PCNSE · Question #552
An administrator has configured a pair of firewalls using high availability in Active/Passive mode. Link and Path Monitoring is enabled with the Failure Condition set to any. There is one link group c
The correct answer is D. Active. Given a link group with a 'Group Failure Condition' set to 'all', the Active firewall will remain active if only one interface within that group fails, because the condition for failover has not been met.
Question
An administrator has configured a pair of firewalls using high availability in Active/Passive mode. Link and Path Monitoring is enabled with the Failure Condition set to any. There is one link group configured containing member interfaces ethernet1/1 and ethernet1/2 with a Group Failure Condition set to all. Which HA state will the Active firewall go into if ethernet1/1 link goes down due to a failure?
Options
- ANon-functional
- BPassive
- CActive-Secondary
- DActive
How the community answered
(22 responses)- A5% (1)
- B18% (4)
- C5% (1)
- D73% (16)
Why each option
Given a link group with a 'Group Failure Condition' set to 'all', the Active firewall will remain active if only one interface within that group fails, because the condition for failover has not been met.
'Non-functional' is not a standard or typical HA state that a Palo Alto Networks firewall enters due to a single link failure under the specified link monitoring conditions; the firewall remains functional but with reduced interface availability.
The firewall would only transition to the Passive state if a failover occurred, which would require the group failure condition ('all' links down) to be met, causing the *other* firewall in the HA pair to become Active.
'Active-Secondary' is not a valid HA state in an Active/Passive setup; the primary states are typically Active, Passive, or potentially Suspended, not a hybrid active-secondary designation.
The HA link group is configured with a 'Group Failure Condition' set to 'all', which means that a failover will only be triggered if *all* member interfaces (ethernet1/1 and ethernet1/2) within that specific group go down. Since only ethernet1/1 has failed, and ethernet1/2 is presumed to be operational, the 'all' condition for group failure is not met, and thus the Active firewall will remain in the Active state.
Concept tested: HA Link and Path Monitoring Group Failure Condition
Source: https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-admin/high-availability/set-up-ha-active-passive/configure-link-and-path-monitoring
Topics
Community Discussion
No community discussion yet for this question.