Palo Alto Networks Certified Network Security Administrator (PCNSA)Initial Configuration and ManagementHard

A network architect is designing a highly resilient network for a critical data center. They require a pair of Palo Alto Networks firewalls to operate in an Active/Active High Availability (HA) configuration. Which of the following is a key prerequisite for implementing Active/Active HA?

  1. ABoth firewalls must be connected to the same Layer 2 segment for all data interfaces.
  2. BThe firewalls must be configured in Virtual Wire mode or operate with multiple Virtual Systems (vsys).
  3. COnly one firewall can have a management interface configured and active at any given time.
  4. DSession synchronization must be disabled to prevent conflicts between active devices.
Show answer & explanation

Correct answer: B. The firewalls must be configured in Virtual Wire mode or operate with multiple Virtual Systems (vsys).

Active/Active HA requires a mechanism to share traffic processing across both firewalls. This is achieved either by using Virtual Wire deployments, where each firewall processes a subset of the traffic, or by leveraging Virtual Systems (vsys) where each vsys is active on a different firewall in the pair. This allows both firewalls to actively forward traffic simultaneously.

Why the other options are wrong

  • A. While data interfaces need to be connected to relevant segments, the specific requirement for Active/Active is how traffic is distributed and processed, not just L2 connectivity.
  • C. Both firewalls in an HA pair typically have their own management interfaces, regardless of HA mode, for independent access and management.
  • D. Session synchronization is crucial for maintaining session state across failovers in both Active/Passive and Active/Active, ensuring traffic continuity. Disabling it would lead to session drops.

Active/Active HA Prerequisites

Active/Active High Availability on Palo Alto Networks firewalls requires specific deployment modes like Virtual Wire or the use of multiple Virtual Systems (vsys) to enable both firewalls to actively process traffic concurrently.

  • Both firewalls process traffic simultaneously.
  • Requires Virtual Wire or multiple Virtual Systems.
  • Distributes load and provides redundancy.
  • More complex to configure than Active/Passive.

Memory trick: Virtual Wires or Vsys are Vital for Active/Active.

More Initial Configuration and Management questions