Palo Alto Networks Certified Network Security Administrator (PCNSA)Initial Configuration and ManagementMedium
A network security architect is designing a high-availability (HA) solution for a pair of Palo Alto Networks firewalls. The requirement is to minimize network disruption during a failover event, ensuring that active sessions are maintained. Which HA mode and feature combination should the architect choose?
- AActive/Active with link monitoring and preemption.
- BActive/Passive with session synchronization enabled.
- CActive/Active with session synchronization and graceful shutdown.
- DActive/Passive with path monitoring enabled.
Show answer & explanationAnswer & explanation
Correct answer: B. Active/Passive with session synchronization enabled.
Active/Passive HA is the standard mode for session persistence during failover. Session synchronization ensures that the passive firewall has up-to-date information on active sessions, allowing it to seamlessly take over if the active firewall fails, thus minimizing disruption.
Why the other options are wrong
- A. Active/Active is not the primary mode for simple session persistence; link monitoring and preemption are failover triggers, not session persistence mechanisms.
- C. Active/Active is used for load sharing and typically requires more complex network configuration; session synchronization is key but 'graceful shutdown' is not an HA mode feature for session persistence.
- D. Path monitoring improves failover detection but doesn't inherently synchronize sessions for persistence.
HA Session Synchronization
The process where session state information is replicated from the active firewall to the passive firewall in an HA pair, enabling session continuity during a failover.
- Crucial for Active/Passive HA.
- Ensures stateful firewall sessions survive failover.
- Minimizes disruption for end-users.
Memory trick: The standby takes over, knowing all the active conversations.