Palo Alto Networks Certified Network Security Administrator (PCNSA)Initial Configuration and ManagementMedium
A network engineer is configuring a new high-availability (HA) pair of Palo Alto Networks firewalls. They need to ensure that the active firewall can seamlessly fail over to the passive firewall without dropping existing sessions or requiring manual intervention. Which HA configuration option is crucial for achieving this seamless failover?
- ASynchronizing configuration and session information between peers.
- BConfiguring separate management interfaces for each firewall.
- CUsing different PAN-OS versions on the active and passive firewalls.
- DEnabling Preemptive mode on the passive firewall.
Show answer & explanationAnswer & explanation
Correct answer: A. Synchronizing configuration and session information between peers.
For seamless failover without session drops, it is critical to synchronize both the configuration and the session information between the active and passive firewalls. This ensures the passive firewall has the exact state of all active connections when it takes over.
Why the other options are wrong
- B. Separate management interfaces are a best practice for HA, but do not directly ensure session synchronization during failover.
- C. Using different PAN-OS versions is a misconfiguration and can prevent HA from functioning correctly, or at all.
- D. Preemptive mode defines how a firewall returns to an active state after recovery, not how sessions are maintained during an initial failover.
HA Session Synchronization
In a Palo Alto Networks HA pair, session synchronization ensures that the passive firewall maintains an up-to-date copy of all active sessions from the active firewall, allowing existing connections to continue uninterrupted after a failover.
- Prevents session drops during failover.
- Requires dedicated HA control and data links.
- Critical for stateful firewall operations.
Memory trick: Sync Sessions Smoothly Saves Services.