Palo Alto Networks Certified Network Security Engineer (PCNSE)Deploy and ConfigureMedium
A network security team needs to implement a High Availability (HA) solution for two Palo Alto Networks firewalls. They decide to configure Active/Passive HA. Which of the following is a key characteristic of an Active/Passive HA configuration?
- AThe passive firewall continuously synchronizes its session table but does not receive configuration updates from the active firewall.
- BOne firewall is active and processes all traffic, while the other remains passive, ready to take over.
- CBoth firewalls actively process traffic simultaneously, sharing the load.
- DTraffic is always split evenly between both firewalls using ECMP.
Show answer & explanationAnswer & explanation
Correct answer: B. One firewall is active and processes all traffic, while the other remains passive, ready to take over.
In Active/Passive HA, one firewall handles all traffic, and the other is a standby, ready for failover. This provides redundancy without load sharing.
Why the other options are wrong
- A. The passive firewall does synchronize configuration updates from the active device to ensure consistency upon failover.
- C. This describes an Active/Active HA configuration, not Active/Passive.
- D. ECMP is a routing feature, not a primary characteristic of Active/Passive HA load sharing.
Active/Passive HA
A High Availability configuration where one firewall is active and processes all traffic, while the other is passive and acts as a standby.
- Provides redundancy and fault tolerance.
- Only one firewall is actively passing traffic at any given time.
- The passive firewall synchronizes configuration and session state.
- Failover occurs if the active firewall becomes unavailable.
Memory trick: One works hard, the other guards, ready for the changing cards!