run:

show high-availability state

Verify:

  • One firewall is active, the other is passive
  • HA state is synchronized
  • Configuration state is In Sync

If you see Out of Sync, continue with the steps below.


2. Check What Is Out of Sync

show high-availability state | match running-sync

or

show config sync status

Look for messages such as:

  • Running configuration not synchronized
  • Candidate configuration exists
  • Peer not synchronized

3. Compare Running Configurations

From the GUI:

  • Dashboard → High Availability
  • Check Running Config Sync status.

Or use:

show config diff

This shows the configuration differences between peers.


4. Verify HA Links

Check whether the HA1 (control) and HA2 (data/session) links are up:

show high-availability interfaces

Verify:

  • HA1 = Up
  • HA2 = Up

Also confirm:

  • No packet loss
  • Correct IP addressing (if using HA1 backup)
  • Same speed/duplex settings

5. Check Software Versions

Both firewalls must have:

  • Same PAN-OS version
  • Same content versions (recommended)
  • Same plugins
  • Same dynamic updates (recommended)

Check:

show system info

6. Verify HA Configuration

Compare:

  • Group ID
  • Device ID
  • Authentication key
  • HA1 IP addresses
  • HA2 configuration
  • Encryption settings

Any mismatch can prevent synchronization.


7. Commit Changes

A common issue is that one firewall has only a candidate configuration.

Run:

commit

Then check sync again.


8. Force Configuration Sync

From the active firewall:

GUI

  • Device → High Availability
  • Sync to Peer

or CLI:

request high-availability sync-to-remote running-config

If it fails, note the exact error.


9. Check HA Logs

less mp-log ha_agent.log

Look for messages such as:

  • Config sync failed
  • Peer rejected config
  • Version mismatch
  • Authentication failure

Also check:

show jobs all

for failed synchronization jobs.


10. Common Causes

SymptomPossible Cause
Out of SyncConfiguration differences
Sync fails immediatelyPAN-OS version mismatch
HA1 downPhysical link, VLAN, or routing issue
Sync stuckCandidate config not committed
Peer rejected configLicense, plugin, or feature mismatch
Passive never updatesDevice suspended or HA disabled

Useful CLI Commands

show high-availability state

show high-availability interfaces

show config sync status

show config diff

show jobs all

show system info

request high-availability sync-to-remote running-config

less mp-log ha_agent.log

If you can provide:

  • the output of show high-availability state,
  • the PAN-OS version (for example, 11.1.6-h3),
  • whether you're seeing "Out of Sync", "Sync Failed", or "Running Config Not Synchronized", and
  • any error from request high-availability sync-to-remote running-config,

I can help identify the specific cause.



No comments:

Post a Comment

PALO ALTO FIREWALL STUDY GUIDE

PALO ALTO FIREWALL STUDY GUIDE 1. Palo Alto Networks Firewall Overview What is Palo Alto Firewall? A Palo Alto Networks Next-Generation Fire...