Palo Alto Networks Certified Network Security Administrator (PCNSA)Palo Alto Networks Security PlatformHard
A network engineer is configuring a Palo Alto Networks firewall in a highly available (HA) active/passive configuration. The engineer needs to ensure that the active firewall can take over the IP addresses and MAC addresses of the passive firewall's data interfaces during a failover event. Which HA feature is responsible for this seamless transition?
- AVirtual MAC Address
- BState Synchronization
- CPath Monitoring
- DHeartbeat Connection
Show answer & explanationAnswer & explanation
Correct answer: A. Virtual MAC Address
In an HA active/passive setup, the active firewall uses a virtual MAC address (along with the virtual IP address) for its data interfaces. Upon failover, the new active firewall takes ownership of this virtual MAC address (and IP), ensuring that upstream and downstream devices do not need to update their ARP tables, thus providing a seamless transition.
Why the other options are wrong
- B. State Synchronization ensures session information is mirrored, allowing active sessions to continue post-failover, but doesn't manage MAC/IP takeover itself.
- C. Path Monitoring checks the reachability of network paths, triggering failover if paths fail, but doesn't handle address takeover.
- D. Heartbeat connection is used to monitor the health of the peer firewall, not for IP/MAC takeover.
Virtual MAC Address (HA)
A shared MAC address used by the active firewall in an HA active/passive pair for its data plane interfaces, allowing for seamless failover without requiring ARP table updates on connected devices.
- Paired with Virtual IP Address.
- Ensures transparent failover.
- Critical for network stability during HA events.
Memory trick: Virtual MAC is like a shared identity card, passed to whoever is 'on duty' to keep traffic flowing.