Professional Documents
Culture Documents
High Availability
High Availability
HIGH AVAILABILITY
• HA components and operation
• Active/passive HA configuration
• Monitoring HA state
EDU-210 Version A
PAN-OS® 9.0
Agenda
After you complete this module,
you should be able to:
Active/passive HA configuration
Monitoring HA state
Firewall High Availability
• HA provides:
• Redundancy Active/Passive Active/Active
• Business continuity
• Not synchronized:
• Management interface
configuration, HA settings, logs,
and ACC information
*Not PA-200
4 | © 2019 Palo Alto Networks, Inc.
Active/Passive HA
• One firewall actively processes traffic Active/Passive
• One firewall synchronized and ready to
process traffic
• No increase in session capacity
• Supports Virtual Wire, Layer 2, and Layer 3
interfaces
Active/passive HA configuration
Monitoring HA state
Active/Passive HA Links
Sync configuration
Mgmt Control Link Control Link Mgmt
(HA1)
Layer 3 link* (HA1)
Plane Plane
Exchange heartbeats and hellos
*Optionally encrypted
Dedicated HA ports:
MP HA1 Control link
• PA-800, PA-3000, PA-3200,
PA-5000, PA-7000 Series DP HA2 Data link
Non-dedicated HA ports:
• PA-200 and PA-500 Series MP MGT* Control link
• VM-Series DP eth n/n Data link
• Use MGT/in-band ports for HA
• Set in-band interface type to HA
MP
eth n/n Backup Data link eth n/n Backup Data link
NPC NPC
Assign device
priorities to both Lower Number Higher Number
firewalls
Switch on failure
Active Passive
Preemption
Enabled?
Automatic failback
after repair
hello hello
Path Groups
Aggressive
Recommended Advanced
Active/passive HA configuration
Monitoring HA state
Prepare In-Band Interfaces
Network > Interfaces > Ethernet > <interface_name>
Select.
Choose same ID on
both peers (1-63).
• If there is no
dedicated HA1 If MGT port, uses
current IP address
port, use MGT or
an in-band port.
Only if peer is on
another subnet
Choose an in-band
port and configure IP
address and netmask
Fail Group if
any link fails
Fail Group if
all links fail
Active/passive HA configuration
Monitoring HA state
Active/Passive HA Pair Start-Up ACTIVE
state
No
No
Administrator
initiated (testing?) No
No
SUSPENDED Suspend PASSIVE
state firewall state
Q &&
A
35 | © 2019 Palo Alto Networks, Inc.
High Availability Lab (Pages 254-263 in the Lab Guide)
• Load a firewall lab configuration
• View HA status in the Dashboard
• Configure active/passive HA
• Configure HA monitoring
• Verify HA configuration