Palo Alto Networks Certified Network Security Engineer (PCNSE)TroubleshootEasy
A network administrator is troubleshooting an issue where users are unable to access internal resources after a recent firmware upgrade on a Palo Alto Networks firewall in an active/passive High Availability (HA) configuration. The passive firewall is showing as 'non-functional' in the HA status. Which of the following is the MOST likely cause for the passive firewall's state?
- AThe passive firewall is running a different software version than the active firewall.
- BThe passive firewall's management interface is incorrectly configured.
- CThe HA backup link is experiencing high latency.
- DThe HA control link is down.
Show answer & explanationAnswer & explanation
Correct answer: A. The passive firewall is running a different software version than the active firewall.
In an active/passive HA configuration, both firewalls must run the exact same software version to maintain a healthy HA state. A version mismatch will often prevent the passive firewall from becoming fully functional and can lead to a 'non-functional' state.
Why the other options are wrong
- B. An incorrectly configured management interface might prevent access to the firewall, but wouldn't directly cause a 'non-functional' HA state related to a firmware upgrade.
- C. High latency on the HA backup link can cause performance issues or failover delays, but is less likely to directly cause a 'non-functional' state due to a firmware upgrade.
- D. A down HA control link would typically show a 'down' state for HA, but not necessarily 'non-functional' due to a firmware upgrade.
HA Version Mismatch
Palo Alto Networks firewalls in an HA pair must run the identical software version to ensure proper synchronization and functionality.
- Required for active/passive and active/active HA.
- Mismatched versions can lead to 'non-functional' or 'partial' states.
- Always upgrade both devices to the same version.
Memory trick: High Availability needs Harmonic Alignment of versions.