Palo Alto Networks Certified Network Security Engineer (PCNSE)Core ConceptsMedium
A network architect is designing a highly available network infrastructure using Palo Alto Networks firewalls. The requirement is that in case of a primary firewall failure, the secondary firewall must seamlessly take over all active sessions without any interruption to users. Which HA mode and configuration setting are necessary to achieve this goal?
- AActive/Active HA with asynchronous session transfer.
- BActive/Passive HA without session synchronization.
- CActive/Active HA with symmetric return enabled.
- DActive/Passive HA with session synchronization enabled.
Show answer & explanationAnswer & explanation
Correct answer: D. Active/Passive HA with session synchronization enabled.
Active/Passive HA is the standard mode for seamless failover without session interruption, provided that session synchronization is enabled. This ensures that the secondary firewall has a real-time copy of all active sessions from the primary.
Why the other options are wrong
- A. Asynchronous session transfer is not a standard HA configuration; session synchronization is typically real-time (synchronous) for seamless failover.
- B. Without session synchronization, active sessions would be dropped and need to be re-established upon failover.
- C. Active/Active HA is for load sharing and typically requires additional routing configurations (like PBF) to maintain session symmetry, and seamless session takeover is not its primary design goal without specific considerations.
HA Session Synchronization
A feature in Palo Alto Networks HA configurations that replicates active session information from the primary firewall to the secondary, enabling seamless failover.
- Replicates ongoing session state
- Prevents session loss during failover
- Crucial for seamless user experience in HA
Memory trick: Two firewalls, one brain for all active conversations.