Palo Alto Networks Certified Network Security Engineer (PCNSE)Plan and DesignMedium
A network security architect is designing a high-availability (HA) solution for a pair of Palo Alto Networks firewalls. The requirement is to minimize downtime during a firewall failure, with the active firewall handling all traffic and the passive firewall taking over immediately upon failure. Which HA mode should be configured to meet this requirement?
- AVirtual Wire HA
- BActive/Active HA with Link Aggregation Group (LAG)
- CActive/Passive HA
- DLayer 3 HA
Show answer & explanationAnswer & explanation
Correct answer: C. Active/Passive HA
Active/Passive HA mode is designed for immediate failover with minimal downtime. In this configuration, one firewall (active) handles all traffic, while the other (passive) remains synchronized and takes over seamlessly if the active firewall fails.
Why the other options are wrong
- A. Virtual Wire HA refers to the deployment mode of the firewall (Layer 2 transparent) and is not an HA mode itself.
- B. Active/Active HA distributes traffic across both firewalls, which is not the primary goal of minimizing downtime on a single device failure, and often requires more complex network configuration.
- D. Layer 3 HA refers to the deployment mode of the firewall (routed mode) and is not an HA mode itself, although Active/Passive can be deployed in Layer 3 mode.
Active/Passive HA
A high-availability configuration for firewalls where one device (active) processes all traffic, and a second device (passive) remains in a synchronized standby state, ready to take over immediately upon failure of the active device.
- One active, one passive firewall
- Seamless failover for minimal downtime
- State synchronization between units
Memory trick: HA: Two firewalls are better than one for uptime.