nerdexam
Palo_Alto_Networks

PCNSE · Question #552

An administrator has configured a pair of firewalls using high availability in Active/Passive mode. Link and Path Monitoring is enabled with the Failure Condition set to any. There is one link group c

The correct answer is D. Active. Given a link group with a 'Group Failure Condition' set to 'all', the Active firewall will remain active if only one interface within that group fails, because the condition for failover has not been met.

Submitted by klara.se· Apr 18, 2026Operate

Question

An administrator has configured a pair of firewalls using high availability in Active/Passive mode. Link and Path Monitoring is enabled with the Failure Condition set to any. There is one link group configured containing member interfaces ethernet1/1 and ethernet1/2 with a Group Failure Condition set to all. Which HA state will the Active firewall go into if ethernet1/1 link goes down due to a failure?

Options

  • ANon-functional
  • BPassive
  • CActive-Secondary
  • DActive

How the community answered

(22 responses)
  • A
    5% (1)
  • B
    18% (4)
  • C
    5% (1)
  • D
    73% (16)

Why each option

Given a link group with a 'Group Failure Condition' set to 'all', the Active firewall will remain active if only one interface within that group fails, because the condition for failover has not been met.

ANon-functional

'Non-functional' is not a standard or typical HA state that a Palo Alto Networks firewall enters due to a single link failure under the specified link monitoring conditions; the firewall remains functional but with reduced interface availability.

BPassive

The firewall would only transition to the Passive state if a failover occurred, which would require the group failure condition ('all' links down) to be met, causing the *other* firewall in the HA pair to become Active.

CActive-Secondary

'Active-Secondary' is not a valid HA state in an Active/Passive setup; the primary states are typically Active, Passive, or potentially Suspended, not a hybrid active-secondary designation.

DActiveCorrect

The HA link group is configured with a 'Group Failure Condition' set to 'all', which means that a failover will only be triggered if *all* member interfaces (ethernet1/1 and ethernet1/2) within that specific group go down. Since only ethernet1/1 has failed, and ethernet1/2 is presumed to be operational, the 'all' condition for group failure is not met, and thus the Active firewall will remain in the Active state.

Concept tested: HA Link and Path Monitoring Group Failure Condition

Source: https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-admin/high-availability/set-up-ha-active-passive/configure-link-and-path-monitoring

Topics

#High Availability#Link Monitoring#Link Groups#HA Failover Logic

Community Discussion

No community discussion yet for this question.

Full PCNSE Practice