nerdexam
Palo_Alto_Networks

PCNSE · Question #789

What happens when an A/P firewall pair synchronizes IPsec tunnel security associations (SAs)?

The correct answer is A. Phase 2 SAs are synchronized over HA2 links. In an Active/Passive HA pair, only Phase 2 (IPsec) Security Associations are synchronized, and they are synchronized over the HA2 data link. Phase 1 (IKE) SAs are not synchronized between HA peers because IKE negotiations are lightweight and can be quickly re-established after…

Submitted by rohit_dlh· Apr 18, 2026Deploy and Configure

Question

What happens when an A/P firewall pair synchronizes IPsec tunnel security associations (SAs)?

Options

  • APhase 2 SAs are synchronized over HA2 links.
  • BPhase 1 and Phase 2 SAs are synchronized over HA2 links.
  • CPhase 1 SAs are synchronized over HA1 links.
  • DPhase 1 and Phase 2 SAs are synchronized over HA3 links.

How the community answered

(47 responses)
  • A
    94% (44)
  • C
    4% (2)
  • D
    2% (1)

Explanation

In an Active/Passive HA pair, only Phase 2 (IPsec) Security Associations are synchronized, and they are synchronized over the HA2 data link. Phase 1 (IKE) SAs are not synchronized between HA peers because IKE negotiations are lightweight and can be quickly re-established after a failover. Synchronizing Phase 2 SAs ensures that existing encrypted tunnels remain active without requiring full IKE and IPsec renegotiation after a failover event, minimizing traffic disruption.

Topics

#High Availability#IPsec Tunnels#HA Links#Session Synchronization

Community Discussion

No community discussion yet for this question.

Full PCNSE Practice